Threat Search Components

Component

Description

ICAP server analyzing requests and network traffic passing through HTTP proxies supporting ICAP (such as Squid).

It prevents transferring infected files and accessing network hosts belonging to unwanted categories of internet resources or added to black lists created by the system administrator. If the access to external servers is forbidden or transmitted data contains a threat, the proxy server is instructed to return to the user a special page informing that it is impossible to access the requested resource or download the infected file.

Uses Dr.Web Network Checker to scan data received from a proxy server


Executable file: drweb-icapd.

Logged internal name: ICAPD

Component for monitoring network traffic and URLs.

It is designed to scan data downloaded from the network to the local host and passed from it to the external network for threats. The component also prevents connections with the network hosts added to the unwanted categories of web resources or black lists created by the system administrator.

Uses the Dr.Web Network Checker component to scan received data.

If allowed by the user, sends requested URLs to the Dr.Web Cloud service for scanning.

The component is supplied only with the distributions designed for GNU/Linux OSes.


Executable file: drweb-gated.

Logged internal name: GateD

Network connection monitor.

Used by SpIDer Gate and provides connection routing for applications that operate on a host to scan traffic of these connections.

The component is supplied only with the distributions designed for GNU/Linux OSes.


Executable file: drweb-firewall.

Logged internal name: LinuxFirewall