Views:

Memory Scanning is a live process image dump feature that implements a function to trigger scanning when malwares have cross-line behaviors after they have been unpacked.

Some malwares use customized packers that can trick file-based scan engines (VSAPI) into bypassing them. Conventional detection is based on virus signature. Thus, virus patterns are constructed into the virus binary machine code. Hackers can reconstruct the virus machine code using packing tools, and as a result, conventional detection rate deteriorates. Triggering a Memory Scan helps avoid this issue.

This option is disabled by default in WFBS 9.0. 

To enable Memory Scanning:

  1. Log in to the WFBS Security Server console.
  2. Go to Security Settings.
  3. Choose either Server (defaults) or Desktop (defaults).
  4. Click Configure Settings.
  5. On the left pane, select Antivirus/Anti-spyware.
  6. Under Advanced Settings, tick the Quarantine malware variants detected in memory checkbox.

    Advanced settings of memory scanning

    Click image to enlarge.

  7. Click Save.
 
For the Memory Scanning function to work properly, Real-time Scan and Behavior Monitoring must both be enabled.