[ Download Now ]
Dr.Web for IBM Lotus Domino is a complex modular solution processing IBM Lotus Domino incoming and outgoing traffic under Microsoft Windows Server 2000/2003/2008 and Linux. The solution filters out viruses, spam, scamming, phishing, pharming and bounce messages.
Dr.Web for IBM Lotus Domino can be installed on the already infected Lotus Domino server and can cure it without resorting to additional utilities. Scanning of e-mail and other databases can be launched as soon as the installation is complete. Before such scanning the option of updating of anti-virus databases is provided so the scan is performed using the latest virus signatures.
Efficient spam filtering
Sophisticated spam filtering technologies use multi-level system processing detected objects; this produces an exceptionally high detection rate for all kinds of unsolicited messages. Dr.Web for IBM Lotus Domino can change its behavior depending on the envelope of a processed e-mail, or the detected blocking objects.
High scan speed
The design of the product, its non-standard file-check technology and flexible management system provide high speed scan at low system load. The multi-thread scan feature of the product enables it managing simultaneously large amounts of data. Low system requirements of Dr.Web for IBM Lotus Domino allow running it on any mail server hardware.
Ease of deployment and flexibility of settings
Administration scripts and detailed documentation help to automate and control the deployment Dr.Web for IBM Lotus Domino. The product provides a system administrator with abundant tools for flexible configuration of actions performed upon results of a message scan: notify a sender, recipient and system administrator on detected viruses, store headers of received messages and attachments.
If install on a partitioned server or Lotus Domino clusters, the installer will allow you to choose partitions to install Dr.Web for IBM Lotus Domino to. So copies of the anti-virus on various partitions will be run as separate processes in RAM, however, they will have a common database and executable files. For all these copies a company should purchase one license only and thus considerably save on IT-security.
Grouping and group management
Grouping makes administration much easier. Every group may have its own settings. You can edit a group profile to apply the same settings to several groups. A profile is used to specify actions upon detection of a suspicious or incurable message: move to the Quarantine or delete. Curable objects are cured by default. If curing is not possible, an object is considered incurable and one of the specified actions is applied to such an object.
Infected and suspicious objects detected by Dr.Web for IBM Lotus Domino can be placed to the Quarantine. So later you can perform necessary actions to these files: extract important information, cure, or delete.
Flexible configuration via the administrator console makes Dr.Web for IBM Lotus Domino easy to customize. The scannings of necessary objects can be initiated/terminated on demand as well. All actions of the program are logged so system administrators can analyze the application behaviour and eliminate bottlenecks. The system promptly notifies an administrator so he/she can perform the required actions in a timely manner.
The multi-thread scan technology allows scanning files on-the-fly before the received messages are processed by a mail client, so the scan doesn't affect the receipt of messages by users.
Dr.Web is not an anti-virus only!
Dr.Web successfully detects, cures or removes viruses and all types of malicious objects, including rootkits, mail and network worms, file viruses, Trojan programs, spyware, adware, hacker tools, paid dialers and joke programs.
Unique non-signature detection technology
The Origins TracingTM technology has been added to traditional signature scan and heuristic analysis. It significantly improves detection of yet unknown viruses. Malicious objects detected using the new technology get the .Origin extension to their names.
Correct scan of archived and packed files
Dr.Web correctly checks the majority of existing formats of packed files and archives with any nesting level, including multi-volume and self-extracting, which is extremely important for e-mail systems. Dr.Web recognizes over 1000 types of archives and packers.
Very frequent updates of the virus database
Updates to the Dr.Web virus database are released as soon as new entries are added - up to several times per hour. "Hot" add-ons are released as soon as a new piece of malware is caught and analyzed. Dr.Web global monitoring network collects samples of new viruses from all over the world. Updates are delivered to customers from several updating servers located in different parts of the globe.
Dr.Web has the most compact virus database
That's why files are scanned quickly, sparing hard drive disk space and RAM, as well as Internet traffic for downloading of the updates is almost instantaneous. Just one entry in the Dr.Web virus database allows detecting dozens, or hundreds, or even thousands of similar viruses.
The e-mail is filtered for spam by the vaderetro plug-in using its own library (Vade Retro).
High filtering speed
Due to the dynamically updated code of the anti-spam's library the filtering speed is always high and the quality of detection is constantly improving. In one second Dr.Web anti-spam checks over one hundred messages for spam on-the-fly (1.9GHz Pentium 4 CPU)! The high speed is combined with resource consumption; the anti-spam perfectly functions on e-mail servers of almost any configuration.
The anti-spam doesn't require tuning!
Unlike anti-spam solutions based on the Bayesian filter, Dr.Web anti-spam doesn't require any initial tuning. The anti-spam starts effectively working as soon as the first message is received!
Intelligent spam detection system
Different technologies are used for different types of undesired mail - spam, phishing, pharming, scamming, bounce messages - to ensure yet higher detection rate.
Stand-alone anti-spam saves traffic
The stand-alone anti-spam analyzer module doesn't require connection to an external server or access to a database which also saves traffic.
The unique technologies!
The unique spam filtering technologies do not require a block list, which means that a company can't be discredited by a deliberate adding it to such lists.
