![]() | |
| HomeStoreNewsProductsPricingSupportInstallationsCorporateContact ASTi | |
|
ASTi Application Note 73: McAfee's Linux Command Line Scanner For Telestra 3/MBV
Introduction
ASTi has tested and certified the McAfee VirusScan Command Line Scanner to protect its Linux-based Telestra 3 / MBV platform from viruses, and to comply with growing security requirements at DoD installation sites. This application offers advanced virus-scanning technology in a UNIX environment.
RequirementsAccess to the Telestra System
This procedure requires you to log into the Telestra with a system-level user account, and gain super user (root) privileges. This means that you must:
Scanner Software
ASTi does not provide the McAfee VirusScan Command Line Scanner software and license, but recommends obtaining it from Softmart. Softmart is an authorized McAfee reseller, and provides the licensed software for download after purchase.
For more information see the following websites:
McAfee VirusScan Command Line Scanner http://www.softmart.com/ (search for "McAfee VirusScan Command Line Scanner Standard") Latest Virus Definitions
Virus scanning software is only as effective as its latest virus definitions allow. As such, you should download the latest virus definitions from McAfee, which can be found at:
http://www.mcafee.com/apps/downloads/security_updates/dat.asp ftp://ftp.mcafee.com/pub/antivirus/datfiles/4.x
To protect against new threats as they arise, ASTi recommends updating the virus definition (.dat) files regularly.
Software Installation
If you have already installed the McAfee VirusScan Command Line Scanner on your Telestra system, and simply wish to update your virus definitions, please skip to the "Updating Virus Definitions" section below, which duplicates a portion of these instructions.
Since most MBV installations do not have direct access to the Internet, ASTi recommends downloading the application and the latest virus definitions (.dat files) to a remote computer with Internet access, and then burning these files onto a CD-ROM. After burning the CD-ROM, insert it into the Telestra's optical drive, and follow the installation instructions below.
Note: Detailed installation instructions can also be found on McAfee's Web site.
Log into the Telestra system using your system-level user account. From the terminal, type and enter each of the commands shown below. If you are asked a question by the system during the installation, press the Enter key to accept its default answer.
At this point, the initial installation is complete.
Now, update the Scanner's virus definitions.
Performing a Virus Scan
WARNING: Running the Command Line Scanner adds a significant CPU load to the Telestra system. DO NOT run a scan while running a model or during a comms exercise or live training.
Due to restrictions placed upon system-level users by way of Linux permissions, ASTi recommends that all scans be initiated by the root (super) user.
To start a scan, you will use the Linux command uvscan.
Here is an example of the command used to start a scan:
uvscan -rv --summary /usr/local/astiIn the above command:
Other Command Options
To view a complete list of uvscan options and how to use them, enter:
man uvscanUse the arrow keys to navigate through the manual page; when you are finished, press "q" to exit.
These command options are also available in the PDF document included in the original TAR archive (vlp[xxxx].tar.Z); look for a file named e[xxxx]upg.pdf. Again, replace the [xxxx] with the software's version number.
Scanning a Security-Hardened Telestra
If you have applied ASTi's STIG Security package to the Telestra 3 / MBV platform, system-level users will be automatically logged out of the system after 15 minutes of idle time. Further, all that user's processes (including a scan) will be halted.
Scanning the entire Telestra file system, however, will take well over 15 minutes to complete. The following example command will allow you to initiate the scan, have it run for as long as needed, and write its output to a text file for later review.
nohup uvscan -rv --summary / > uvscan_log.txtIn the above command:
Updating Virus Definitions
Important: Follow this procedure only if you have already installed the VirusScan Command Line Scanner software on your Telestra system.
|
|
| HomeStoreNewsProductsPricingSupportInstallationsCorporateContact ASTi | |
| Copyright 1997-2008 ASTi | Legal Stuff | |