Threat Search Components

Component

Description

GNU/Linux File System Monitor.

Operates in background mode and controls file operations (such as creation, opening, closing, running) in GNU/Linux file systems. It sends the Dr.Web File Checker component requests to scan new or modified files as well as executables of programs when they are run.

Depending on OS features, uses the fanotify system mechanism or a custom kernel module developed by the Doctor Web company (LKM is supplied with SpIDer Guard as a separate package). When the fanotify system mechanism is used, the monitor can operate in enhanced or “paranoid” mode, blocking access to the files that have not been scanned yet until the scan is complete. By default, a regular monitoring mode is enabled.

The component is supplied only with the distributions designed for GNU/Linux OSes.


Executable file: drweb-spider.

Logged internal name: LinuxSpider

Linux loadable kernel module for SpIDer Guard

Linux loadable kernel module (LKM) used by SpIDer Guard to have access to file system events in some operating systems, where fanotify API is unavailable or implemented with limited functionality.

The component is distributed both as a binary (for a set of operation systems where fanotify is not implemented or is unavailable) and as source code allowing to build and install the operating system kernel module manually (for the instruction, refer to the Use of the Kernel Module for SpIDer Guard section).

The component is supplied only with the distributions designed for GNU/Linux OSes.

The loadable kernel module is not supported for architectures ARM64, E2K and IBM POWER (ppc64el).


Executable file: drweb.ko

Samba shared directory monitor.

Operates in a background mode and monitors file system operations (such as creating, opening, closing, read and write operations) in directories selected as the Samba SMB server file storage. Sends requests for scanning of new and modified files to the Dr.Web File Checker component.

For integration with the file server uses VFS SMB modules that operate on the Samba server side


Executable file: drweb-smbspider-daemon.

Logged internal name: SMBSpider

NSS (Novell Storage Services) volume monitor.

Operates in a background mode and monitors file system operations (such as creation, opening, closing and write operations) on NSS volumes mounted on the file system. Sends requests for scanning new and modified files to the Dr.Web File Checker component.

The component is supplied only with the distributions designed for GNU/Linux OSes. Can operate only on Novell Open Enterprise Server SP2 based on SUSE Linux Enterprise Server 10 SP3 and later.


Executable file: drweb-nss.

Logged internal name: NSS