Stopping malware at the gateway: challenges and solutions

Martin Stecher Secure Computing

  download slides (PDF)

Anti-malware scanning at a gateway has different requirements than anti-malware scanning at a client or server.

Some aspects become simpler (e.g. no on-access scanning, false positives are less dramatic) while new challenges are introduced (e.g. latency, chunk-by-chunk scanning, streaming, more important scanning of archives and office document formats). The default behaviour for some corner cases should be different (what to do if an archive is nested too often or the archive is encrypted). Common pitfalls should be avoided when moving an engine from the client to the gateway such as bypassing certain filetypes by name or media type.

The deployment at the gateway also offers the chance to combine more prevention techniques with classic anti-malware; by watermarking form data for example, legitimate posting of data can be distinguished from data that spyware wants to send to its server.

Which protocols should be handled by a gateway? Is SSL scanning possible and needed? Can callout protocols such as ICAP or OCP help to write an application agnostic scanner that works in all environments? How would tests such as the VB100 need to change so that gateway anti-malware products can participate?

Quick Links



Poll

When do you install software updates?
As soon as they are released
As soon as I have some time
I take my time, but I always install them eventually
Only when I feel it is absolutely necessary
Never
Leave a comment
View 12 comments

Jobs Career Sidebar

Twitter Feed

virusbtn: September VB issue: LNK files, anti-unpacker, sender authentication, VBSpam review and more http://bit.ly/987AOC
5 hours ago


virusbtn: The VBSpam quadrant plots anti-spam products spam catch rates against false positive rates. Latest update at http://bit.ly/a2Ppcs
10 hours ago


Virus Bulletin

In this month's magazine:
  • VB100 – Windows Vista Business Edition Service Pack 2
  • Apple pie order?
  • Anti-unpacker tricks – part eleven
  • Advanced exploit framework lab set-up
  • HTML structure-based proactive phishing detection
  • What’s the deal with sender authentication? Part 3
Virus Bulletin 08 2010
Subscribe now!
Virus Bulletin currently has 208,638 registered users.