LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-10-2003, 04:43 AM   #1
hrr
LQ Newbie
 
Registered: Feb 2003
Location: Sweeden
Distribution: Debian
Posts: 6

Rep: Reputation: Disabled
Question How to build an antivirus web proxy


Hi all

I am currently researching the possibility of setting up an antivirus scanning web proxy based on linux (clients on the network use this proxy and have all there web, ftp etc. scanned for virus before it reaches the client).

So far I haven't really found any clearcut solutions.

I imagine using a commercial antivirus product, but does anyone have any experience combining such with, say, squid or something?

Are there other ways to do this I should consider?

Or is this basically a project best left for the Windows world where full vendorsupported solutions already exist?

Regards,
Henning
 
Old 04-12-2003, 08:21 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
So far I haven't really found any clearcut solutions.
Possibly because there is not a significant threat or no (commercial) interest to develop such products.

SMTP can be done on a server, but IMO HTTP and FTP scanning is best left to clientside apps. You could use a signature-based scanner like Snort in front of the proxy tho, and have it drop connections but you'll have to tune the rulesets for false positives.
Furthermore I'd think running AV will be major CPU intensive on a large cache, and besides that what happens to the payload on a "MISS" from the cache?

Or is this basically a project best left for the Windows world where full vendorsupported solutions already exist?
Sure, as long as consumers don't want to contribute to improve existing products or push (vendors) for building new ones we can all sit together and wonder why Linux "ain't takin' over" (not that that's a valid goal). Of course, of course, it ain't your "responsability", and you haven't got the expertise and time to invest in it... All valid reasons...
 
Old 04-14-2003, 02:35 AM   #3
hardigunawan
Member
 
Registered: Dec 2001
Posts: 35

Rep: Reputation: 15
openantivirus.org has a module called squid-vscan. However, as the project status says, the scannerdaemon is lacking many features and as such not able to detect polymorphic viruses ....
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
multi web proxy lopl Linux - Networking 1 12-05-2005 04:03 AM
Setting up Debian proxy with firewall and antivirus ghanalinux Linux - Networking 1 07-02-2005 06:07 AM
proxy server antivirus solution msound Linux - Networking 2 06-02-2005 12:46 PM
how do i build a web server ? ruwach Linux - Software 5 08-09-2004 08:47 PM
MNF Web Proxy apoc63 Mandriva 2 06-08-2004 01:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration