{"id":900,"date":"2013-01-23T07:14:21","date_gmt":"2013-01-23T15:14:21","guid":{"rendered":"https:\/\/thebeagle.itgroove.net\/?p=900"},"modified":"2023-02-24T21:48:51","modified_gmt":"2023-02-24T21:48:51","slug":"multi-level-anti-virus","status":"publish","type":"post","link":"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/","title":{"rendered":"Multi-level anti-virus"},"content":{"rendered":"<p>No, this is not an article about weird marketing practices or \u201cponzi\u201d schemes within the A\/V industry.&nbsp; It IS an article about how you can better protect yourself against viruses and malware.&nbsp; I decided to write this after one of our customers had the willies scared out of them by one of their other vendor\u2019s \u201csecurity alert\u201d circular.<\/p>\n<p>We (itgroove) have always worked from the assumption that no single a\/v product provides 100% protection against all virus and malware threats.&nbsp; The A\/V vendors may take issue with that stance but it\u2019s what we believe and it sets the tone for how we architect customer\u2019s infrastructures.&nbsp; We always \u201clayer\u201d A\/V protection so that there are at least two layers of scanning using multiple vendors technologies.&nbsp; Our preferred architecture relies on Sonicwall firewalls with Sonicwall\u2019s McAfee-based technology scanning at the gateway (firewall) and Trend Micro\u2019s A\/V installed on all machines on the inside LAN (usually WFBS).&nbsp; If the customer utilizes Office365 that adds another layer as Forefront is scanning at the Exchange level (on premise Exchange&nbsp; is covered by the aforementioned Trend A\/V).<\/p>\n<p>The reason we layer is simple:&nbsp; chances are if one vendor\u2019s technology misses or does not identify and eliminate a virus or malware the other vendor\u2019s will.&nbsp; It is a simple numbers game where you have better protection if your \u201clayer number\u201d is 2 or greater.&nbsp; Single vendor solutions such as Sonicwall\u2019s Gateway A\/V and Enforced Client A\/V (to name but one) can leave you vulnerable as the same technology is in place at the gateway and on the LAN; if the technology does not identify a virus or malware then it misses it entirely throughout your infrastructure.&nbsp; (To be fair to Sonicwall, they do offer Kaspersky as an optional layer.)<\/p>\n<p>I want to circle back to my point about our customer and the security circular they received.&nbsp; The circular highlighted the existence of a nasty virus that targets POS systems running on Windows boxes and was also a pitch for a \u201cmanaged\u201d single-vendor a\/v service.&nbsp; The interesting thing is the vendor provided stats from Virustotal which listed 40 different a\/v vendors and whether or not their product identified and removes this particular virus.&nbsp; Roughly half of the vendors missed identifying the virus.&nbsp; Using our two preferred vendors as a measuring stick, Sonicwall (McAfee) missed and TrendMicro identified\/removed.&nbsp; If our customer\u2019s network had ONLY been protected by McAfee they could have been at risk but they have the second layer in place.&nbsp; Of course, the possibility exists that BOTH layers could miss something but the odds are much more in your favour with two layers than with a single layer.<\/p>\n<p>If your network is only covered by a single layer of a\/v then I urge you to look into how you can add a second layer from another vendor.&nbsp; There are many, many options available and you don\u2019t have to use our particular model.&nbsp; But you <em>should<\/em> do something.&nbsp; You <em>should<\/em> scan at the gateway as the best defence is to keep the garbage out of your network, period; specially so in this age of BYOD on your network.&nbsp; You <em>should <\/em>ensure your various devices on the LAN are covered with a\/v.&nbsp; You <em>should <\/em>ensure your mobile users have a\/v that ramps things up when they are NOT behind your corporate firewalls.&nbsp; And you <em>should <\/em>pay attention to what your various a\/v dashboards tell you.<\/p>\n<p>We have a lot of customers set up with the multi-layer approach and it works extremely well.&nbsp; It can work well for you, too.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>No, this is not an article about weird marketing practices or \u201cponzi\u201d schemes within the A\/V industry.&nbsp; It IS an article about how you can better protect yourself against viruses and malware.&nbsp; I decided to write this after one of our customers had the willies scared out of them by one of their other vendor\u2019s &hellip; <a href=\"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/\"><\/a><\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[237],"tags":[295],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Multi-level anti-virus - Archive<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Multi-level anti-virus - Archive\" \/>\n<meta property=\"og:description\" content=\"No, this is not an article about weird marketing practices or \u201cponzi\u201d schemes within the A\/V industry.&nbsp; It IS an article about how you can better protect yourself against viruses and malware.&nbsp; I decided to write this after one of our customers had the willies scared out of them by one of their other vendor\u2019s &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/\" \/>\n<meta property=\"og:site_name\" content=\"Archive\" \/>\n<meta property=\"article:published_time\" content=\"2013-01-23T15:14:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-24T21:48:51+00:00\" \/>\n<meta name=\"author\" content=\"Sean Wallbridge\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sean Wallbridge\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/\",\"url\":\"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/\",\"name\":\"Multi-level anti-virus - Archive\",\"isPartOf\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#website\"},\"datePublished\":\"2013-01-23T15:14:21+00:00\",\"dateModified\":\"2023-02-24T21:48:51+00:00\",\"author\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\"},\"breadcrumb\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog Archive\",\"item\":\"https:\/\/regroove.ca\/archive\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Multi-level anti-virus\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/regroove.ca\/archive\/#website\",\"url\":\"https:\/\/regroove.ca\/archive\/\",\"name\":\"Archive\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/regroove.ca\/archive\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\",\"name\":\"Sean Wallbridge\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"caption\":\"Sean Wallbridge\"},\"url\":\"https:\/\/regroove.ca\/archive\/author\/swallbridge\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Multi-level anti-virus - Archive","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/","og_locale":"en_US","og_type":"article","og_title":"Multi-level anti-virus - Archive","og_description":"No, this is not an article about weird marketing practices or \u201cponzi\u201d schemes within the A\/V industry.&nbsp; It IS an article about how you can better protect yourself against viruses and malware.&nbsp; I decided to write this after one of our customers had the willies scared out of them by one of their other vendor\u2019s &hellip;","og_url":"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/","og_site_name":"Archive","article_published_time":"2013-01-23T15:14:21+00:00","article_modified_time":"2023-02-24T21:48:51+00:00","author":"Sean Wallbridge","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sean Wallbridge","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/","url":"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/","name":"Multi-level anti-virus - Archive","isPartOf":{"@id":"https:\/\/regroove.ca\/archive\/#website"},"datePublished":"2013-01-23T15:14:21+00:00","dateModified":"2023-02-24T21:48:51+00:00","author":{"@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77"},"breadcrumb":{"@id":"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/regroove.ca\/archive\/2013\/01\/23\/multi-level-anti-virus\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog Archive","item":"https:\/\/regroove.ca\/archive\/"},{"@type":"ListItem","position":2,"name":"Multi-level anti-virus"}]},{"@type":"WebSite","@id":"https:\/\/regroove.ca\/archive\/#website","url":"https:\/\/regroove.ca\/archive\/","name":"Archive","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/regroove.ca\/archive\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77","name":"Sean Wallbridge","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","caption":"Sean Wallbridge"},"url":"https:\/\/regroove.ca\/archive\/author\/swallbridge\/"}]}},"_links":{"self":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/900"}],"collection":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/comments?post=900"}],"version-history":[{"count":1,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/900\/revisions"}],"predecessor-version":[{"id":3030,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/900\/revisions\/3030"}],"wp:attachment":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/media?parent=900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/categories?post=900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/tags?post=900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}