Download presentation
Presentation is loading. Please wait.
1
Computer Networks I Antivirus explained By: Daniel Josefsson Daniel Josefsson dannej@gmail.com Kristoffer Wallin Kristoffer Wallin om>om>
2
Content History Malicious logic TrojansWormsViruses
3
Content, continued AntivirusScanningDictionaryHeuristicsSandboxingRemovalToday
4
History “I’M THE CREEPER : CATCH ME IF YOU CAN” Berndt Fix Beginning of 90’s Peter Tippett Virus distribution
5
Trojans Definition: A program with an overt (documented or known) effect and a covert (undocumented or unexpected) effect Payloads Remote Accessing Data Destruction Downloader Server Trojan(Proxy, FTP, IRC, Email, HTTP/HTTPS, etc.) Security software disabler Denial-of-service attack (DoS)
6
Worms Definition: A program that copies itself from one computer to another NetworkPayload
7
Viruses Definition: A program that inserts itself into one or more files and then performs some (possibly null) action InfectionVirus-Worms
8
Dictionary Requires frequently updated dictionary EncryptionPolymorphic
9
Heuristics Behavior Emulate files False positives
10
Sandboxing Emulate OS Performance issues
11
Removal Attempt to remove the malicious code Quarantine the file Delete the malicious file Might fail
12
Today Best detection rates by June 2008 (1) G DATA 2008 version 18.2.7310.844 - 99.05% F-Secure 2008 version 8.00.10 - 98.75% TrustPort version 2.8.0.1835 - 98.06% Detection of new viruses Whitelisting (1) http://www.virus.gr/portal/en/content/2008-06%2C-1-21-june http://www.virus.gr/portal/en/content/2008-06%2C-1-21-june
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.