Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


August 2005

Beat Back Viruses

5 Exchange antivirus suites
RSS
Subscribe to Windows IT Pro | See More Antivirus Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Performance

Antigen for Microsoft Exchange 8.0
Sybari's first claim to fame was that its product replaced the Exchange Extensible Storage Engine (ESE) DLL with Sybari's version in Exchange Server 5.5, with the purpose of offering features and performance that Microsoft didn't yet support. If the idea of letting a program replace your Exchange DLLs makes you sweat, you'll be glad to know that Sybari Antigen for Microsoft Exchange can now use either ESE- or Exchange Virus Scanning API (VSAPI)-based scanning.

Antigen supports eight scanning engines, using CA Vet and InoculateIT, Norman Data Defense, and Sophos Anti-Virus by default (as Figure 3 shows) and also offering support for Command, Kaspersky, Virus Busters, or AhnLab V3 engines (if you've purchased them). The idea is that if one engine misses a virus, another will catch it, but after testing the product, I don't buy this theory. Antigen came in fourth in my accuracy tests. You might wonder why Antigen's accuracy results were lower than eTrust's even though Antigen uses both CA scan engines. By default, Antigen uses at least two engines to scan each message, but it determines how many engines must complete a scan of each message at runtime. You can use this setting, called the bias, to direct Antigen to use only one engine, multiple engines, or all available engines, depending on your requirements. Sybari recommends setting the bias to Maximum Certainty during a virus outbreak. When using bias settings other than Maximum Certainty, Antigen chooses from the available engines, but gives priority to engines based on historically accuracy and the age of virus definitions.

Antigen has an easy-to-use set of management features. You can perform remote installations, manage multiple servers, and configure automatic updates of all the scanning engines from one client installation or from the web-based Sybari Enterprise Manager (SEM). The product also lets you switch between ESE scanning mode and VSAPI scanning mode after installation.

Poor accuracy, sub-par performance, poor support for scanning file types, and no content filtering inside attachments prevents me from recommending Antigen. Still, you might consider the product for larger Exchange infrastructures that have plenty of extra CPU cycles to run additional engines with a bias towards certainty or if you want to go with an all-Microsoft solution.

Correction (Added online after publication date):
I had some additional notes about Antigen that didn’t make it into the print issue of this article. For users considering the product in larger environments, Sybari’s multiple scan engine technique can offer many benefits. For example, you can run Antigen on Exchange Server bridgehead servers and backend servers. Antigen can use the Max Certainty bias setting to get the benefits of all its scan engines on the bridgehead server where performance is less of a consideration. Antigen can then use the Favor Performance bias setting on backend servers where performance directly impacts user’s experience. Such an environment can give you the best of both worlds. Also remember that although using multiple scan engines takes more processor power, the effects aren’t cumulative; Two engines doesn’t take twice as long as using one.

Antigen had some other benefits not fully described in print. The Sybari suite I tested included Sybari Advanced Spam Manager for spam and content filtering. Sybari’s Intelligent suite supports setting the Exchange Spam Confidence Level (SCL) to quarantine spam or forwarded it to Outlook junk mail folders.

Also note that although the current version of Antigen doesn’t perform content filtering within attachments, it fully supports blocking attachments based on the file type and scanning attachments for viruses. Sybari will include content filtering inside attachments in the next version of the Antigen.

Sybari Antigen for Microsoft Exchange 8.0
Contact: Sybari (recently purchased by Microsoft) * 631-630-8500
Web: http://www.sybari.com
Price: Starts at $36.75 per mailbox for 1 to 25 users
Summary
Pros: Supports multiple scan engines
Cons: Displayed better accuracy but a severe performance impact; doesn't filter content in attachments; poor file-scanning support; content filtering missed Unicode text file
Rating: 2 out of 5
Recommendation: A good option if you don't want to commit to one vendor's scan engine.


Mail Security for Microsoft Exchange 4.6
Symantec Mail Security for Microsoft Exchange's virus-scanning accuracy took only a slight second to Active Mail Protection's and offered much better performance in my tests. Although Mail Security, which Figure 4 shows, missed some attachment types in my content-filtering tests, it was the best overall solution and wins Editors' Choice in this comparative.

Two noteworthy features of Mail Security are Rapid Release virus definitions and Premium AntiSpam. Rapid Release definitions are released earlier than Symantec's regular virus definitions are, but are tested less-thoroughly and tested only on Windows. Using Rapid Release is free and can help protect against new threats. Premium AntiSpam (originally a Brightmail product) is a separately purchased, signature-based antispam add-on that blocks messages from known and suspected spammers. Symantec reports that these antispam signatures are created by using data from more than 20 million decoy email accounts. If you don't want to buy Premium Antispam, Mail Security includes basic heuristic- and blacklist-based antispam functionality. Both versions let you take action according to Exchange Spam Confidence Level (SCL) values; you can specify which SCL value you want the product to set on detected spam. Disappointingly, Mail Security's content filtering failed to catch problem text inside a .pdf, .rtf, and zipped word file. However, it did successfully filter a Unicode text file, something both GroupShield and ScanMail failed to do.

