05.08.2013 Views

Trend Micro InterScan Gateway Security Appliance M-Series ...

Trend Micro InterScan Gateway Security Appliance M-Series ...

Trend Micro InterScan Gateway Security Appliance M-Series ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Trend</strong> <strong>Micro</strong> <strong>InterScan</strong> <strong>Gateway</strong> <strong>Security</strong> <strong>Appliance</strong> M-<strong>Series</strong> Administrator’s Guide<br />

Scan Engine Technology<br />

IntelliScan<br />

IntelliScan is a feature in <strong>Trend</strong> <strong>Micro</strong> products that allows optimization of scanning<br />

time by enabling the product to skip file types that are safe from virus infection.<br />

It is a safe compromise between performance and detection. Users can enable<br />

IntelliScan at the gateway or in the desktop so that their product scans only scannable<br />

file types. Scannable file types are those that can contain malicious code. Such file<br />

types are known to be used by malware authors.<br />

IntelliScan identifies true file type, such that it detects even renamed Win32<br />

executable files.<br />

IntelliTrap<br />

IntelliTrap scans SMTP and POP3 traffic to catch packed malicious executables sent<br />

as attachment to email messages. It is the Scan Engine technology that heuristically<br />

catches packed malware at the gateway.<br />

IntelliTrap evaluates attachments by checking for characteristics of compressed<br />

Win32 files. It is based on the concept that average users do not usually pack<br />

program files and send them through email. On the other hand, malware authors<br />

usually use packers to change the binary image of their programs, and then spam<br />

them via email or give them malware mass-mailing capability.<br />

It is designed specifically to catch possibly malicious packed Win32 executable files.<br />

It uses the detection name PAK_GENERIC.XXX. To minimize the possibility of<br />

false positives, IntelliTrap uses exception patterns for normal software.<br />

C-10<br />

As with <strong>Trend</strong> <strong>Micro</strong>'s other heuristics technologies, IntelliTrap detection is<br />

superseded by specific detection.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!