buchspektrum Internet-Buchhandlung

Neuerscheinungen 2011

Stand: 2020-01-07
Schnellsuche
ISBN/Stichwort/Autor
Herderstraße 10
10625 Berlin
Tel.: 030 315 714 16
Fax 030 315 714 14
info@buchspektrum.de

Robert Schneider, Patrick Winkler (Beteiligte)

What the virus


A behavior-aware multi-engine malware scanning service
2011. 108 S.
Verlag/Jahr: VDM VERLAG DR. MÜLLER 2011
ISBN: 3-639-35939-9 (3639359399)
Neue ISBN: 978-3-639-35939-8 (9783639359398)

Preis und Lieferzeit: Bitte klicken


Anti-virus software is a key security technology on today´s end user systems. Current anti-virus engines use two complementary techniques to detect malware. One is to statically scan potential malware sample files for certain patterns which are known ("malware signatures"). The other is to dynamically detect typical malicious behavior (e.g., modifications of registry keys, DLL injections etc.) upon execution of a sample. No anti-virus product can reliably detect malware. Rather, all products are plagued by false positives and false negatives. An interesting approach to improve the reliability of detection is to run several anti-virus products on a given malware sample. There are several online scanning services, that implement this approach. However, for performance reasons these services only use the static signature detection functionality of the anti- virus products, and thus do not take advantage of the full functionality of current anti-virus engines. This book explains how to overcome this limitation and to build an efficient online malware scanning service that fully utilizes the capabilities of current anti-virus engines.
Robert Schneider, geboren 1961, lebt in Meschach, einem Bergdorf in Vorarlberg. Für seinen Debütroman (1992) erhielt er zahlreiche in- und ausländische Preise.