Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
j1udith
New Contributor

Virus Outbreak Protection

I was digging into this feature wanted to get some real-world understanding.

Have you of had this service block something?

Is it only malware / file-based (assuming so since its in the AV Profile)

Is there anything comparable in the Palo world? Sounds a bit like Wildfire but Wildfire is more sandboxing. But it also has crowdsourcing since if one customers wildfire detects a file that is malicious everyone will get that wildfire update.

Thanks and appreciate any thoughts here.

omegle xender
3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Anthony-Fortinet Community Team.
Jean-Philippe_P
Moderator
Moderator

Hello j1udith,

 

I found this solution. Can you tell us if it helps, please?

 

The Virus Outbreak Protection Service (VOS) in FortiGate is designed to enhance antivirus protection by using malware hash signatures from FortiGuard’s Global Threat Intelligence servers. Here's a breakdown of your queries:

  1. Real-world Blocking: The VOS can block files deemed malicious by matching their hash against FortiGuard's database. This real-time detection helps in identifying zero-day threats before traditional signatures are available.

  2. File-based Protection: Yes, VOS is primarily file-based as it is part of the antivirus profile. It focuses on identifying malicious files through hash signature matching.

  3. Comparison with Palo Alto Networks:

    • Palo Alto Networks' WildFire is indeed more focused on sandboxing, where files are executed in a virtual environment to observe their behavior. It also uses crowdsourcing, where once a file is identified as malicious, the information is shared across all customers.
    • While both services aim to enhance threat detection, VOS relies on hash matching, whereas WildFire uses behavioral analysis in a sandbox environment.

Both services provide additional layers of security, but they operate using different methodologies.

Regards,
Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors