background image

16

ESET  File Security

This  chapter  describes  the  On-demand  and  On-access  scanner  configuration  which  will 

provide  the  most  effective  protection  from  virus  and  worm  file  system  infections.  ESET  File 

Security's scanning power is derived from the On-demand scanner command '

esets_scan

' and 

the On-access scanner command '

esets_dac'

. The Linux version of ESET File Security offers an 

additional On-access scanner technique which uses the preloaded library module 

libesets_pac.

so

. All of these commands are described in the following sections.

5.1. On-demand scanner

The On-demand scanner can be invoked by a privileged user (usually a system administrator) 

through  the  command  line  interface  or  by  the  operating  system's  automatic  scheduling  tool 

(e.g., cron). Thus, the term "On-demand" refers to file system objects which are scanned on user 

or

 system demand.

The  On-demand  scanner  does  not  require  special  configuration  in  order  to  run.  After  the 

ESETS package has been properly installed and a valid license has been moved to the license 

keys directory (@ETCDIR@/license), the On-demand scanner can be run immediately using the 

command line interface or scheduler tool. To run the On-demand scanner from the command 

line, use the following syntax:

    

 

@SBINDIR@

/esets_scan [option(s)] FILES

        

where FILES is a list of directories and/or files to be scanned.

Multiple command line options are available using ESETS On-demand scanner.  To  see the full  

list  of options, please see the esets_scan(8) man page.

5.2. On-access scanner powered by Dazuko

The On-access scanner is invoked by user(s) access and/or operating system access to file 

system objects. This also explains the term "On-access"; the scanner is triggered on any attempt 

to access a selected file system object.

The technique used by 

ESETS

 On-access scanner is powered by the Dazuko (da-tzu-ko) kernel 

module  and  is  based  on  the  interception  of  kernel  calls. The  Dazuko  project  is  open  source, 

which means that its source code is freely distributed. This allows users to compile the kernel 

module for their own custom kernels. Note that the Dazuko kernel module is not a part of any 

ESETS

 product and must be compiled and installed into the kernel prior to using the On-access 

command 

esets_dac

.  On  the  other  hand  the  Dazuko  technique  makes  On-access  scanning 

independent of the file system type used. It is also suitable for controlling file system objects via 

Network File System (NFS), Nettalk and Samba.

IMPORTANT

:  Before  we  provide  detailed  information  related  to  the  On-access  scanner's 

configuration and operation, it should be noted that the scanner has been primarily developed 

and tested to protect file systems mounted externally. If there are multiple file systems which are 

not externally mounted, they will need to be excluded from file access control in order to prevent 

system hang-up. An example of a typical directory to be excluded is the ‘/dev’ directory and any 

directories used by 

ESETS

.

5.2.1. Operation principle

The On-access  scanner esets_dac (ESETS Dazuko-powered file Access Controller) is a resident 

Summary of Contents for FILE SECURITY

Page 1: ...ESET File Security Installation Manual and User Guide we protect digital worlds...

Page 2: ...Interface 24 6 5 Remote Administration 24 7 ESET Security system update 25 7 1 ESETS update utility 26 7 2 ESETS update process description 26 7 3 ESETS mirror http daemon 27 8 Let us know 29 Appendi...

Page 3: ...Chapter 1 Introduction...

Page 4: ...run under non privileged user account to enhance security The system supports selective configuration based on the user or client server Multiple logging levels can be configured to get information ab...

Page 5: ...Chapter 2 Terminology and abbreviations...

Page 6: ...ion the primary installation directory is opt eset esets ESETS daemon The main ESETS system control and scanning daemon esets_daemon ESETS base directory The directory where ESETS loadable modules con...

Page 7: ...s directory The SBINDIR value for the following Operating Systems is listed below Linux usr sbin Linux RSR opt eset esets sbin FreeBSD usr local sbin NetBSD usr pkg sbin Solaris opt esets sbin ESETS o...

Page 8: ......

Page 9: ...Chapter 3 Installation...

Page 10: ...ade the product use the following command sh esets i386 ext bin For the Linux RSR variation of the product use the command sh esets rsr i386 rpm bin to display the product s User License Acceptance Ag...

Page 11: ...Chapter 4 Architecture Overview...

Page 12: ...tegrate ESETS with the Linux BSD Solaris Server environment UTILITIES The utility modules provide simple and effective management of the system They are responsible for relevant system tasks such as l...

Page 13: ...le For detailed information on the most effective way to organize this file please refer to the esets cfg 5 and esets_daemon 8 man pages as well as relevant agents man pages ETCDIR certs This director...

Page 14: ......

Page 15: ...Chapter 5 Integration with File System services...

Page 16: ...list of options please see the esets_scan 8 man page 5 2 On access scanner powered by Dazuko The On access scanner is invoked by user s access and or operating system access to file system objects Thi...

Page 17: ...n As mentioned previously the Dazuko kernel module must be compiled and installed within the running kernel before esets_dac can be initialized To compile and install Dazuko please see http www dazuko...

Page 18: ...hould be used See section 5 3 1 below for detailed information Please note that this section is relevant only for Linux OS users and contains information regarding the operation installation and confi...

Page 19: ...g the following line LD_PRELOAD path to libesets_pac so COMMAND COMMAND ARGUMENTS where COMMAND COMMAND ARGUMENTS is the original executable statement Review and edit the global and pac sections of th...

Page 20: ......

Page 21: ...Chapter 6 Important ESET File Security mechanisms...

Page 22: ...has been taken as a result of these three action options the object is accepted Otherwise the object is blocked 6 2 User Specific Configuration The purpose of the User Specific Configuration mechanis...

Page 23: ...m will be processed by the ESET virus laboratory and if necessary added to the ESET virus signature database NOTE ACCORDINGTO OUR LICENSE AGREEMENT BY ENABLING SAMPLE SUBMISSION SYSTEMYOU ARE AGREEING...

Page 24: ...ministrator Manual This manual is located on our web site here http download eset com manuals ESET_ERA_User_Guide_EN pdf The ESETS Remote Administration Client is part of the main ESETS daemon For bas...

Page 25: ...Chapter 7 ESET Security system update...

Page 26: ...TS configuration file The ESETS daemon must be up and running in order to successfully update the virus signature database 7 2 ESETS update process description The update process consists of two stage...

Page 27: ...o yes and the Mirror is enabled Options av_mirror_httpd_port and av_mirror_httpd_addr define the port default 2221 and address default all local tcp addresses where the http server listens The option...

Page 28: ......

Page 29: ...Chapter 8 Let us know...

Page 30: ...ly improve the quality and effectiveness of our documentation If you feel that any sections in this Guide are unclear or incomplete please let us know by contacting Customer Care http www eset com sup...

Page 31: ...Appendix A PHP License...

Page 32: ...ll be given a distinguishing version number Once covered code has been published under a particular version of the license you may always continue to use it under the terms of that version You may als...

Reviews: