
McAfee Email Gateway
Security Target
Page 7 of 61
1.2.1 Anti-Virus
Anti-Virus Scanning -The TOE features an Anti-Virus module that provides protection from viruses and
malicious programs. This module contains the essential scanning engine used for specific scans
performed by other modules within the TOE.
Global Threat Intelligence: File Reputation - A further service is provided through use of McAfee
Global Threat Intelligence (GTI) file reputation technology. McAfee Global Threat Intelligence file
reputation is McAfee’s comprehensive, real-time, cloud-based file reputation service that enables McAfee
products to protect customers against both known and emerging malware-based threats.
Packers - Packers compress files, which changes the binary structure of the executable. Packers can
compress Trojan-horse programs and make them harder to detect. The TOE can be configured to take
specified actions on detection of specific packer use.
Potentially Unwanted Programs (including Spyware) - The Potentially Unwanted Programs (PUP)
(part of AV) utilizes the Anti-Virus Module’s PUP scanning functionality to identify PUPs, including
Spyware. PUPs can include programs intended to track network user browsing habits, establish
keylogger programs or other local tracking programs on network user computers.
1.2.2 Anti-Spam
Anti-spam - The McAfee MEG TOE provides for full scanning of email traffic through the device to
identify spam messages and Phishing attempts. This makes use of streaming updates, rules and scores,
and blacklists/whitelists.
Anti-Phishing – The Anti-Phishing module leverages the scanning functionality of the Anti-Virus module
in scanning email messages for characteristics typical of a Phishing attempt..
Global Threat Intelligence: Message Reputation - A further service is provided through use of McAfee
Global Threat Intelligence (GTI) message reputation technology. This service is applied also for spam and
phishing detection.
1.2.3 Compliance
Based on Administrator configured rules, email messages are scanned by the TOE to determine if the
content matches a restricted category or rule. Various parts of the email message may be scanned
based on Administrator preferences and Administrators may receive a message that specifies which rule
has been violated resulting in the blocking of a message. Compliance techniques include dictionary
checks, data loss prevention, and image, file and mail filtering.
1.2.4 Quarantine Management
The TOE can be configured to send an e-mail message (known as a quarantine digest) to any network
user that has quarantined e-mail messages.
1.2.5 Secure Web Delivery
The TOE provides users with a means to store and access emails securely in situations where the user’s
mail server does not provide sufficient assurance of confidentiality. Two approaches are supported for
Commenti su questo manuale