|
|
|
sponsored by ESET
|
|
|
Posted:
|
15 Oct 2009
|
|
Published:
|
14 Sep 2009
|
|
Format:
|
PDF
|
|
Length:
|
14
Page(s)
|
|
Type:
|
White Paper
|
|
Language:
|
English
|
|
|
ABSTRACT:
Once upon a time, one infection by specific malware looked much like another infection, to an antivirus scanner if not to the naked eye. Even back then, virus naming wasn't very consistent between vendors. In 2009, though, the threat landscape looks very different. Viruses and other replicative malware, while far from extinct, pose a comparatively manageable problem compared to other threats with the single common characteristic of malicious intent.
Detection techniques such as generic signatures, heuristics and sandboxing have also changed the ways in which malware is detected and therefore how it is classified, confounding the old assumptions of a simple one-to-one relationship between a detection label and a malicious program. This presentation will explain how one-to-many, many-to-one, or many-to-many models are at least as likely as the old one-detection-per-variant model, why "Do you detect Win32/UnpleasantVirus.EG?" is such a difficult question to answer, and explain why exact indication is not a pre-requisite for detection and remediation of malware, and actually militates against the most effective use of analysis and development time and resources.
|
|
|
|
 |
BROWSE RELATED
RESOURCES
Anti-Spam Software | Anti-Spyware Software | Cybersecurity | Malware | Security Management | Security Threats | Virus Detection Software | Virus Protection
|
View All Resources
sponsored by ESET
|
|
|
|
|
SecurityPark Research Library Copyright © 1998-2009 Bitpipe, Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. TechTarget · 117 Kendrick St · Needham, MA · 02494
Use of this web site constitutes acceptance of the Bitpipe Terms and Conditions and Privacy Policy. webmaster@bitpipe.com
|