01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

6<br />

<strong>Web</strong> filtering<br />

Virus and malware filtering<br />

Allow URL hosts that match in list Antimalware URL Whitelist<br />

URL.Host matches in list Antimalware URL Whitelist –> Stop Rule Set<br />

The rule uses the URL.Host property to check whether a given URL matches one of the entries on<br />

the specified whitelist. If it does, processing of the rule set stops and the blocking rule is not<br />

processed.<br />

You can use this rule to exempt web traffic from filtering when the hosts of the URLs involved are<br />

well-known web servers for which it is safe to assume that they spread no viruses and other<br />

malware. Whitelisting increases performance because it avoids the effort of scanning the<br />

respective web objects.<br />

Allow streaming media from list Antimalware Media Whitelist<br />

(URL Categories contains Streaming Media OR<br />

URL Categories contains Internet Radio / TV OR<br />

URL Categories contains General News)<br />

AND MediaType.Ensured all in list Antimalware Media Type Whitelist –> Stop Rule Set<br />

The rule uses the URL.Categories property to check whether a given URL belongs to Streaming<br />

Media or related categories. The URL Filter module, which is called to retrieve category<br />

information, runs with the Default settings, as specified with the property.<br />

The second part of the criteria uses the MediaType.Ensured property to check if the media type of<br />

a web object is found on the specified whitelist.<br />

If the URL belongs to one of the categories in question, and the web object that is located by the<br />

URL is of a media type that is on the whitelist, processing of the rule set stops and the blocking<br />

rule is not processed.<br />

The Anti-Malware module scans complete files, which means it waits for the end of data<br />

transmission before starting the scan. As streaming media is by nature an endless stream of data,<br />

the Anti-Malware module would wait forever. However, the risk that streaming media will contain a<br />

virus or other malware is very low. Therefore, streaming media can be exempted from scanning.<br />

Block if virus was found<br />

Antimalware.Infected equals true –> Block<br />

— Statistics.Counter.Increment (“BlockedByAntiMalware”,1)<br />

The rule uses the Antimalware.Infected property to check whether a given web object is infected<br />

by a virus or other malware. The Anti-Malware module, which is called to scan the object runs with<br />

the <strong>Gateway</strong> Antimalware settings, as specified with the property. These settings let the module<br />

use all its three submodules and their methods to scan web objects.<br />

If the module finds that a web object is infected, processing of all rules stops and the object is not<br />

passed on any further. Access to it is blocked this way. In a request cycle, the infected web object<br />

is not passed on to the web. In the response and embedded object cycles, it is not passed on to<br />

the user who requested it.<br />

The action settings specify a message to the requesting user.<br />

The rule also uses an event to count blocking due to virus and malware infections. The event<br />

parameters specify the counter that is incremented and the size of the increment. The event<br />

settings specify the settings of the Statistics module, which executes the counting.<br />

176 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!