2
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

AIX環境へのClamAV導入手順

2
Last updated at Posted at 2026-09-23

はじめに

AIX では、オープンソースのソフトウェアである ClamAV を用いてマルウェアのスキャンを行うことができます。

さらに、IBM PowerSC を活用することで、複数台の AIX LPAR に導入された ClamAV の定義ファイル更新状況やスキャンステータス、検知アラートを Web GUI 上で一元管理することが可能です。

本記事では、AIX 上に ClamAV を導入・初期設定し、PowerSC GUI と連携した際の作業メモです。

全体概要と構成イメージ

+-------------------------------------------------------------+
|               PowerSC GUI Server (Web GUI)                  |
|  - マルウェア対策ステータス確認 / 定義ファイル更新管理 / スキャン指示  |
+-------------------------------------------------------------+
                               |
                               | 
                               v
+-------------------------------------------------------------+
|                      対象 AIX LPAR                           |
|                                                             |
|   +-----------------------+     +-----------------------+   |
|   |   PowerSC GUI Agent   | <-> |         ClamAV        |   |
|   +-----------------------+     |                       |   |
|                                 |                       |   |
|                                 +-----------------------+   |
+-------------------------------------------------------------+

実施環境

OS AIX 7.3 TL3 SP0
ハードウェア IBM Power S922
PowerSC バージョン PowerSC V2.3
パッケージ管理 AIX Toolbox から dnf が導入済み

1. AIX Toolbox から ClamAV のインストール

AIX Toolbox から AIX 向けにコンパイル・提供されている ClamAV パッケージを dnf を使用してインストールしました。

AIX Toolbox で提供されている ClamAV のパッケージを確認しました。

# dnf list clamav
AIX generic repository                                           2.8 kB/s | 1.3 kB     00:00
AIX noarch repository                                            2.9 kB/s | 1.3 kB     00:00
AIX 7.3 specific repository                                      2.9 kB/s | 1.3 kB     00:00
Available Packages
clamav.ppc                                1:1.4.6-1                                AIX_Toolbox_73

ClamAV のパッケージをインストールしました。

# dnf install clamav
Last metadata expiration check: 0:20:48 ago on Wed Sep 23 07:11:24 JST 2026.
Dependencies resolved.
======================================================================================================================
 Package                  Architecture          Version                        Repository                        Size
======================================================================================================================
Installing:
 clamav                   ppc                   1:1.4.6-1                      AIX_Toolbox_73                   108 M

Transaction Summary
======================================================================================================================
Install  1 Package
(省略)

インストールされた ClamAV のバージョンを確認しました。

# clamscan --version
ClamAV 1.4.6

2. ClamAV の初期設定

インストール直後の設定ファイルにはサンプルのコメントアウト(Example 行)が含まれているため、実運用向けに設定を編集しました。

2.1 freshclam(定義ファイル更新ツール)の設定

freshclam.conf.sample を /opt/freeware/etc/clamav/freshclam.conf にコピーしました。

# cp /opt/freeware/etc/clamav/freshclam.conf.sample /opt/freeware/etc/clamav/freshclam.conf

/opt/freeware/etc/freshclam.conf のファイル先頭にある Example の行をコメントアウトし、DatabaseOwner を root にしました。

# vi /opt/freeware/etc/freshclam.conf
# Comment or remove the line below.
Example
(省略)
DatabaseOwner root

ClamAV の権限を変更しました。

# ls -l /var/lib | grep clamav
drwxr-xr-x    2 root     system          256 Aug 11 14:42 clamav
# chmod -R 700 /var/lib/clamav
# ls -l /var/lib | grep clamav
drwx------    2 root     system          256 Aug 11 14:42 clamav

ClamAV のデータベースを最新の状態までアップデートしました。

# freshclam update
ClamAV update process started at Wed Sep 23 08:10:12 2026
WARNING: Can't query current.cvd.clamav.net
WARNING: Invalid DNS reply. Falling back to HTTP mode.
Trying to retrieve CVD header from https://database.clamav.net/daily.cvd
Time:    0.2s, ETA:    0.0s [========================>]       512B/512B
OK
daily database available for download (remote version: 28131)
Time:    0.3s, ETA:    0.0s [========================>]   22.35MiB/22.35MiB
Testing database: '/var/lib/clamav/tmp.25593e5f03/clamav-c2635f62a9f9867e64e743a49ddb5fbd.tmp-daily.cvd' ...
Database test passed.
daily.cvd updated (version: 28131, sigs: 355666, f-level: 90, builder: svc.clamav-publisher)
Trying to retrieve CVD header from https://database.clamav.net/main.cvd
Time:    0.0s, ETA:    0.0s [========================>]       512B/512B
OK
main database available for download (remote version: 63)
Time:    0.9s, ETA:    0.0s [========================>]   84.95MiB/84.95MiB
Testing database: '/var/lib/clamav/tmp.25593e5f03/clamav-1dd197be2a546646a05ddb79bf10ecb8.tmp-main.cvd' ...
Database test passed.
main.cvd updated (version: 63, sigs: 3287027, f-level: 90, builder: tomjudge)
Trying to retrieve CVD header from https://database.clamav.net/bytecode.cvd
Time:    0.0s, ETA:    0.0s [========================>]       512B/512B
OK
bytecode database available for download (remote version: 339)
Time:    0.1s, ETA:    0.0s [========================>]  275.10KiB/275.10KiB
Testing database: '/var/lib/clamav/tmp.25593e5f03/clamav-c75519f758a81df7ee4a598b8918e9b1.tmp-bytecode.cvd' ...
Database test passed.
bytecode.cvd updated (version: 339, sigs: 80, f-level: 90, builder: nrandolp)

AIX uiAgent を再起動しました。

# stopsrc -s pscuiagent
0513-044 pscuiagent サブシステムは停止を要求されました。
# startsrc -s pscuiagent
0513-059 pscuiagent サブシステムは始動しました。サブシステム PID は 15204724 です。

3. 手動スキャンのテスト実行

正常に検知エンジンが動作するか、AIX 上でテストスキャンを実施しました。

3.1 通常スキャンの実行

/tmp ディレクトリをスキャン

CLIの場合

# clamscan -r /tmp

GUIの場合
ブラウザからPowerSC GUI Serverにログイン後、「セキュリティー」→対象LPARのアクション覧の「︙」→「マルウェア」→「マルウェアの構成」を選択しました。

image.png

スキャンするファイル・パスとして /tmp を選択し、保存しました。
image.png

再び対象LPARのアクション覧の「︙」→「マルウェア」を選択し、「マルウェア・スキャンの実行」をクリックしスキャンを実行しました。
image.png

画面上部の「レポート」からマルウェア・スキャンの開始と完了のイベント・ログを確認できました。
image.png

以上

2
0
1

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
2
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?