DTAVSEL-001 - The anti-virus signature file age must not exceed 7 days - avvscan.dat

Information

Anti-virus signature files are updated almost daily by anti-virus software vendors. These files are made available to anti-virus clients as they are published. Keeping virus signature files as current as possible is vital to the security of any system. By configuring a system to attempt an anti-virus update on a daily basis, the system is ensured of maintaining an anti-virus signature age of 7 days or less. If the update attempt were to be configured for only once a week, and that attempt failed, the system would be immediately out of date.

Solution

From a desktop browser window, connect to the McAfee VirusScan Enterprise for Linux (VSEL) Monitor (WEB interface) of the Linux system being reviewed and logon with the nails user account.

In the VSEL WEB Monitor, under 'Schedule', select 'Product Update'.
Under 'When to update', select the 'Immediately' radio button, and click on 'Next'.
Under 'Choose what to update', select 'Virus definition files (also known as DAT files)', click on 'Next'.
Under 'Enter a task name', type a unique name for this task, and click on 'Finish'.

Re-validate anti-virus signature file age.
To run the Update task manually without the Web interface, access the Linux system being review, either at the console or by a SSH connection.
Add a task to /etc/crontab to run the nails updater.
At the command line, enter the command '/opt/NAI/LinuxShield/bin/nails task -l'.
After the task runs, a (Completed) response will be returned.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_McAfee_VSEL_1-9_2-0_Y20M04_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3b., CAT|I, CCI|CCI-001240, Rule-ID|SV-77561r1_rule, STIG-ID|DTAVSEL-001, Vuln-ID|V-63071

Plugin: Unix

Control ID: a7a2a5c94d23d3bb903789d6e5c3ee873d2a8ac7439d3df23f816341214a4bf7