STIGUI
V-285608CAT I — High severitySV-285608r1274299_rule

The Content Analysis System (CAS) must implement signature based and/or nonsignature-based malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.

Rule version BCAS-ND-001945 · STIG v1 · 2026-09-16

Discussion

System entry and exit points include firewalls, remote access servers, workstations, electronic mail servers, web servers, proxy servers, notebook computers, and mobile devices. Malicious code includes viruses, worms, Trojan horses, and spyware. Malicious code can also be encoded in various formats contained within compressed or hidden files or hidden in files using techniques such as steganography. Malicious code can be inserted into systems in a variety of ways, including by electronic mail, the world wide web, and portable storage devices. Malicious code insertions occur through the exploitation of system vulnerabilities. A variety of technologies and methods exist to limit or eliminate the effects of malicious code.

Malicious code protection mechanisms include both signature- and nonsignature-based technologies. Nonsignature-based detection mechanisms include artificial intelligence techniques that use heuristics to detect, analyze, and describe the characteristics or behavior of malicious code and to provide controls against such code for which signatures do not yet exist or for which existing signatures may not be effective. Malicious code for which active signatures do not yet exist or may be ineffective includes polymorphic malicious code (i.e., code that changes signatures when it replicates). Nonsignature-based mechanisms also include reputation-based technologies. In addition to the above technologies, pervasive configuration management, comprehensive software integrity controls, and anti-exploitation software may be effective in preventing the execution of unauthorized code. Malicious code may be present in commercial off-the-shelf software as well as custom-built software and could include logic bombs, backdoors, and other types of attacks that could affect organizational mission and business functions.

In situations where malicious code cannot be detected by detection methods or technologies, organizations rely on other types of controls, including secure coding practices, configuration management and control, trusted procurement processes, and monitoring practices to ensure that software does not perform functions other than the functions intended. Organizations may determine that, in response to the detection of malicious code, different actions may be warranted. For example, organizations can define actions in response to malicious code detection during periodic scans, the detection of malicious downloads, or the detection of maliciousness when attempting to open or execute files.

Check

Verify that antivirus engines, patterns, and scanning behaviors are configured correctly with the following steps:

1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to System >> Licensing. 3. Under "Antivirus", verify both "Symantec" and "ClamAV" are checked. 4. Navigate to Services >> AV Patterns. 5. Under "Antivirus Patterns", verify the "Symantec" and "ClamAV" patterns have been updated according to the policy-defined frequency. 6. Under "Downloads", verify every "Status" entry displays "Success (200)". 7. Navigate to Services >> AV Scanning Behavior. 8. Verify that "Cached Responses" is set to "Enabled". 9. Navigate to Services >> AV File Types. 10. Under both "Global Options" and "Symantec Options", verify that every file category has "scan" selected. 11. Navigate to Services >> File Reputation. 12. Verify "Cached Responses" is checked.

If any of the above conditions are not met, this is a finding.

Fix

Configure antivirus engines, update patterns, and set scanning behaviors with the following steps:

1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to System >> Licensing. 3. Under "Antivirus", check the boxes for "Symantec" and "ClamAV". 4. Click "Save Changes". 5. Navigate to Services >> AV Patterns. 6. Click "Force Update All Now" under the "Antivirus Patterns" section. 7. Navigate to Services >> AV Scanning Behavior. 8. Select "Enabled" under the "Cached Responses" section. 9. Click "Save Changes". 10. Navigate to Services >> AV File Types. 11. Under both "Global Options" and "Symantec Options", select the radio button for "scan" for all available file categories. 12. Click "Save Changes". 13. Navigate to Services >> File Reputation. 14. Check the box for "Cached Responses". 15. Click "Save Changes".

Identifiers

Group ID
V-285608
Group title
SRG-APP-000516-NDM-000317
Rule ID
SV-285608r1274299_rule
Check ID
C-90288r1272941_chk
Fix ID
F-90193r1272942_fix