* The detection using the database of virus signatures (virus signature database): How this antiviral approach that is widely used by traditional anti-virus, the search for signs of the presence of the virus by using a small portion of virus code that has been analyzed by antivirus vendor, and has been categorized according to the type, size, power and smash a few other categories. This can be calculated fast and reliable to detect the virus-the virus that has been analyzed by antivirus vendor, but can not detect the new virus until the virus signature database is installed in the new system. Virus signature database can be obtained from the antivirus vendor, and generally can be obtained for free via download or via subscription (subscription).
* The detection to see how the virus works: How it works is like this antiviral approach borrowed from the new technology that is applied in the Intrusion Detection System (IDS). This is often referred to as Behavior-blocking detection. This is the policy (policies) that should be applied to detect the presence of a virus. If there is software that behavior "not reasonable" according to the policy that is applied, as well as the software tries to access the address book to send e-mail in bulk to the list of e-mail that is in the address book is (it is often used by virus to transmit the virus through e-mail), then the antivirus will stop the process undertaken by the software. Antivirus can also isolate codes suspected virus as administrator to determine what to do next. The advantage of this is the antivirus can detect the new virus-the virus that has not been recognized by the virus signature database.The weakness, clearing way to monitor the antivirus software business as a whole (not the monitor), it often makes anti-virus false alarm or "False Alarm" (if the antivirus configuration too "loud"), or even allow the virus to multifly in the system (if antivirus configuration is too "soft"), false positive occurred. Some manufacturers call this technique as a heuristic scanning.
Antivirus which uses behavior-blocking detection is still a little amount, but in the future, most likely all will use antivirus this way. Some antivirus also use two methods on the same time

Tidak ada komentar:
Posting Komentar