Showing posts with label Software. Show all posts
Showing posts with label Software. Show all posts

Thursday, February 10

How Antivirus Software Works

Ultimate Zip Cracker Software Download

How antivirus works

Due to the growing threat of virus and other malicious programs, almost every computer comes with a pre-installed antivirus on it. In fact, an antivirus program has become one of the most important software package for each computer. Although each of us has an antivirus software installed on our computers, only a few bother to actually understand how it really works! If you are one among those few who really worthwhile to understand how it works, an antivirus, then this article is for you.

 

 

An antivirus software typically uses a variety of strategies to identify and remove viruses, worms and other malicious programs. The following are the two methods most widely employed for recognition:

 

1. Signature based dectection (Dictionary)

 

This is usually employed method which includes the search for known virus patterns into a specific file. Any antivirus software will have a dictionary with sample malware codes signatures called in its database. Whenever a file is examined, the antivirus refers to the dictionary of sample codes presence inside the database and compares the same as the current file. If the piece of code within the file matches the one in the dictionary then it is flagged and appropriate action is taken immediately in order to stop the virus from further reproduction. Antivirus may choose to repair the file, isolating or deleted permanently on the basis of the potential risk.

As new viruses and malwares are created and released every day, this detection method is unable to mark new malwares unless their samples are collected and signatures are released by the company of antivirus software. Some companies may also encourage users to upload new viruses and variants, so that they can analyse the virus and the signature can be added to the dictionary.

Signature based detection can be very effective, but requires frequent updates to the virus signature dictionary. Therefore, users must update their antivirus software on a regular basis in order to defend against new threats released daily.

 

2. Heuristic based detection (approach suspicious behaviour)

 

Based on the heuristic detection involves determining suspicious behavior from any given program may indicate a potential risk. This approach is used by some of the advanced antivirus software to identify new malware and variants of known malware. Unlike signature-based approach, the antivirus does not attempt to identify known viruses, but instead monitors the behavior of all programs.

For example, malicious behaviors, such as a program tries to write data to an executable program is highlighted and the user is alerted about this action. This method provides an additional level of detection from unknown threats.

File emulation: this is another type heuristic approach where a program that runs in a virtual environment and recorded actions performed by it. Based on the actions which have been recorded, the antivirus software can determine if the program is malicious or not, and to carry out necessary actions in order to clean the infection.

Most commercial antivirus software uses a combination of both heuristic and signature-based approaches to combat malicious software.

 

Issues facing

 

Zero-day threats: is a zero-day (zero hour) a threat or an attack where a malicious software that tries to exploit vulnerabilities application not yet unidentified by the antivirus companies. These attacks are used to cause damage to your computer, even before being recognized. Since the patches are not yet released for such new threats, you can manage easily bypass the antivirus software and perform malicious actions. However, most of the threats identified after a day or two away from release, but the damage caused by them before the recognition is absolutely unavoidable.

Daily updates means since new viruses and threats are released daily, it is now essential to update the antivirus software in order to keep the virus definitions updated. Most software will have an automatic update feature, so that the virus definitions are updated whenever the computer is connected to the Internet.

effectiveness: even if an antivirus software can match almost any malware, is still not 100% foolproof against all kinds of threats. As explained earlier, a zero-day threat can easily bypass the shield antivirus software. Also the virus authors tried to stay one step ahead by writing (oligomorphic groups) "," polymorphic "and, more recently," transformed "virus codes, which will encrypt parts themselves or amend the same as metamfiesmenos method, so that it fits with virus signatures in the dictionary.

Therefore, user education is as important as antivirus software? users must be trained to practice safe surfing habits, such as downloading files only from trusted websites and not blindly runs a program that is unknown or obtained from an untrusted source. I hope this article will help you understand the operation of an antivirus software.

Popularity: 5% [?]

Read also visitors who read this post:

  1. How to test your antivirus-test EICAR

  2. 10 tips to avoid Adware

  3. How to protect your computer against Keyloggers

  4. How firewalls work

  5. What is CAPTCHA and how does it work?


  By using this site, following you agree to our legal disclaimer

Ultimate Zip Cracker Software Download

Sunday, February 6

Hardware, software, to help protect operating systems from attack

Ultimate Zip Cracker Software Download

ScienceDaily (January 27, 2011) operating system (OS) is the backbone of your PC. If the operating system is compromised, attackers can take over your computer or crash it. Now researchers at the University of North Carolina have developed an efficient system that utilizes hardware and software to restore the operating system if it is attacked.

In each issue are security attacks where the outside party successfully compromises a computer application (such as a Web browser) and then uses the application to access the operating system. For example, the compromised application could result in "system call" operating system, effectively asking the operating system to perform a particular function. However, instead of routine function, the attacker will use the system call to try to gain control of the operating system.

"Our goal is to give the ability to survive such attacks, the operating system," says Dr. Yan Solihin, Professor of the partner computer engineering and power in NC co-author of a paper describing the new system. "Our approach has three elements: the attack detection; Security fault isolation; And recovery. "

The idea is to take a picture of the operating system while strategies points (such as system calls or interrupts), when functioning as usual, then, if attacked the operating system, to delete what they did since the picture was taken last "good" – effectively back in time before attacking OS. The engine also allows the operating system to identify the source of the attack and isolate it, so the operating system will no longer be vulnerable to attacks from the same application.

