Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Anti-Malware Profile

Want to summarize with AI?

Log in

Learn how an Anti-Malware Profile scans incoming data for viruses, ransomware, and other malicious threats before they can infect protected systems.


An anti-malware profile prevents malware attacks by scanning all incoming data to prevent malware from being installed and infecting a computer. Anti-malware programs can also detect advanced forms of malware and offer protection against ransomware attacks. Currently, the Talos ClamAV virus detection engine is a large portion of the profile. ClamAV® is an antivirus engine for detecting trojans, viruses, malware and other malicious threats.

The current version of ClamAV in use is 1.4.

If you opt to create an anti-malware profile, we strongly recommend immediately adding it to a policy by configuring it to a rule.


Create an Anti-Malware Profile

Procedure

1.

Navigate to Policies > Profiles > Anti Malware.

2.

Select Anti-malware.

3.

Provide a unique Name and enter a description.

4.

Select one of the following modes for Talos ruleset:

  • Manual Mode - select the Talos Ruleset Version from dropdown. The selected ruleset version is used by the Multicloud Defense datapath engine on all Gateways which use this profile and is not automatically updated to newer ruleset versions.

  • Automatic Mode - select how many days to delay the deployment by, after the ruleset version is published by Multicloud Defense. New rulesets are published daily by Multicloud Defense and the gateways using this profile are automatically updated to the latest ruleset version which is N days or older, where N is the "delay by days" argument selected from the dropdown. For example, if you select to delay the deployment by 5 days on Jan 10, 2024, the Multicloud Defense Controller will select a ruleset version which was published on Jan 5th or before. Note that Multicloud Defense may not publish on certain days if internal testing with that ruleset version fails.

5.

Select the desired Action to take when a match for a virus signature is found.

What to do next

Attach the profile to a policy rule set. See Rule Sets and Rule Set Groups for more information.