Mailbag: Virus scanning

Opinion
Feb 18, 20032 mins

* Readers generally satisfied with antivirus tools

By In a previous article, we asked how much satisfaction administrators have with their internal e-mail virus scanners. Here’s a sampling of the feedback we received:

* “E-mail based antivirus systems are a nice psychological panacea for CEOs to believe in. As long as your e-mail gateway rejects everything that contains attachments with *.EXE, *.COM, *.PIF, *.SCR, and *.VBS files, you’ve knocked out potentially 90% of the virus carriers from your system. You still may have to watch out for files stored in archives (*.ZIP files), but those should be picked up by your mandatory workstation-based virus scanners. Administering automatic virus updates and receiving notifications about viruses that have penetrated the workstations is relatively difficult.”

* “We are very satisfied with our current internal antivirus messaging capabilities, but it has taken a lot of work to get to the point where we are now. Not that we have been infected… rather we have spent many hours finding the right products with the right interfaces to make it all self-updating and have total control of what is going on. [Using] two different vendors’ scanners is also important.”

* “We haven’t had an infection in years.”

* “We may just be lucky, but since invoking our e-mail server-based antivirus scanning we haven’t had any user reports of receiving infected e-mail.”

* “As a defensive line, [we are] very satisfied with our internal antivirus capabilities. However, the issues we see are not with detection, but with maintaining the distribution of antivirus definition files… We use Lotus Notes, and even though a virus may sneak through our defenses the issue for us is in simply removing it from mailboxes of those receiving it.”

The information we received indicates that antivirus tools’ ability to stop viruses is clearly very satisfactory, but that management of these systems could be made somewhat easier and more automatic.