The idea of identifying attacks, re-setting system into safe mode is a well-known technique for restoring the normal functions of the system after a failure, but this is the first time that researchers have developed a system with the security element of fault isolation. This critical component prevents the operating system to attack it ???????? over and over again.

The idea of taking images of the operating system and using it to replace the operating system if it is a candidate was previously viewed as practical, because taking these images, and running the system such as significantly slowdown your computer operating speeds. "But we've developed the hardware support that allows the operating system to combine these elements of survival more efficiently, so they take up less time and energy," says Solihin. Researchers say survival system takes up less than 5 percent of the operating system overhead.

The paper, "an architectural Framework for operating system support, survival" was co-authored Solihin, student NC State ph. d. Former Jiang Xiaowei. The paper will be February 16 at IEEE International Convention on the high-performance computer architecture in San Antonio, Texas. The research supported, in part, by the National Science Foundation.

NC State Department of Electrical engineering methods computer is part of the College of engineering of the University.

E-mail or share this story:


Story source:

The story above printed (with adapting to editing by the team of the day-to-day science) materials provided by the of the University of North Carolina.

Note: you mentioned when not composing, source is created instead.

Disclaimer: views expressed in this article do not necessarily reflect those of its employees or ScienceDaily.

Ultimate Zip Cracker Software Download

Saturday, February 5

How Antivirus Software Works

Ultimate Zip Cracker Software Download

How antivirus works

Due to the growing threat of virus and other malicious programs, almost every computer comes with a pre-installed antivirus on it. In fact, an antivirus program has become one of the most important software package for each computer. Although all of us have an antivirus software installed on our computers, only a few bother to actually understand how it really works! Well, if you are one among those few who really worthwhile to understand how it works, an antivirus, then this article is for you.

 

 

An antivirus software typically uses a variety of strategies in detecting and removing viruses, worms and other malware programs. The following are the two methods most widely employed for recognition:

 

1. Signature based dectection (dictionary)

 

This is the most commonly employed a process which involves the search for known virus patterns within a given file. Any antivirus software will have a dictionary of the sample malware codes signatures called in its database. Whenever a file is examined, the antivirus is mentioned in the dictionary of sample codes present in the database and compares the same as the current file. If the piece of code within the file matches the one in the dictionary then it is flagged and proper action is taken immediately in order to stop the virus from further reproduction. The antivirus program can choose to repair the file quarantine or delete it permanently from potential risk.

As new viruses and malwares are created and released every day, this detection method cannot defend against new malwares unless their samples are collected and signatures are released by antivirus software company. Some companies may also encourage users to upload new viruses and variants, so that they can analyse the virus and the signature can be added to the dictionary.

Signature based detection can be very effective, but requires frequent updates to the virus signature dictionary. Hence users should update their antivirus software on a regular basis in order to defend against new threats released daily.

 

2. Heuristic based detection (approach suspicious behaviour)

 

Based on the heuristic detection involves determining suspicious behavior from any given program may indicate a potential risk. This approach is used by some of the advanced antivirus software to identify new malware and variants of known malware. Unlike signature-based approach, the antivirus does not attempt to identify known viruses, but instead monitors the behavior of all programs.

For example, malicious behaviors, such as a program tries to write data to an executable program is flagged and the user is alerted about this action. This method provides an additional level of detection of security threats of unidentified.

Simulation of file: this is another type of approach based on heuristic where a given program is running in a virtual environment and recorded actions performed by it. Based on the actions logged, the antivirus software can determine if the program is malicious or not and to carry out any actions necessary in order to clean the infection.

Most commercial antivirus software uses a combination of both heuristic and signature-based approaches to combat malicious software.

 

Issues facing

 

Zero-day threats: A zero-day (zero hour) threat or attack where a malicious software that tries to exploit computer application vulnerabilities which have not yet unidentified by the antivirus companies. These attacks are used to cause damage to your computer, even before they are identified. Since the patches are not yet released for such new threats, you can manage easily bypass the antivirus software and perform malicious actions. However most of the threats identified after a day or two away from release, but damage was caused by them before recognition is absolutely unavoidable.

Daily updates means since new viruses and threats are released daily, it is now essential to update the antivirus software in order to keep the virus definitions updated. Most software will have an automatic update feature, so that the virus definitions are updated whenever the computer is connected to the Internet.

effectiveness: although an antivirus can catch almost any malware, is still not 100% foolproof against all kinds of threats. As explained earlier, a zero-day threat can easily bypass the protective shield of antivirus software. Virus writers also tried to stay one step ahead by writing "oligomorphic", "polymorphic" and, more recently, "metamorfikis" virus codes, which will encrypt portions of the same or otherwise modify themselves as a method of concealing, so that it fits with virus signatures in the dictionary.

Therefore, user education is as important as antivirus software? users must be trained to practice safe surfing habits, such as downloading files only from trusted websites and not blindly run a program that is unknown or obtained from an untrusted source. I hope this article will help you understand the operation of an antivirus software.

Popularity: 4% [?]

Read also visitors who read this post:

  1. How to test your Antivirus – working EICAR test

  2. 10 tips to avoid Adware

  3. How to protect your computer against Keyloggers

  4. How firewalls work

  5. What is CAPTCHA and how does it work?


  From this site using/following you agree to our legal disclaimer

Ultimate Zip Cracker Software Download