F-Secure and email scan, I look for info.

A

Adriano

Hi,
in F-Secure I have enable email scan but I have noticed it slow down a
lot the incoming emails. Yet when I used AVG Pro everithing was
faster. With AVG also I had enabled email scan.
Why?
Another question please:
IN "Scan in realtime" is it better enable "automatically disinfect" or
"automatically delete"?
Thanks

bye Adriano
 
J

Jeffrey A. Setaro

Hi,
in F-Secure I have enable email scan but I have noticed it slow down a
lot the incoming emails. Yet when I used AVG Pro everithing was
faster. With AVG also I had enabled email scan.
Why?

F-Secure's email scanner works at the protocol level and scans e-mail
messages as they are downloaded. Unfortunately it can increase
download time by about 40 percent on large messages.
Another question please:
IN "Scan in realtime" is it better enable "automatically disinfect" or
"automatically delete"?

Neither... "Ask after scan" is your best bet. NEVER let an anti-virus
program automatically disinfect or delete anything. Doing so could
unfortunate results in the event of a false positive.
Thanks

bye Adriano

Cheers-

Jeff Setaro
jasetaro@SPAM_ME_NOT_mags.net
http://people.mags.net/jasetaro/
PGP Key IDs DH/DSS: 0x5D41429D RSA: 0x599D2A99 New RSA: 0xA19EBD34
 
T

Tamas Feher

Dear Sirs,
F-Secure enable email scan but noticed it slow down

The built-in e-mail scanning in F-Secure Client Security 5.5x uses a
novel method that is very different from the usual.

NortonAV and most other competitors use a local-proxy based approach to
e-mail (SMTP/POP3) virus scanning. This is vulnerable, because malware
with built-in SMTP engine can circumvent it. But it offers greater
flexibility in port configuration and is not performance critical.

F-Secure's solution uses a trick involving the DFW personal firewall
component of the FSAVCS software. They are essentially slicing the
network interface card NDIS driver layer in half and insert a data pump
in between the parts. The pump sucks all port 25 and port 110 traffic
out and feeds it into the virus scanning core. This method cannot be
circumvented, as long as the AV is running. But it is not possible to
change the ports (you cannot use e-mail scanning with an SMTP server on
port 26 or access POP3 running on port 109).

Besides these issues, the solution is also performance critical, because
actions are not acknowledged until all AV scanning is done, sometimes
leading to timeouts, etc. Large size e-mails with packed attachments or
a slow link (e.g. 56kbps analogue modem) can lead to problems. Some
fixes have been implemented in the latest version. Please use the FSAVCS
5.52 SR1, available here:
ftp://ftp.f-secure.com/support/hotfix/fsavcs/avcs_5.52-10130-sr1.zip

Sincerely: Tamas Feher from Hungary.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top