---
title: "Anti-Malware"
canonical: "https://docs.aryaka.com/space/KNOW/1275854932/Anti-Malware"
format: markdown
---
SD-WAN subscriptions include  Basic Firewall . For additional security, Aryaka offers Unified SASE, which includes Next Generation Firewall - Secure Web Gateway ( NGFW-SWG ), Anti-Malware, and an  Intrusion Prevention System (IPS) . You can also purchase Advanced Security, which includes  Cloud Access Security Broker (CASB)  and  Data Loss Prevention (DLP) . Anti-Malware protects your sites and remote users from malware, viruses, and file-based threats. With an Aryaka Anti-Malware subscription, your sites and remote users have their inbound and outbound traffic inspected by an Anti-Malware security engine that applies user-defined controls to network traffic.  This document provides an overview of the Aryaka Anti-Malware security offering and describes how to get started with  configuring your service  and  monitoring your service  in MyAryaka.  Prerequisites A site or remote user license for Unified SASE. Use cases The following are the two primary use cases for Anti-Malware: Protect against malware attacks.  Anti-Malware scans files that are being downloaded to your network to detect and block malicious files. Verify file reputation.  Anti-Malware classifies files that are being downloaded to your network by reputation to determine whether they are trustworthy, malicious, or require further investigation. User-defined traffic controls can then be applied to permit or block files based on their reputations.  Features Anti-Malware includes the following functionality: Malware protection—Detects known malware and drops it at on-premises and cloud edges. Edges are regularly updated with the latest threat intelligence to stop the distribution of emerging threats. Anti-virus protection—Consults automatically updated indicators of compromise and signatures from a threat intelligence database to prevent virus infections. File-based threat protection—Scans file contents and makes dynamic, byte-by-byte determinations based on the file’s reputation while the content is being downloaded or is in transit on a network. Industry-standard MD5 file hashes are used as fingerprints to uniquely identify files regardless of filename, platform, and encryption. High-speed file processing ensures no impact to the end-user experience. These security functions are performed by the Anti-Malware security engine, which is described in the section that follows. Anti-Malware security engine The Anti-Malware security engine detects known malware, viruses, and file-based threats in inbound and outbound traffic. This engine performs deep packet inspection (DPI) to evaluate network traffic against a database of known malware signatures and patterns. Aryaka uses  Webroot  and  Sophos  to classify a file's reputation as Good, Bad, or Unknown. Files are separated into sections of data that are classified one at a time to reduce the bandwidth required for classifying large files. If a Bad section is detected, the transfer of the file can be blocked without the rest of the file needing to be classified. For files that are classified as Unknown, you can  configure Unknown Traffic Control  to determine whether they should be permitted or denied. The following graphic depicts the processing sequence of the Anti-Malware security engine and the other NGFW-SWG and IPS engines: This engine uses a rule table that contains rules that are read from top to bottom. The first rule that matches the client’s traffic is applied and all subsequent rules are ignored. This engine uses the following match criteria to permit or drop files, log the flow, or skip scanning a file: Source IP Source zone Source geolocation User Application Domain name HTTP header Protocol URL Destination IP Destination network Destination site Destination geolocation Schedule For more information about match criteria, see the  Security rule match criteria  topic. For more information about the security rule framework and rule tables, see the  Security  topic.  The Anti-Malware security engine performs one of the following actions on matched traffic: Enforce Verdict—File reputation is verified and only files with a classification of  Good  are permitted. Ignore Verdict—File reputation is verified but traffic is permitted regardless of the file’s classification. Log Only—File reputation is verified but traffic is permitted regardless of the file’s classification. This is intended as a temporary action for traffic that needs to be evaluated. After evaluation, update the rule to perform one of the other three actions (enforce verdict, ignore verdict, or skip engine). Skip Engine—File reputation is not verified and the traffic is permitted. Default rule The default Anti-Malware rule matches any traffic that arrives at the rule table and permits it without verifying file reputation. To modify the Anti-Malware rule table, you can  add site-level Anti-Malware rules  or  create an Anti-Malware ruleset . Best practices Develop rule tables based on your organization’s needs.  The Anti-Malware security engine includes a default rule that permits traffic without verifying file reputation. Aryaka recommends that you create additional security rules based on your organization's needs. Use URL regex in rules to match traffic.  Use URL regex-based match conditions in your security rules to match files that should be scanned. The goal is to match traffic using the GET URLs containing file names with extensions at the end of the URL. For example, the goal of the following URL regex is to match all traffic with URLs that are attempting to download files: .*\.