DTAVSEL-114 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Demand scanner must be enabled to scan mounted volumes when mounted volumes point to a network server without an anti-virus solution installed.

Information

Mounting network volumes to other network systems introduces a path for malware to be introduced. It is imperative to protect Linux systems from malware introduced from those other network systems by either ensuring the remote systems are protected or by scanning files from those systems when they are accessed.

Solution

From a desktop browser window, connect to the McAfee VirusScan Enterprise for Linux (VSEL) Monitor (WEB interface) of the Linux system being reviewed and logon with the nails user account.

In the VSEL WEB Monitor, review tasks under 'View', 'Scheduled Tasks'.
With the System Administrator's assistance, determine which task is intended as the regularly scheduled scan task.
Click on the task, and then click 'Modify'.
Select '2. What to Scan'.
Under 'Path', add each otherwise unprotected network server to which this Linux system has mounted volumes, and click 'Add'.
Once all mounted volumes have been added, click 'Next', and then click 'Finish'

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_McAfee_VSEL_1-9_2-0_Local_Client_V1R5_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CAT|II, CCI|CCI-001241, Rule-ID|SV-77625r2_rule, STIG-ID|DTAVSEL-114, Vuln-ID|V-63135

Plugin: Unix

Control ID: 20b99046dbb5d4d7cea708898c31235b05979652dde59198129045d613a3aa94