SIG的无花果首页SIG的无花果新闻SIG的无花果通过电子邮件SIG的无花果最热门的职位
重要人物
Helping you, by helping myself with blogging, browsing, and tech tips 帮助您,帮助自己与博客,浏览和高新技术的秘诀

Do You Use Protection?您使用的保护呢?

May 2nd, 2008 · by David Bradley 2008年5月2日,由大卫布拉德利

保护 I’m not trying to get a sneak peak into your private life, but am interested in your privacy and safety.我不是要得到潜入山顶到您的私人生活,但很感兴趣,在您的隐私和安全。 If you are only using a conventional antivirus (AV) package whether that’s AntiVir (recommended), AVG (recommended) or any of the myriad other AV products, such as McAfee, f-Prot, or Norton, then you may not know that you are wide open to attack from malware particularly in between AV updates.如果您只使用常规的防病毒(影音)封装,无论是antivir (推荐) ,平均(推荐)或任何的无数其他影音产品,如McAfee的,架F - prot ,或Norton ,那么您可能不知道您是敞开的攻击,从恶意软件特别是在之间的AV更新。 How come, you ask?如何来,你问?

Well, the answer lies in understanding how conventional AV software works, and how new viruses, trojans, and other nasties can circumvent it.那么,答案就在于如何理解传统的AV软件工程,以及如何利用新的病毒,木马,及其他nasties可以规避它。 To detect a viral attack on your computer, your standard AV package monitors computer activity against an internal database of signatures.检测到病毒攻击您的电脑上,您的标准AV包监测计算机活动对内部数据库的签名。 These signatures are the “digital fingerprints” of viruses, trojans, and spyware.这些签名是“数码指纹”的病毒,木马及间谍软件等。 If the AV program spots one of these signatures being loaded into memory on your computer, it kicks into action and blocks any ensuing activity, protecting you from known malware.如果视听节目景点之一,这些签名被载入到记忆体在您的计算机上,它踢转化为行动和拦截任何随后的活动,保护你从已知恶意软件。

However, although every threat has a unique fingerprint, your AV software can only intercept it if it has a copy of that fingerprint in its internal database.不过,虽然每一种威胁有其独特的指纹,您的AV软件只能拦截,如果它有一个副本说,指纹图谱在其内部数据库。 You can update your AV software on a daily business, but what happens if a new virus emerges, which is very likely, between updates when no signature has yet been identified or added to the AV update?您可以更新您的AV软件对一的日常业务,但会发生什么,如果一个新的病毒出现,这是非常有可能,之间的更新时,没有签名至今尚未确定或添加到的AV更新?

There are some rare AV programs that use heuristics to spot activity that might be associated with viral activity, as well as monitoring signatures, but the most commonly used repeatedly misses new viruses and can lead to false positives.有一些罕见的AV程序使用启发式,以现货的活动,可能与病毒活性,以及监测签名,但最常用的一再错过了新的电脑病毒,并可能导致假阳性。 ThreatFire threatfire , is apparently different. ,是明显不同。 It labels itself as zero-day protection (zero-day referring to the fact that a virus can appear before standard AV software gets updated).它的标签本身作为零天保护(零天是指这样一个事实,即病毒可以出现之前,标准AV软件得到更新) 。

ThreatFire’s ActiveDefense technology closes those protection gaps. threatfire的activedefense技术关闭这些保护方面的差距。 It uses behavioral analysis instead of signatures to detect malicious activity. 它使用行为分析,而非签名来侦测恶意的活动。 This means it can protect you from threats so new your AV doesn’t even know about them yet. 这意味着它可以保护你不受威胁,使新您的AV甚至不知道他们还。

ThreatFire’s creators, PCTools, suggest that while its software can catch those attacks between AV updates, it’s probably a good idea to run a standard security suite with AV updating at least once daily on your system. threatfire的创作者, pctools ,建议的同时,其软件可以赶上这些袭击之间的AV更新,这可能是一个好主意,运行一个标准的安全套件的AV更新至少一次,每天在您的系统上。 One might say it’sa case of wearing both belt and suspenders, but perhaps more appropriately for the initial tone of this piece it’s more like using a double layer of, ahem, latex.一会说,这案件都身穿带和吊杆,但也许更恰当地为初步的语气,这一块它更喜欢使用双层的, ahem ,乳胶。

4 responses so far ↓四反应到目前为止↓

Leave a Comment留下意见

Comments are checked for spam before appearing, no need to post it twice.评论是检查垃圾邮件之前出现,不需要后两次。

Related Posts相关文章