Discussion:
Amavis and anti-virus engine ?
(too old to reply)
Olivier CALVANO
2016-02-23 10:54:54 UTC
Permalink
Hi

what is the best antivirus engine for postfix/amavis ?

Because with clamav, we have a big quantity of crypto locker into our mail.
We run on CentOS 7


Thanks for your help
regards
Olivier
Patrick Ben Koetter
2016-02-23 18:50:25 UTC
Permalink
Post by Olivier CALVANO
what is the best antivirus engine for postfix/amavis ?
Because with clamav, we have a big quantity of crypto locker into our mail.
We run on CentOS 7
Good engines, which we have used in the past and would recommend are:

- Avira SAVAPI
- avast!
- Sophos

Reasons we think they are good:

- Fast
- Efficient
- Low False-Positive rate
- Low impact on system (they don't install a pletora of additional software)
- Good support

We tested and used others as well, but to they were crappy, instable and/or
the vendor left the UNIX market. Some didn't seem to be trustworthy enough to
let them handle our customers data.

You might want to check http://www.av-comparatives.org/ for regular surveys.

***@rick
--
[*] sys4 AG

https://sys4.de, +49 (89) 30 90 46 64
Franziskanerstraße 15, 81669 München

Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263
Vorstand: Patrick Ben Koetter, Marc Schiffbauer
Aufsichtsratsvorsitzender: Florian Kirstein
Per-Erik Persson
2016-02-23 18:58:59 UTC
Permalink
Has anyone tried a recent clamav with YARA support and ya
Jakob Curdes
2016-02-23 20:14:30 UTC
Permalink
As far as I know, Avira has also discontinued their linux product.
We have augmented clamav with the sanesecurity signatures.
I just read about the interesting YARA project and am looking into
adding these rules also.

Also we block .js and the old microsoft office formats.

Up to now this seems to work quite well, we do not see anything relevant
get through.
On our customer's mail servers we partly run the kaspersky mail scanner
which works very well.

HTH, Jakob
Post by Patrick Ben Koetter
Post by Olivier CALVANO
what is the best antivirus engine for postfix/amavis ?
Because with clamav, we have a big quantity of crypto locker into our mail.
We run on CentOS 7
- Avira SAVAPI
- avast!
- Sophos
- Fast
- Efficient
- Low False-Positive rate
- Low impact on system (they don't install a pletora of additional software)
- Good support
We tested and used others as well, but to they were crappy, instable and/or
the vendor left the UNIX market. Some didn't seem to be trustworthy enough to
let them handle our customers data.
You might want to check http://www.av-comparatives.org/ for regular surveys.
Patrick Ben Koetter
2016-02-23 20:26:39 UTC
Permalink
Post by Jakob Curdes
As far as I know, Avira has also discontinued their linux product.
The scan engine is still available to system integrators. We are one of those
and like the other integrators we add some magic sauce [tm] and wrap the
engine into a product of our own.
Post by Jakob Curdes
We have augmented clamav with the sanesecurity signatures.
I just read about the interesting YARA project and am looking into
adding these rules also.
Also we block .js and the old microsoft office formats.
Up to now this seems to work quite well, we do not see anything
relevant get through.
ACK
Post by Jakob Curdes
On our customer's mail servers we partly run the kaspersky mail
scanner which works very well.
HTH, Jakob
Post by Patrick Ben Koetter
Post by Olivier CALVANO
what is the best antivirus engine for postfix/amavis ?
Because with clamav, we have a big quantity of crypto locker into our mail.
We run on CentOS 7
- Avira SAVAPI
- avast!
- Sophos
- Fast
- Efficient
- Low False-Positive rate
- Low impact on system (they don't install a pletora of additional software)
- Good support
We tested and used others as well, but to they were crappy, instable and/or
the vendor left the UNIX market. Some didn't seem to be trustworthy enough to
let them handle our customers data.
You might want to check http://www.av-comparatives.org/ for regular surveys.
--
[*] sys4 AG

https://sys4.de, +49 (89) 30 90 46 64
Franziskanerstraße 15, 81669 München

Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263
Vorstand: Patrick Ben Koetter, Marc Schiffbauer
Aufsichtsratsvorsitzender: Florian Kirstein
Tom Hendrikx
2016-02-23 20:44:50 UTC
Permalink
Post by Patrick Ben Koetter
Post by Jakob Curdes
As far as I know, Avira has also discontinued their linux
product.
The scan engine is still available to system integrators. We are
one of those and like the other integrators we add some magic sauce
[tm] and wrap the engine into a product of our own.
The Avira Antivir product was indeed discontinued [1], but the SAVAPI
engine [2] is not. This is what Patrick is pointing at.