(acm|ax|cpl|dll|drv|efi|exe|mui|ocx|scr|sys|tsp|mun|pdf)$ Test new rules . Test rules you want to add to your Anti-malware configuration in a safe environment before applying them to your network. Start the Anti-Malware security engine for your sites.  Once you have configured rule tables based on your organization’s needs, start the Anti-Malware security engine for each of your subscribed sites. Do not stop the engine for performance reasons. If you are experiencing issues, determine the source of the problem and adjust your configuration accordingly. Monitor network traffic.  When creating new rules to permit traffic, choose the  Log Only  rule action and then regularly audit your security logs to ensure your rules are operating as expected. If you discover that you need to block a certain type of traffic or create a rule exception due to a false positive, you can modify the rule or create additional rules as needed. See the  Security  topic for general best practices for managing your SASE service. Configuration The Aryaka security rule framework is designed to allow you to achieve your organization’s security and routing requirements using simple workflows. You can configure your Aryaka Anti-Malware service to your organizations’s specifications in MyAryaka by enabling the entitlement, configuring the rule tables for each of your sites, and then starting the security engine for each of your sites. These processes are described in the following sections.  Enable your Anti-Malware entitlement If you purchased a Unified SASE or Advanced Security license (part of a 2025 Enterprise Billing plan), this entitlement is enabled by default and this step is not necessary.  To enable Anti-Malware for a site in MyAryaka, click  Sites  in the left navigation pane. On the Sites page, select a site and then click  View  on the Site Details tile. The Site-Add-Ons pane allows you to toggle on entitlements for the site. To enable Anti-Malware for a remote user region in MyAryaka, click  Universal ZTNA  >  Settings  in the left navigation pane, and then select a region. The User Count & Features pane allows you to toggle on entitlements for the region. See the  Getting Started with Aryaka Unified SASE  guide for a more detailed procedure on enabling entitlements.  Configure rule tables, assets, and rulesets To create an Anti-Malware security rule for a site in MyAryaka, click  Sites  in the left navigation pane. On the Sites page that appears, select the site that you want to configure a security rule for. On the  siteName  page, the  Security  pane includes a tile for each security engine. Click  View  on the Anti-Malware tile to view a page where you can add or edit Anti-Malware security rules for the selected site. For detailed information about creating site-level security rules, and for an example rule, see the  Configure site-level security features  help topic. When you add a security rule to a rule table you can leverage  assets  and  rulesets —components that can be created and then reused in your security configuration. The follwing paragraphs provide more detail on these reusable components. To create an asset that you can reuse as match criteria when creating security rules in MyAryaka, click  Security  >  Asset Management  in the left navigation pane. The Asset Management page includes a tile for each of the asset types that you can create. For detailed information about creating assets, see the  Asset management  help topic. To create a ruleset in MyAryaka, click  Security  >  Anti-Malware  in the left navigation pane. For detailed information about creating an Anti-Malware ruleset, see the  Configure an Anti-Malware ruleset  help topic. For general information about rulesets, and to view an example, see the  Security engine rulesets  help topic.  Start the Anti-Malware security engine After you have configured a rule table for a site to your specifications, you can start the Anti-Malware security engine in MyAryaka. Click  Sites  in the left navigation pane. On the Sites page that appears, select the site that you want to start the security engine for. On the  siteName  page, the Security pane includes a tile for each security engine. Click  View  on the Anti-Malware tile, then  Start Engine  on the Anti-Malware page.  Monitoring MyAryaka allows you to monitor the usage of the Anti-Malware security engine and to view security logs for events in your network. To monitor the Anti-Malware security engine in MyAryaka, navigate to the  Security  >  Monitor  page. This page displays a diagram of the security engines in the order in which they receive and inspect traffic and a series of tables and graphs that provide statistics about permitted and denied traffic in your network. For detailed information about the functionality included on the Security page, see the  Monitor security  help topic. Click the  Anti-Malware  security engine in the Engine Sequencing diagram. The Engine: Anti-Malware page displays an Engine Sequencing diagram and a series of graphs that are specific to the Anti-Malware security engine. For detailed information about the functionality included on this page, see the  Monitor Anti-Malware  security engine help topic. To view your security logs in MyAryaka, navigate to the  Security  >  Monitor  page and then use the Quicklink toolbar floating at the bottom of the page to access the Security Logs page. The following graphic displays two security logs where traffic was permitted and one where it was denied: You can use the advanced filter to display, for example, only logs where a specific action was taken after inspection by the Anti-Malware security engine. For detailed information about security logs, see the  View security logs  help topic. In this topic