4.2.3 Enable Outbreak Prevention Database

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Ensure FortiGate AV inspection uses outbreak prevention database as an added layer of protection on top of antivirus' signature-based detection.

Rationale:

Antivirus mainly uses signature for malware blocking. By enabling 'FortiGuard outbreak prevention database', FortiGate can leverage on 3rd party malware hash signatures curated by the FortiGuard as an additional protection layer.

The hash signatures are obtained from FortiGuard's Global Threat Intelligence database. The antivirus database queries FortiGuard with the hash of a scanned file. If FortiGuard returns a match, the scanned file is deemed to be malicious.

Solution

Review Antivirus Security Profiles and validate that 'Use FortiGuard outbreak prevention database' is enabled.

Default Value:

Disabled

See Also

https://workbench.cisecurity.org/benchmarks/10730