本帖最后由 驭龙 于 2015-10-20 14:37 编辑
如题
八月四日特征码总数4198万
八月五日特征码总数3593万
官方链接
http://www.symantec.com/security ... .jsp?certid=2015-08
一次性缩减六百万的特征码,是不是很疯狂?所以下次不要再说Symantec不会优化特征库了,因为优化是很猛烈的,而且SAPE特征与日俱增,Symantec的特征库已经不再是一味的入库和臃肿了。
我再补上关于SAPE Technology的技术内容:
SAPE is a heuristic technology designed to detect several different classes of risks. Heuristic detections protect against many risk families that share similar characteristics and can often provide wider and faster detection for fast evolving risks.
Category: Virus
A file detected with the SAPE technology, that has the category of Virus, is a Trojan and is deemed by Symantec to pose a security threat. Symantec will detect and block these files from accessing the computer. These files are considered malicious and may have the potential to cause harm to a system in the form of destruction, disclosure, data modification, and/or Denial of Service (DoS).
Category: Adware
A file detected with the SAPE technology, that has the category of Adware, is considered a security risk. These include programs that facilitate delivery for advertising content to the user and in some cases gather information from the user's computer, including information related to Internet browser usage or other computer habits.
Category: Security Risk or Misleading Application
A file detected with the SAPE technology, that has the category of Security Risk or Misleading Application, is a PUA (Potentially Unwanted Application). SAPE PUA detects programs that users may wish to be made aware of. These programs include applications that have an impact on security, privacy, resource consumption, or are associated with other security risks. These programs can show a pattern of installation without user permission or notice on a system or be deemed to be separate and different from the application installed.
机器翻译:
SAPE是用来检测几个不同的类风险的启发式技术。启发式检测防止许多相似特征,并且常常可以提供更广泛,更快速检测,快速发展的风险,风险的家庭。
分类:病毒
与SAPE技术检测的文件,有病毒的范畴,是一个木马程序,是由赛门铁克认为构成安全威胁。赛门铁克将检测和访问计算机阻止这些文件。这些文件被认为是恶意的,并且可以具有造成损害的系统中破坏,公开内容,数据修改的形式的潜力,和/或拒绝服务(DoS)的。
类别:广告软件
与SAPE技术检测的文件,有广告软件的范畴,被认为是安全风险。这些包括促进递送广告内容给用户,在某些情况下,收集来自用户的计算机的信息,包括与互联网浏览器的使用情况或其它电脑习惯的信息的程序。
类别:安全风险或具误导性的应用
与SAPE技术检测的文件,有安全风险或具误导性的应用的范畴,是一个PUA(可能有害的应用程序)。 SAPE PUA检测到用户不妨方案,使知之。这些程序包括对安全,隐私,资源消耗产生影响,或与其他安全风险关联的应用程序。这些程序可以显示安装未经用户许可或通知的模式在系统上还是被认为是独立的,不同的安装应用程序。
这真的是Symantec特征库的未来啊,希望它快一点强大起来
官方原文:http://www.symantec.com/security_response/sape/ |