Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


August 2005

Beat Back Viruses

5 Exchange antivirus suites
RSS
Subscribe to Windows IT Pro | See More Antivirus Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Performance

Protecting your network from email viruses and spam has become a full-time job; finding the right antivirus software can make all the difference in whether it's a job well done. To help you, I tested the Microsoft Exchange Server versions of the top five products from the Best Antivirus/Mail Server category in Windows IT Pro's 2004 Readers' Choice awards: Computer Associates International (CA) eTrust Antivirus 7.1 Option for Microsoft Exchange, McAfee Active Mail Protection, Sybari (recently purchased by Microsoft) Antigen for Microsoft Exchange 8.0, Symantec Mail Security for Microsoft Exchange 4.6, and Trend Micro ScanMail for Microsoft Exchange 7.0. (Pick up next month's issue of Windows IT Pro to discover this year's winners.)

My lab consisted of two virtual machines—a domain controller (DC) and an Exchange server—on one dual-processor host system. I evaluated the products on the basis of their virus-scanning accuracy, spam- and content-filtering capabilities, and management functionality. I used virtual machines to provide a consistent test environment, but the overhead of the virtual machines magnified the performance differences between the products. Therefore, although I evaluated the products' performance against a baseline and against one another (as I explain in the Web sidebar "Performance," http://www.windowsitpro.com, InstantDoc ID 46978), I didn't consider performance to be the deciding factor in my final decisions.

I configured the Exchange server with 512MB of RAM, gave it exclusive use of one CPU, and put its virtual hard disk on a different disk than the host OS. For my antivirus tests, I disabled each product's spam- and content-filtering functions but left all other options at their defaults. I chose 4303 unique viruses from various virus-exchange Web sites; I chose viruses labeled win32, worm, macro, or .bat (i.e., batch file). Some vendors, such as McAfee and Symantec, try to catch all viruses, regardless of threat level. Others, such as Trend Micro, target their antivirus-definition files toward real-world threats that you'll find in the wild. The first approach resulted in high accuracy but poor performance in my tests; the second approach had the opposite effect. Because many of the viruses I chose aren't currently common in the wild (and because performance differences on production servers will likely be less drastic than they were in my tests), I suggest you consider the product's virus-catching approach as only one aspect of the products' overall capabilities. I used Microsoft SMTP server on the host machine to deliver 4303 virus-infected attachments to one user on the Exchange server, then repeated the test. Table 1 lists the number of viruses that each product caught (best of the two passes).

One way that malicious entities get past antivirus systems is by compressing or encoding malicious content. Therefore, I also sent a compressed or encoded copy of the Melissa virus, as well as a .zip file compressed within a .zip file to determine whether each product supported recursive archives; they all did. (I didn't test encrypted .zip files because encryption prevents the in-transit viewing upon which these products depend.) Table 2 lists the archive formats that each product was able to scan. To my dismay, none of the products were able to scan ISO images, which can be especially troublesome if infected with a virus.

Spam and content filtering (i.e., searching incoming or outgoing content for key words or phrases) are increasingly important in today's atmosphere. The McAfee, Sybari, Symantec, and Trend Micro products all supported content-filtering of both messages and attachments, either natively or through add-ons. (CA provides content-filtering through a separate product, eTrust Secure Content Manager, which was unavailable for review because of an upcoming release.) Content-filtering products must be able to read a file's format to filter its content, so I tested each product with eight common document formats. Table 3 shows the results.

After my accuracy and performance tests, I added a second Exchange server to test each product's management capabilities. Let's take a closer look at the individual products and their test results.

eTrust Antivirus 7.1 Option for Microsoft Exchange
CA eTrust Antivirus Option for Microsoft Exchange is an add-on to CA eTrust Antivirus, the file system–based antivirus product. eTrust Antivirus scans only for viruses and performs no spam or content filtering.

