IMSVA leverages
ATSE to determine which messages are sent to Deep Discovery Advisor.
When enabled, ATSE provides an additional layer of protection against
advanced threats, such as document exploits and other threats used
in targeted attacks.
ATSE detections are identifiable through the prefixes HEUR and EXPL.
If the detection name contains one of these prefixes, IMSVA:
Deep Discovery Advisor assigns
a risk level to each analyzed message. IMSVA queries
this risk level approximately 15 minutes after sending the message
to Deep Discovery Advisor.
After receiving the risk level, IMSVA logs
the detection as a Probable advanced threat or an Analyzed
advanced threat based on the risk level and the security
level that you select on the IMSVA management
console.
 |
Note
If IMSVA does
not receive a risk level, or if the risk level returned is invalid, IMSVA logs
the detection as a Probable advanced threat.
|