Threat Search Components

Component

Description

Scanner

Component that performs scanning of file system objects (files, directories and boot records) for threats on user demand or on schedule. The user can start scanning either in graphical mode or in command line mode.

GNU/Linux File System Monitor.

Operates in background mode and controls file operations (such as creation, opening, closing, running) in GNU/Linux file systems. It sends the Dr.Web File Checker component requests to scan new or modified files as well as executables of programs when they are run.

Depending on OS features, uses the fanotify system mechanism or a custom kernel module developed by the Doctor Web company (LKM is supplied with SpIDer Guard as a separate package). When the fanotify system mechanism is used, the monitor can operate in enhanced or “paranoid” mode, blocking access to the files that have not been scanned yet until the scan is complete. By default, a regular monitoring mode is enabled.

The component is supplied only with the distributions designed for GNU/Linux OSes.


Executable file: drweb-spider.

Logged internal name: LinuxSpider

Linux loadable kernel module for SpIDer Guard

Linux loadable kernel module (LKM) used by SpIDer Guard to have access to file system events in some operating systems, where fanotify API is unavailable or implemented with limited functionality.

The component is distributed both as a binary (for a set of operation systems where fanotify is not implemented or is unavailable) and as source code allowing to build and install the operating system kernel module manually (for the instruction, refer to the Appendix F. Building Kernel Module for SpIDer Guard section).

The component is supplied only with the distributions designed for GNU/Linux OSes.

The loadable kernel module is not supported for architectures ARM64, E2K and IBM POWER (ppc64el).


Executable file: drweb.ko

Component for monitoring network traffic and URLs.

It is designed to scan data downloaded from the network to the local host and passed from it to the external network for threats. The component also prevents connections with the network hosts added to the unwanted categories of web resources or black lists created by the user.

Uses the Dr.Web Network Checker component to scan received data.

Sends files downloaded from the internet (from the servers access to which is not restricted) to Scanner and blocks downloading them if they contain threats.

If allowed by the user, sends requested URLs to the Dr.Web Cloud service for scanning.


Executable file: drweb-gated.

Logged internal name: GateD

Network connection monitor.

Used by SpIDer Gate and provides connection routing for applications that operate on a host to scan traffic of these connections.


Executable file: drweb-firewall.

Logged internal name: LinuxFirewall

Component for scanning email messages.

Analyzes email messages and prepares them for scanning for threats. It can operate in two modes.

1)Filter for mail servers (Sendmail, Postfix, and so on) connected via the Milter interface, Spamd or Rspamd interfaces.

2)Transparent proxy of email protocols (SMTP, POP3, and IMAP). SpIDer Gate is used in this mode.

Uses the Dr.Web Network Checker component to scan data extracted from email messages


Executable file: drweb-maild.

Logged internal name: MailD

Component for scanning email messages for signs of spam.

Used by the Dr.Web MailD component. Can be unavailable depending on distribution. If it is unavailable, scanning email messages for sings of spam is not performed by the Dr.Web MailD component.

The component is not supported for ARM64, E2K and IBM POWER (ppc64el) architectures.


Executable file: drweb-ase.

Logged internal name: Antispam