GB/T 35277-2017 in English
VALIDInformation security technology―Security technical requirements and testing and evaluation approaches for antivirus gateway products
- Issued on:2017-12-29
- Implemented on:2018-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$592.00
| Standard No: | GB/T 35277-2017 |
| Document status: | VALID |
| Title in English: | Information security technology―Security technical requirements and testing and evaluation approaches for antivirus gateway products |
| Title in Chinese: | 信息安全技术 防病毒网关安全技术要求和测试评价方法 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2017-12-29 |
| Implemented on: | 2018-07-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Professional Classification: | GB-National Standard |
| Related Topics: | GB/T 35277-2017
gateway virus security test evaluation GBT35277 GB/T 35277-2017 Information Security Test Score |
《GB/T 35277-2017信息安全技术 防病毒网关安全技术要求和测试评价方法》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Analysis of the core content of the standard
The GB/T 35277-2017 standard constructs a complete technical framework that includes the functions, performance, and security requirements of anti-virus gateway, and implements differentiated protection capability requirements through a basic and enhanced level grading system.
Comparison of key technical requirements
| Dimensions | Basic level requirements | Enhanced level extension requirements |
|---|---|---|
| Protocol support | HTTP/FTP/SMTP/POP3 | Add IMAP protocol support |
| Detection capability | Static virus detection rate ≥ 90% | Dynamic virus detection + evasion technology detection |
| Performance indicators | No requirements | TCP concurrency ≥ 700,000/new creation ≥ 10,000 per second |
Typical application scenarios
Deployment case in the financial industry: A bank uses an enhanced anti-virus gateway to achieve:
- Dual-machine hot standby architecture ensures failover time of <1 minute
- Deep detection of HTTPS traffic to identify encrypted channel threats
- Link with SIEM system to share threat intelligence
Implementation suggestions
- Level selection: Critical information systems should give priority to meeting the enhanced level requirements
- Protocol compatibility: IPv6 networks need to verify tunnel technology implementation
- Performance planning: Reserve 30% performance margin according to the indicators in Section 6.3.2
Key points of test method
Chapter 6 of the standard specifies three types of testing methods in detail:
- Functional verification:Use the virus sample library provided by the standard (including 2000+ basic samples)
- Performance testing:Requires special testing equipment to simulate Gbps-level traffic
- Security assessment:Includes penetration testing and vulnerability scanning

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 32915-2016 in English
Information security technology - Binary sequence randomness detection method
2016-08-29 -

GB/T 32213-2015 in English
Information security technology―Public key infrastructure―Specification for remote password authentication and key establishment
2015-12-10 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 34095-2017 in English
中华人民共和国国家质量监督检验检疫总局 中国国家标准化管理委员会
2017-07-31 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 29241-2012 in English
Information security technology—Public key infrastructure—PKI interoperability evaluation criteria
2012-12-31