CA offers two virus scanning engines—Vet and InoculateIT—but eTrust Antivirus can scan with only one engine at a time. eTrust also performs heuristic scanning to detect viruses even before new definition files are released, but the documentation offers no additional explanation of the factors that the product uses for heuristics.

eTrust integrates with a CA Unicenter TNG module, but you don't need that product to manage remote servers from any console. Configuration was simple and involved only the small dialog box that Figure 1 shows. Another console let me view logs and monitor quarantined files but lacked detailed reporting or alerting based on detection rates (to help identify outbreaks).

eTrust offered an excellent balance of accuracy and performance in my tests, falling only slightly short of Symantec's and McAfee's products. I can't give the product my complete blessings without having reviewed Secure Content Manager, but if you're looking only for antivirus capabilities at an excellent price, I highly recommend eTrust Antivirus.

CA eTrust Antivirus 7.1 Option for Microsoft Exchange
Contact: Computer Associates International * 631-342-6000
Web: http://www.ca.com
Price: $40 per server; no annual virus definition subscription fee
Summary
Pros: Great balance of accuracy, performance and price; multiple scan engines; heuristic virus scanning
Cons: Can use only one scan engine at a time; offers minimal reporting functionality
Rating: 3 out of 5
Recommendation: Great antivirus-only solution. (The vendor's content-filtering product was unavailable for testing.)


Active Mail Protection
McAfee Active Mail Protection bundles three of the company's products: GroupShield for Microsoft Exchange (which Figure 2 shows) provides antivirus functionality, SpamKiller for Microsoft Exchange delivers spam and content filtering, and ePolicy Orchestrator (ePO) offers integrated security-policy management.

McAfee's Active Mail Protection suite was designed with enterprise-class management in mind. ePO (which is really more of a framework) let's you distribute GroupShield and SpamKiller to multiple Exchange servers and centrally manage policies, alerts, and reporting. The product uses a Microsoft SQL Server or Microsoft SQL Server Desktop Engine (MSDE) back-end and can be managed by remote consoles from anywhere on your network.

Active Mail Protection came out on top for virus-scanning accuracy in my tests but took the second-longest time to deliver messages. The product came out on top as far as supported file formats go, catching 13 file types. SpamKiller's content filtering doesn't support regular expressions—a powerful, standardized syntax for searching text—but it does support simple wildcards. Active Mail Protection also includes extensive categorized lists of predefined filtered words to target inappropriate content. You can build custom lists and assign words a high, medium, or low severity for granular content control. I consider regular expressions a prerequisite for filtering of any type, but if you can live without them, Active Mail Protection might be the best solution for you. I rated Active Mail Protection a close second in this review; my decision came down to my personal preferences for specific features: the regular expressions–based content filtering and Microsoft Management Console (MMC)–based multiserver management console that Symantec offers.

McAfee Active Mail Protection
Contact: McAfee * 888-847-8766
Web: http://www.mcafee.com
Price: Starts at $54.10 per mailbox per year for 11 to 25 users; annual virus definition subscription fee starts at $21.64 per mailbox per year for 11 to 25 users
Summary
Pros: Excellent antivirus accuracy; best support for content filtering in compressed attachments; great multiserver management
Cons: Could have a significant performance impact on slow servers; doesn't support regular expressions for content filtering
Rating: 4 out of 5
Recommendation: This full-featured product came in a close second. In fact, if your mail server is beefy, price is an issue, and you simply can't compromise on antivirus accuracy, this product might be your best bet.


   Previous  [1]  2  Next 


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Interact! Research more antivirus products at our IT Solutions Center

Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...


Security Whitepapers Anti-Virus Is Dead: The Advent of the Graylist Approach to Computer Protection

Getting the Job Done: Comparing Approaches for Desktop Software Lockdown

Instant Messaging, VoIP, P2P, and games in the workplace: How to take back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Maximize your SharePoint Investment – 8 Cities
Discover best practices and tips for both architecting and administering SharePoint. Early Bird Price of $99 through Sept 15th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



Entrust Unified Communications Certs
Secure Exchange 2007 and save 20%. Now through Sept. 2008.

Increase Application Performance
Free White Paper by Editor's Best winner, Texas Memory Systems.

Need to convert between XML, DBs, EDI, and Excel? Try MapForce free!
Drag & drop to transform between popular data formats – get results instantly or generate code.

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing