Operating Principles

Top  Previous  Next

The component is designed to refer to the Dr.Web Cloud service to scan contents of the specified file for threats unknown to the local Dr.Web Scanning Engine, and to check whether the specified URL belongs to any of Doctor Web’s predefined categories of web resources.

Dr.Web CloudD is automatically run by the configuration daemon. The component is run upon receiving a command from the user or one of the Dr.Web for UNIX components. The operation scheme is shown in the figure below.

Figure 1. Diagram of the components’ operation

In this scheme, the following notations are used:

 

— Dr.Web for UNIX as a whole and external Dr.Web applications together with systems which are not included in the solution.

 

— external to Dr.Web for UNIX programs and products for its integration.

 

— Components that are included in Dr.Web for UNIX engine. Other product components use the engine as a service that performs anti-virus checks.

 

— Service components designed to perform particular anti-virus protection functions (for example, scanning file system objects, updating virus databases, managing the operation of the product).

 

— Components that provide the user with the interface for Dr.Web for UNIX.

 

— Quarantine as a set of file system directories which store isolated malicious files.

Components marked with a dashed line can be missing depending on the distribution.

Requests to the Dr.Web Cloud service (to perform scanning of URL and files) via this component can send various components of Dr.Web for UNIX, marked in the scheme as “Other component” (depending on the product).

Besides that, the component is used during the scanning of files on the command from the Dr.Web for UNIX product management utility from the command line Dr.Web Ctl (it is started by the drweb-ctl command): upon detection of threats, the Dr.Web Scanning Engine scanning engine sends a report about the file to Dr.Web Cloud.