SpIDer Guard

This component is included only in the distributions designed for the OSes of the GNU/Linux family.

The SpIDer Guard file system monitor is designed for monitoring file activity on GNU/Linux file system volumes. The component operates as a resident monitor and controls main file system events related to file modification (creating, opening, closing). When such an event is intercepted, the monitor checks whether the file was modified and, if so, the module generates a task for the Dr.Web File Checker file scanning component to scan the modified file with Dr.Web Scanning Engine.

Moreover, the SpIDer Guard file system monitor detects attempts to run executable files. If a program in an executable file is considered malicious during scanning, all processes started from this file will be forcibly terminated.

 

Details:

Operating Principles

Command-Line Arguments

Configuration Parameters

Building kernel module for SpIDer Guard

Configuring File System Monitoring