- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-02-2010 05:43 AM
For data filtering we set a rule to alert for certain downloads (such as .bat, .exe, etc). In the monitor log, all alerts are listed as LOW severity. I have noticed a pattern where a workstation shows a suspicious download such as game.exe or abyzdew.exe (random letters in name) and then starts showing outbound spyware or virus messages. My deduction is the download was some type of malware.
Is there a way to have the files being downloaded scanned for malware and alerted in the data filter tab? What is the purpose of the severity column in the data filtering tab as it relates to the "FILE" type of data filter and why does it always show as low.
Thanks.
Crill
11-02-2010 10:54 AM
>For data filtering we set a rule to alert for certain downloads (such as .bat, .exe, etc). In the monitor log, all alerts are listed as LOW >severity. I have noticed a pattern where a workstation shows a suspicious download such as game.exe or abyzdew.exe (random letters >in name) and then starts showing outbound spyware or virus messages. My deduction is the download was some type of malware.
>Is there a way to have the files being downloaded scanned for malware and alerted in the data filter tab? What is the purpose of the
Downloaded files will be scanned for malware through antivirus profile (Objects->Security Profiles -> Antivirus). Corresponding logs are generated in 'Threat' Log. If you click on the log, it will also show corresponding logs for the 'same' session from different log databases e.g, if a file blocking profile also got triggered on the file, you will see that log when you click on the virus log in the threat log.
>severity column in the data filtering tab as it relates to the "FILE" type of data filter and why does it always show as low.
Currently, all file blocking logs show up as 'low' severity. Let me know if you have some suggestions on how you would like to see this in a future release (Also, please work through your Sales Engineer/Reseller to have them open a feature request for better tracking).
Let me know if you have any further questions,
Thanks,
Sandeep
>Thanks.
>Crill
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!