Anti-spam updates are released on a daily basis and are downloaded by Dr.Web automatic updating utility. The unique technologies allow staying up-to-date with the latest filtering evasion techniques applied by spammers with only one update in 24 hours and, therefore, save traffic.
Vaderetro is the spam filtering plug-in that uses a library of its own (Vade Retro). Depending on the analysis each message receives the score from the VadeRetro library - an integer ranging from -10000 to +10000. The less the score is, the more likely the message is to be "legitimate", i.e. not spam. The threshold is set by the SpamThreshold parameter of the plug-in the configuration file (if the score equals to the value of the SpamThreshold parameter or if it is greater than this value the message is considered to be spam).
Depending on its configuration the plugin may add one of the following headers to a message after analysis:
Additionally, at the beginning of the "Subject:" field of messages classified as spam, or those containing a virus, the vaderetro plug-in can add the following:
- X-Drweb-SpamScore: n. n - the score given by the VadeRetro library.
- X-Drweb-SpamState: b. b - yes for spam and messages with viruses and no for non-spam messages and bounces.
- X-Drweb-SpamState-Num: s. s - classification results of the VadeRetro analysis. s can take the following values: 0, 1, 2 and 3. 0 - a message is not spam, 1 - a message is spam, 2 - a message contains a virus, 3 - a message is a bounce. This header is added if the value for the ddXDrwebSpamStateNumHeader parameter of the vaderetro plug-in configuration file is set to yes.
- X-Drweb-SpamVersion: version. version - the version of the VadeRetro library. This header is added if the value for the AddVersionHeader parameter of the vaderetro plug-in configuration file is set to yes.
- X-IS-SPAM, value YES/NO
- X-SPAM-SCORE, a number of points given to the message by VadeRetro
- X-SPAM-AGENT, the version of the VadeRetro library
- X-SPAM-DETAILS, a detailed description of spam returned by the VadeRetro library
- X-SPAM-STATE, current status of a message.
Spam filtering technologies
The anti-spam technologies consist of several thousands of rules which can be divided into several groups.
A highly intelligent technology that empirically analyzes all parts of a message: header, message body, etc. Not only the message itself, but its attachment is analyzed. The heuristic analyzer is being constantly improved; new rules are frequently added.
The counter-reaction technique is one of the most advanced and efficient technologies of Dr.Web anti-spam. It helps counteract techniques and tricks used by spammers to avoid detection.
Messages containing HTML code are compared with a list of known patterns from the anti-spam library. Such comparison, in combination with data on sizes of images typically used by spammers, helps protect users against spam messages featuring HTML-code, which often contains online images.
During a semantic analysis words and phrases of a message are compared with words and phrases typical of spam. A special dictionary is used for the analysis. All words, phrases and symbols are analyzed - both those visible to the human eye and those masqueraded by the technical tricks of spammers.
Scam (as well as pharming messages - a type of scam-messages) is the most dangerous type of spam, including the so-called "Nigerian" scams, loan scams, lottery and casino scams and false messages from banks and credit organizations. A special module of Dr.Web anti-spam is used to filter scams.
Technical spam filtering
So-called bounces are delivery-failure messages sent by a mail server. An actual recipient of a bounce is not necessarily a sender of an undelivered message; such a message could be sent by a mail worm. Therefore bounces are as unwanted as spam A special module of Dr.Web anti-spam filters such messages as unwanted.
Depending on the licence scheme Dr.Web for IBM Lotus Domino allows to do the following:
- detect, cure or remove any malicious objects, including e-mail and network worms, rootkits, file viruses, Trojans, bodiless and stealth viruses, polymorphic viruses, macro-viruses and MS Office worms, script viruses, spyware, password stealers, key loggers, paid dialers, adware, suspicious applications, hack tools, backdoors, jokers, spam, phishing, pharming, scamming and bounce messages;
- process incoming and outdoing e-mails "on-the-fly" (in the real-time mode) or as scheduled by an administrator when a server load is minimal. A message body is scanned as well as all its components regardless of the nesting level. According to the scanning results the filter may allow a message, block it, or modify. Dr.Web for IBM Lotus Domino has a unique inbuilt anti-spam that doesn't require training. It starts working as soon as the first message is received! The anti-spam doesn't require connection to an external server or access to a database which also saves traffic;
- check documents in specified nsf-bases for viruses;
- examine e-mail messages and analyze all their components;
- cure infected messages and their attached files;
- move infected and suspicious objects to the Quarantine. Lotus Notes client is used to access the quarantined objects;
- process correctly archived files of most known formats, including multi-volume and self-extracting (SFX) archives;
- send scan reports to recipients or other specified addressees using the templates;
- collect statistics on all activities of the system;
- protect its own plug-ins against failures.
Version for Windows:
Version for Linux:
- Windows Server 2000/2003/2008/2008R2 (32-bit & 64-bit)
- Lotus Domino R 6.0 for Windows or later
- Processor: Pentium 133 MHz
- RAM: 64 MB, recommended 128 MB
- Free disk space: 60 MB
- Red Hat Enterprise Linux (RHEL) 4/5, Novell SuSE Linux Enterprise Server (SLES) 9/10 (32-bit only)
- Lotus Domino R 7.x
- Processor: Pentium 133 MHz
- RAM: 64 MB, recommended 128 MB
- Free disk space: 50 MB