
FAQ
2.4
Hands-on
G
19
2
ZyWALL UTM Solution
Hands-on
G01. Are the signature database in Kasperky's Anti-Virus software and
ZyWALL Anti-Virus different?
Yes. The two virus signature databases are different.
The signatures in ZyWALL's virus database are carefully selected and updated. The reasons for doing
this are:
Increased performance and efficiency
Reduced database size with no virus patterns that are very old.
Lowered false-positive rate
For ZyNOS v4.00, the signatures are chosen and delivered to ZyXEL by Kaspersky so that our Anti-
Virus subscribers can always keep their virus signatures updated.
G02. For the signature database in ZyNOS v4.00, what are the criteria for
selecting those signatures out of the complete Kaspersky signature
database?
The signatures for ZyNOS v4.00 chosen by Kaspersky are based on the following criteria:
I. Active (In the Wild):
The complete Kaspersky's signature database contains over 130K of virus patterns. However, not
all of them are relevant in today's virus threats. Thus viruses are classified as in the "zoo" and "in
the wild". Viruses in the "zoo" are almost non-existent and listed in the database for precautionary
reasons. The most important ones are classified "in the wild" (http://www.wildlist.org), viruses in
this group are "active", and should be taken care of more carefully. According to Kaspersky, the
number of viruses in the "zoo" is over 120K. Thus these are the ones that we need to address.
II. Infectious through networks:
Not all viruses are spread via networks. Some only infect the host that executed the virus code
(host-based) but will not spread to other hosts on the network. Since our product is aimed to
deliver gateway Anti-Virus protection, we focus on those viruses which can be spread via networks
instead of those host-based viruses.
III. Top 20 of Kaspersly Anti-Virus Database:
Kaspersky always updates the top 20 in their signature database. This is also included in ZyXEL's
signature updates.
Based on the above criteria, Kaskersky helps screen the list of important virus signatures (between 1K
to 1.5K) for the ZyWALL devices and sets the update priority to the selected signatures. After the list is
chosen and updated, Kaspersky sents the update to ZyXEL. Thus, for a gateway Anti-Virus solution,
what matters is not how old the virus signature is but whether the virus is active or not and the
G
Comentarios a estos manuales