Unlike other anti-virus developers Sophos concentrates on business users and offers no specific consumer products. The main product, Sophos Anti-Virus (SAV), can be implemented on workstations, notebooks and servers, with versions available for a range of platforms including all versions of Windows from 95 to the latest Windows XP for desktops and Windows Server 2003. Dos, OS/2 and Apple Macintosh versions are also available, along with SAV for Novell Netware (3.2 and above), x86 versions of Linux and FreeBSD. A number of proprietary Unix platforms are catered for too, including AIX, HP-UX, Solaris and OpenVMS.
Third-party developers of email and other applications are able to use SAV to check for viruses through calls to the published API (SAVI), with a developers' toolkit available for this purpose. Sophos also offers a custom application called Mail Monitor that can be used with Microsoft Exchange (2000 and 2003), Lotus Notes/Domino and generic SMTP mail servers on a variety of Windows and Linux/Unix host platforms. And Pure Message checks SMTP mail for viruses and to screen out spam.
All implementations of SAV are based on the same anti-virus engine with on-demand and scheduled scanning, plus realtime on-access examination of open files using a separate Intercheck monitor. Scanning of compressed files and recursive archives is supported as standard, along with the ability to scan network shares. Every node can be updated directly from Sophos (you can get monthly updates on CD-Rom), but most customers opt for network deployment and centralised updates. Here the software is first put into a central installation directory (CID), from where it is installed onto each workstation or server. The CID version is then kept updated and each node automatically configured to update itself at regular intervals. The Intercheck monitor on each client can also be configured to co-ordinate alerting via a central network server.
The Sophos CID can be updated manually, but more usually EM Library, a Windows-based tool for NT4 or 2000, is used to automatically retrieve the updates to both the virus identify files and the software itself from the Sophos databank. This runs as an MMC snap-in and allows the databank to be checked up to 24 times a day. It's a relatively easy tool to set up, and for the most part can be left to get on with its job unaided. The initial download of the packages to be used can take some time, especially on a dial-up link, but later updates are much quicker.
Until recently EM library was called Enterprise Manager, but it's now rebranded and the old name reserved for a package of management tools which includes EM Library plus a reporting tool (EM Reporter) and Remote Update, which allows remote and mobile users to update their SAV software over an HTTP Internet connection.
Enterprise Manager includes a network management tool, SAVAdmin. This is installed on a Windows server or workstation and only works with Windows systems, but can identify protected and unprotected nodes and remotely install or update SAV software. You need an agent for 95, 98 and ME clients, but 2000 and XP machines are handled automatically.
Installation is straightforward but SAVAdmin isn't that easy to configure, especially on networks without a Windows domain server. However, the procedures are well documented and we had few problems getting it to work. Once configured it worked very smoothly with minimal intervention required.
Prices for Anti-Virus depend on the number of users and the level and length of support required. The prices quoted here are for 500 SAV Connect licences, which includes Enterprise Manager and a one-year support agreement.
Though scan times weren't as fast as some other software here, they weren't that slow either, and Sophos has a good record of identifying viruses in the wild. It was quick to alert us to the latest Netsky and Bagle worms which appeared during our tests, with timely updates released. A trial version of SAV is available on our cover disc of the June 2004 issue of Personal Computer World.
Contact: Sophos 01235 559 933
www.sophos.co.uk
Price details:
Price £16.45 (£14 ex VAT) per user (500+ users)
Back to corporate anti-virus tools group test
See also:
All Antivirus & Firewalls




