Dr.Web for UNIX Internet Gateways Components

For UNIX Internet gateways protection, the following anti-virus components are provided:

General Components

Dr.Web ICAPD

ICAP server analysing requests and traffic which goes via HTTP proxy servers (such as Squid). It also prevents transmitting infected files and access to the network hosts belonging to the Internet resources categories and to black lists, created by the system administrator. If access to external servers must be forbidden, or transmitted data contains a threat, it instructs the proxy server to return to a user a special page informing that it is impossible to access the requested resource or that the transmitted file is infected.

Core component of Dr.Web for UNIX Internet Gateways program complex. Allows to integrate it with HTTP/FTP-proxy server using ICAP protocol (usually this is server under protection that provides access to the Internet for LAN workstations).

SpIDer Gate

The component which works in resident mode and monitors all network connections. Provides protection for a company's public web server.

It checks whether the requested URL falls into the unwanted category of web resources or in the user’s black list, and, if so, blocks access to the resource.

Also it checks files uploading from the Internet to server under protection and blocks their uploading if they contain threats.

Dr.Web Console Scanner (can be managed on station only)

Provides detection and neutralisation of viruses on the local machine. Managed via the console command line.

Dr.Web ClamD

Component emulating interface of the anti-virus daemon clamd, which is a component of ClamAV® anti-virus. Allows all applications that support ClamAV® to transparently use Dr.Web for UNIX Internet Gateways for anti-virus scanning.

Quarantine

Isolates malicious and suspicious objects in the special folder.

info

Files on the workstation can be quarantined by Console Scanner only.

 

Description of how to manage Quarantine via the Control Center you can find in the Administrator Manual.

Auxiliary Components

Dr.Web Agent for UNIX

The component is used for interaction between Dr.Web for UNIX Internet Gateways installed on the station and Dr.Web Enterprise Security Suite.

File Checker

The component is used by Console Scanner for checking files in Scanning Engine and for managing Quarantine.

Network Checker

The component is used to send data to the Scanning Engine for actual scanning. It is used by general components to check data transmitted over the network.

Scanning Engine

The component is used by File Checker and Network Checker for anti-virus scan and virus databases managing.

SNMP Agent

The component is designed for integration of Dr.Web for UNIX Internet Gateways with external monitoring systems over the SNMP protocol.

Dr.Web ConfigD

The component that coordinates operation of all Dr.Web for UNIX Internet Gateways components.

Dr.Web CloudD

The component that sends the following information to the Dr.Web Cloud service: visited URLs and information about the scanned files, to check them for threats not yet described in virus databases.

Dr.Web LookupD

Component retrieving data from external data sources (directory services, such as Active Directory) using LDAP protocol. The data are used in rules of traffic monitoring.

Dr.Web HTTPD

Web server for managing Dr.Web for UNIX Internet Gateways components. It provides the management web interface for product installed on the station.