In addition to remote deployment, Mail Security includes the multiserver console, an MMC snap-in that lets you manage remote instances by user-defined groups. The console let me synchronize settings with the server that I added for management testing. My only complaint was that the multiserver console requires a separate machine on which to store configuration data, so all your messaging administrators must have access to that system.

Mail Security offered great accuracy and acceptable performance. I loved the regular expressions–based content filtering, detailed options for integrating with SCLs in Exchange, and the well-organized, responsive UI.

Symantec Mail Security for Microsoft Exchange 4.6
Contact: Symantec * 800-745-6054
Web: http://www.symantec.com
Price: Basic product starts at $37.70 per mailbox for 10 to 24 users; Premium Antispam add-on starts at $25.90 per mailbox per year for 10 to 24 users; annual virus definition subscription starts at $20.80 per mailbox for 10 to 24 users
Summary
Pros: Excellent antivirus accuracy; great SCL support; supports regular expressions for content filtering
Cons: Content filtering didn't scan .rtf or .pdf documents; failed to scan some types of compressed files
Rating: 4.5 out of 5
Recommendation: This product's combination of accuracy, performance, and detailed spam control make Mail Security Editors' Choice.


ScanMail for Microsoft Exchange 7.0
Trend Micro ScanMail for Microsoft Exchange, which Figure 5 shows, targets the most current and harmful threats. Unsurprisingly, then, Exchange quickly delivered all my test messages, but ScanMail caught only 3279 of the 4303 viruses. (A spot check showed that the product did catch Melissa, Blaster, Loveletter, and Nimda.)

ScanMail offers a spam-filtering technology (similar to Symantec's Premium Antispam) but doesn't let you control how it sets SCLs in Exchange. The product's content filtering supports regular expressions and scanned inside most of the attachment types that I tested.

Though not as complex as Mail Security or Active Mail Protection, ScanMail's management features are probably sufficient for most organizations. The ScanMail installer let me simultaneously deploy the product to multiple Exchange servers. Each server connects to a Web-based management console, but you can automatically replicate settings to other servers to manage a larger Exchange infrastructure. And ScanMail's outbreak-management feature can generate alerts according to the number of viruses or attachments blocked in a given period.

Trend Micro's virus-definition strategy might make its results look less than optimal, but the viruses it misses might not be ones you'd see in the wild. The product's performance and feature set were both amazing, so I strongly recommend ScanMail if speedy email delivery is of paramount importance.

Trend Micro ScanMail for Microsoft Exchange 7.0
Contact: Trend Micro * 877-268-4847
Web: http://www.trendmicro.com
Price: Starts at $41.40 per mailbox per year for 5 to 25 users; annual virus definition subscription fee costs 30 percent of purchase price
Summary
Pros: Minimal impact on mail-server performance; supports regular expressions for content filtering
Cons: Virus database isn't as extensive as other reviewed products'; content filtering missed Unicode text file
Rating: 3.5 out of 5
Recommendation: If speedy email delivery is of paramount importance, consider this product, but be aware that its targeted approach is likely to let viruses through sooner or later.


Get What You Need
I've tried to give you an idea of how some of our readers' favorite mail-server antivirus products stack up, but take a look at the features listed in Table 4 to get more information about which product offers the features that matter most in your environment. Also, you can find out about many other available Exchange antivirus products by visiting our IT Solution Center (see Interact! for details).

End of Article

   Previous  1  [2]  Next  


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Interact! Research more antivirus products at our IT Solutions Center

Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Google's Browser Created Out of Fear of Microsoft

A deep fear of Microsoft drove Google to create its own Web browser, the company's cofounders implicitly admitted Tuesday, though each was careful never to mention the software giant by name. Instead, during a press conference, Google's leaders discussed ...

Let's Get Out of the (Network) Neighborhood

Network Neighborhood might've made sense way back when, but it's long past obsolete today. ...


Security Whitepapers Protecting (You and) Your Data with Exchange Server 2007

Extended Validation SSL Certificates

Unauthorized applications: Taking back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

IT Connections
Dive into the new Microsoft platforms and products you implement and support with the experts from Microsoft, TechNet Magazine, Windows ITPro and industry gurus. There are 70+ sessions and interactive panels with networking opportunities.

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes and add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Get SQL Server 2008 at WinConnections
Don’t miss Microsoft Exchange and Windows Connections conferences, the premier events for Microsoft IT Professionals in Las Vegas, November 10-13. Every attendee will receive a copy of SQL Server 2008 Standard Edition with one CAL.



Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing