AV-suite integration

Prev Next

By default, the Intelligent Virtual Execution - Server appliance uses a DTI cloud solution to provide intelligent analysis of complete, incomplete, or corrupted network files. This feature, called AV-suite integration, uses a connection from the Intelligent Virtual Execution - Server appliance, through the Central Management System appliance, to the DTI cloud. A two-way sharing CONTENT_UPDATES license is required.

With AV-suite integration, the Intelligent Virtual Execution - Server appliance processes malware samples submitted by Network Security sensors. The AV client on the Intelligent Virtual Execution - Server appliance determines whether the integrated antivirus tools detected malware in the submitted samples. The AV-suite detection and analysis tool uses the unique hash of each sample to query the DTI cloud for match results.

The Intelligent Virtual Execution - Server appliance returns AV-suite analysis results to the originating Network Security sensors, where the information can be viewed at the Alerts > Alerts page of the sensor Web UI (or the Alerts > Web MPS > Alerts page of the Central Management System Web UI, if the sensor is under Central Management System management).