logging

Julian Field mailscanner at ecs.soton.ac.uk
Thu Sep 12 14:32:45 IST 2002


Ok, here are all the responses:

1. From <$1> To <$2> virus <$3>

Impossible to generically extract the name of the virus, so this would have
to include the whole virus report.

2. something that grep could sniff out easily ONLY for caught viruses. Or
do you have a better solution? The Email ID to go along with it as well
would be nice. for ones that were scanned and ones that were found to be
infected

Such as?

3. I would definately like the virus name reported by the virus engine

See (1)

4. making the logging as machine freindly as possible

I will do what I can.

5. entries that could be used to create email usage reports.  For each
email to have To, From, Subject, Date, bytes, and names of any attachments
would allow for easier creation of user reports.

Is there a limit on the length of a log entry? These would be *very* long.

6. Identifiable tag
When you get a chance would you consider altering the logging code for
matches on filename rules to have an identifiable tag. E.g. instead of
logging:
"Executable file in filename.exe" and "Possible MS-Dos shortcut attack
in filename.pif"
Log:
"Filename Rules: Executable file in filename.exe" and "Filename rules:
Possible MS-Dos shortcut attack in filename.pif"

Definite good idea.

Any more thoughts from anyone?
--
Julian Field                Teaching Systems Manager
jkf at ecs.soton.ac.uk         Dept. of Electronics & Computer Science
Tel. 023 8059 2817          University of Southampton
                             Southampton SO17 1BJ
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20020912/c87f1734/attachment.html


More information about the MailScanner mailing list