Dr.Web SNMPD

Dr.Web SNMP agent (Dr.Web SNMPD) is designed for integration of Dr.Web for UNIX servers suite and systems of monitoring via SNMP. Such integration will allow to control operational status of Dr.Web for UNIX servers as well as collect statistics on detected and neutralized threats. The agent provides monitoring systems and SNMP managers with the following information:

State of any suite

Number of detected threats of certain types (according to the Dr.Web classification)

List of detected threats

Moreover, the agent sends SNMP trap notifications upon detection of a threat and upon failures in neutralization of detected threats. The agent supports SNMP protocol of version 2c and 3.

Description of the information which can be sent by the agent is stored in a special section of MIB (Management Information Base) created by Dr.Web. In the MIB section, defined by Dr.Web, the following information is specified:

1.Format of SNMP trap notifications on detected threats. The notification includes:

File name (path to the file) where the threat was detected

Name of the infected object

Threat type

Threat name

Name of the component that requested the scan during which the threat was detected.

2.Format of SNMP trap notifications on unsuccessful attempt to neutralize a threat. The notification has the same fields as an SNMP trap notification on a detected threat and one additional threat with description of the occurred error.

3.Operation statistics and states of the suite components:

a)Counters of detected threats

Known viruses

Suspicious Objects

Adware

Joke programs

Dialers

Riskware

Hacktools

Table with threat information (name, number of detections)

b)Counters of suite errors

4.Information on component states:

PID

State

Last modified time

Last modified code.

Access to Manual

Full version of the Dr.Web for UNIX servers Administrator Manual is available:

on Doctor Web website at http://download.drweb.com/doc/?lng=en (requires a valid Internet connection)

as the PDF file residing in <opt_dir>/share/doc directory (the suffix in the file name determines the language of the document).

 

Details:

Operation Principles

Command-Line Arguments

Configuration Parameters

Integration with SNMP Monitoring Systems