SIG的無花果首頁SIG的無花果新聞SIG的無花果通過電子郵件SIG的無花果最熱門的職位
重要人物
Helping you, by helping myself with blogging, browsing, and tech tips 幫助您,幫助自己與博客,瀏覽和高新技術的秘訣

Do You Use Protection?您使用的保護呢?

May 2nd, 2008 · by David Bradley 2008年5月2日,由大衛布拉德利

保護 I’m not trying to get a sneak peak into your private life, but am interested in your privacy and safety.我不是要得到潛入山頂到您的私人生活,但很感興趣,在您的隱私和安全。 If you are only using a conventional antivirus (AV) package whether that’s AntiVir (recommended), AVG (recommended) or any of the myriad other AV products, such as McAfee, f-Prot, or Norton, then you may not know that you are wide open to attack from malware particularly in between AV updates.如果您只使用常規的防病毒(影音)封裝,無論是antivir (推薦) ,平均(推薦)或任何的無數其他影音產品,如McAfee的,架F - prot ,或Norton ,那麼您可能不知道您是敞開的攻擊,從惡意軟件特別是在之間的AV更新。 How come, you ask?如何來,你問?

Well, the answer lies in understanding how conventional AV software works, and how new viruses, trojans, and other nasties can circumvent it.那麼,答案就在於如何理解傳統的AV軟件工程,以及如何利用新的病毒,木馬,及其他nasties可以規避它。 To detect a viral attack on your computer, your standard AV package monitors computer activity against an internal database of signatures.檢測到病毒攻擊您的電腦上,您的標準AV包監測計算機活動對內部數據庫的簽名。 These signatures are the “digital fingerprints” of viruses, trojans, and spyware.這些簽名是“數碼指紋”的病毒,木馬及間諜軟件等。 If the AV program spots one of these signatures being loaded into memory on your computer, it kicks into action and blocks any ensuing activity, protecting you from known malware.如果視聽節目景點之一,這些簽名被載入到記憶體在您的計算機上,它踢轉化為行動和攔截任何隨後的活動,保護你從已知惡意軟件。

However, although every threat has a unique fingerprint, your AV software can only intercept it if it has a copy of that fingerprint in its internal database.不過,雖然每一種威脅有其獨特的指紋,您的AV軟件只能攔截,如果它有一個副本說,指紋圖譜在其內部數據庫。 You can update your AV software on a daily business, but what happens if a new virus emerges, which is very likely, between updates when no signature has yet been identified or added to the AV update?您可以更新您的AV軟件對一的日常業務,但會發生什麼,如果一個新的病毒出現,這是非常有可能,之間的更新時,沒有簽名至今尚未確定或添加到的AV更新?

There are some rare AV programs that use heuristics to spot activity that might be associated with viral activity, as well as monitoring signatures, but the most commonly used repeatedly misses new viruses and can lead to false positives.有一些罕見的AV程序使用啟發式,以現貨的活動,可能與病毒活性,以及監測簽名,但最常用的一再錯過了新的電腦病毒,並可能導致假陽性。 ThreatFire threatfire , is apparently different. ,是明顯不同。 It labels itself as zero-day protection (zero-day referring to the fact that a virus can appear before standard AV software gets updated).它的標籤本身作為零天保護(零天是指這樣一個事實,即病毒可以出現之前,標準AV軟件得到更新) 。

ThreatFire’s ActiveDefense technology closes those protection gaps. threatfire的activedefense技術關閉這些保護方面的差距。 It uses behavioral analysis instead of signatures to detect malicious activity. 它使用行為分析,而非簽名來偵測惡意的活動。 This means it can protect you from threats so new your AV doesn’t even know about them yet. 這意味著它可以保護你不受威脅,使新您的AV甚至不知道他們還。

ThreatFire’s creators, PCTools, suggest that while its software can catch those attacks between AV updates, it’s probably a good idea to run a standard security suite with AV updating at least once daily on your system. threatfire的創作者, pctools ,建議的同時,其軟件可以趕上這些襲擊之間的AV更新,這可能是一個好主意,運行一個標準的安全套件的AV更新至少一次,每天在您的系統上。 One might say it’sa case of wearing both belt and suspenders, but perhaps more appropriately for the initial tone of this piece it’s more like using a double layer of, ahem, latex.一會說,這案件都身穿帶和吊桿,但也許更恰當地為初步的語氣,這一塊它更喜歡使用雙層的, ahem ,乳膠。

4 responses so far ↓四反應到目前為止↓

Leave a Comment留下意見

Comments are checked for spam before appearing, no need to post it twice.評論是檢查垃圾郵件之前出現,不需要後兩次。

Related Posts相關文章