
Explanation
The file could not be scanned by the anti-virus module since the
decompression of the compressed file failed. Since anti-virus is
running in audit mode, the data transfer will be allowed to continue.
Gateway Action
allow_data
Recommended Action
Change Fail Mode parameter to deny if files that fail decompression
should be blocked.
Revision
1
Parameters
filename
[layer7_srcinfo]
[layer7_dstinfo]
Context Parameters
ALG Module Name
ALG Session ID
Connection
2.3.6. compression_ratio_violation (ID: 05800006)
Default Severity
WARNING
Log Message
Compression ratio violation for file <filename>. Compression ratio
threshold: <comp_ratio>
Explanation
Anti-virus has scanned a compresed file with a compression ratio
higher than the specified value. Action is set to continue scan.
Gateway Action
continue_scan
Recommended Action
Files with too high compression ratio can consume large amount of
resources. This can be a DOS attack.
Revision
1
Parameters
filename
comp_ratio
[layer7_srcinfo]
[layer7_dstinfo]
Context Parameters
ALG Module Name
ALG Session ID
Connection
2.3.7. compression_ratio_violation (ID: 05800007)
Default Severity
WARNING
Log Message
Compression ratio violation for file <filename>. Compression ratio
threshold: <comp_ratio>
Explanation
Anti-virus has scanned a compresed file with a compression ratio
higher than the specified value. Action is set to continue scan.
Gateway Action
abort_scan
Recommended Action
Files with too high compression ratio can consume large amount of
resources. This can be a DOS attack.
2.3.6. compression_ratio_violation
(ID: 05800006)
Chapter 2. Log Message Reference
140
Содержание DFL-210 - NetDefend - Security Appliance
Страница 25: ...List of Tables 1 Abbreviations 28 25...
Страница 26: ...List of Examples 1 Log Message Parameters 27 2 Conditional Log Message Parameters 27 26...
Страница 36: ...1 3 Severity levels Chapter 1 Introduction 36...
Страница 156: ...Recommended Action None Revision 1 2 5 7 unsynced_databases ID 05000008 Chapter 2 Log Message Reference 156...
Страница 173: ...Context Parameters Packet Buffer 2 9 14 route_collision ID 00700015 Chapter 2 Log Message Reference 173...
Страница 195: ...2 12 6 route_removed ID 01100006 Chapter 2 Log Message Reference 195...
Страница 240: ...Revision 1 Parameters iface linkspeed duplex 2 20 3 ifacemon_status_bad ID 03900004 Chapter 2 Log Message Reference 240...
Страница 309: ...Context Parameters Rule Name Packet Buffer 2 24 3 ip_rsv_flag_set ID 01600003 Chapter 2 Log Message Reference 309...
Страница 409: ...2 40 19 scp_failed_not_admin ID 04704000 Chapter 2 Log Message Reference 409...
Страница 476: ...2 49 14 zd_block ID 03800014 Chapter 2 Log Message Reference 476...