[1]
https://www.avira.com/en/support-for-home-knowledgebase-detail/kbid/1491
v
[2] https://www.avira.com/en/oem-antivirus
Post by Patrick Ben Koetter
Post by Jakob Curdes
We have augmented clamav with the sanesecurity signatures. I just
read about the interesting YARA project and am looking into
adding these rules also.
Also we block .js and the old microsoft office formats.
Up to now this seems to work quite well, we do not see anything
relevant get through.
ACK
Post by Jakob Curdes
On our customer's mail servers we partly run the kaspersky mail
scanner which works very well.
HTH, Jakob
Post by Patrick Ben Koetter
Post by Olivier CALVANO
what is the best antivirus engine for postfix/amavis ?
Because with clamav, we have a big quantity of crypto locker
into our mail. We run on CentOS 7
Good engines, which we have used in the past and would
- Avira SAVAPI - avast! - Sophos
- Fast - Efficient - Low False-Positive rate - Low impact on
system (they don't install a pletora of additional software) -
Good support
We tested and used others as well, but to they were crappy,
instable and/or the vendor left the UNIX market. Some didn't
seem to be trustworthy enough to let them handle our customers
data.
You might want to check http://www.av-comparatives.org/ for
regular surveys.
Jakob Curdes
2016-02-23 21:00:53 UTC
Permalink
Yes but for the general audience this does not help very much...
JC
Jakob Curdes
2016-02-23 22:09:57 UTC
Permalink
Has anyone tried a recent clamav with YARA support and yara-rules available?
I have just played around with yara but you need to be careful and
read/understand each rule before dropping it into the clamav DB directory.
There are rules that mark each mail without image and another marks each
mail with an image. Clamav will detect this as infection and so will
declare every single mail as infected.....

JC
Olivier Nicole
2016-02-24 02:44:43 UTC
Permalink
Hi,

I am using Kaspersky (on FreeBSD)

Olivier
--
Patrick Ben Koetter
2016-02-24 07:41:36 UTC
Permalink
Post by Jakob Curdes
Yes but for the general audience this does not help very much...
There are quite a few vendors where you can buy a scanner based on SAVAPI like
any other regular product. I think it just isn't well known that such products
are out there and that anyone can buy them.

***@rick
--
[*] sys4 AG

https://sys4.de, +49 (89) 30 90 46 64
Franziskanerstraße 15, 81669 München

Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263
Vorstand: Patrick Ben Koetter, Marc Schiffbauer
Aufsichtsratsvorsitzender: Florian Kirstein
Olivier Nicole
2016-02-24 07:34:35 UTC
Permalink
Has anyone tried a recent clamav with YARA support and yara-rules available?
But why not using yara as yet another anti-virus directly in Amavis?

Best regards,

Olivier

--
Jakob Curdes
2016-02-24 08:07:11 UTC
Permalink
Post by Patrick Ben Koetter
Post by Jakob Curdes
Yes but for the general audience this does not help very much...
There are quite a few vendors where you can buy a scanner based on SAVAPI like
any other regular product. I think it just isn't well known that such products
are out there and that anyone can buy them.
Can you give a hint !? I am interested, but I asked Avira and they said
they do not support Linux any more.
JC
Patrick Ben Koetter
2016-02-24 08:06:02 UTC
Permalink
Post by Jakob Curdes
Post by Patrick Ben Koetter
Post by Jakob Curdes
Yes but for the general audience this does not help very much...
There are quite a few vendors where you can buy a scanner based on SAVAPI like
any other regular product. I think it just isn't well known that such products
are out there and that anyone can buy them.
Can you give a hint !? I am interested, but I asked Avira and they
said they do not support Linux any more.
Avira licenses per user. You can send me the number of mailboxes you need to
protect and I can send you a quote.

***@rick
--
[*] sys4 AG

https://sys4.de, +49 (89) 30 90 46 64
Franziskanerstraße 15, 81669 München

Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263
Vorstand: Patrick Ben Koetter, Marc Schiffbauer
Aufsichtsratsvorsitzender: Florian Kirstein
Loading...