首页> 外文期刊>Virus Bulletin >ANTI-VIRUS VS ANTI-VIRUS: FALSE POSITIVES IN AV SOFTWARE
【24h】

ANTI-VIRUS VS ANTI-VIRUS: FALSE POSITIVES IN AV SOFTWARE

机译:反病毒与反病毒:视听软件中的假阳性

获取原文
获取原文并翻译 | 示例
       

摘要

Anti-virus tools from one company often have problems co-existing with the tools from another, especially in the area of false positives. Some of these problems could easily be avoided- the developers would only need to store their virus signatures properly encrypted in all parts of the program, the engine and the virus definition files. Not only should the virus signatures be encrypted to avoid false positives, but also to provide a form of protection against virus writers (who, having access to the easily-visible signatures can create new variants using different patterns) as well as protecting the company's intellectual property. A simple runtime-compression or encryption of the whole executable file is not a viable option, because many anti-virus tools are able to uncompress or decrypt such programs easily. Therefore they would still find the signatures that caused the false positive. In addition, the detection routines of a number of anti-virus programs should be fine-tuned so that a single short signature found in a file does not result in a virus alert at all. Last but not least, it is important for anti-virus vendors to have a copy of all competitors' programs (including the most recent updates and special cleaning tools) in a false positive test set which should be scanned before releasing a new definition update.
机译:一家公司的防病毒工具通常会与另一家公司的工具共存问题,特别是在误报方面。这些问题中的某些问题很容易避免-开发人员只需要在程序的所有部分,引擎和病毒定义文件中存储正确加密的病毒签名即可。不仅应该对病毒签名进行加密以避免误报,而且还应提供一种形式的保护,以防止病毒编写者(使用易于查看的签名可以使用不同的方式创建新变体),并保护公司的知识分子。属性。对整个可执行文件进行简单的运行时压缩或加密不是可行的选择,因为许多防病毒工具都可以轻松地对此类程序进行解压缩或解密。因此,他们仍然会找到导致误报的签名。此外,应对许多防病毒程序的检测例程进行微调,以使在文件中找到的单个短签名根本不会导致病毒警报。最后但并非最不重要的一点是,对于防病毒供应商而言,在误报测试集中拥有所有竞争对手程序(包括最新更新和特殊清理工具)的副本非常重要,应在发布新的定义更新之前对其进行扫描。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号