本帖最后由 水墨静音 于 2016-8-2 16:05 编辑
既然有人放出了avast官方对加强模式和deepscreen运作方式的解释,那我就完整翻译下,让不明真相的人看看好了。
剧情也算是大反转,官方解释一出,生龙活虎胡诌乱编的终于消停了....还大家真相~
官方解释网址:https://support.business.avast.com/hc/en-us/articles/206435345-About-DeepScreen-Hardened-Mode
The two features share some “overlapping” functions and therefore there is no reason to turn them both on at the same time (if you do, the Hardened Mode will always prevail over the DeepScreen).
Simply put, the Hardened Mode is a means of “parental control” for executable files
When enabled, it is always running in the background and checking every process launched on the machine. The evaluation of files is based on their reputation coming from the cloud (controlled by the VLab).
•In the Aggressive Hardened Mode, only chosen executable files with known high ratings are allowed; the rest gets prevented from running.
•On the other hand, the Moderate Hardened Mode blocks only files which have bad ratings (and those which have no ratings at all, due to being new).
加强模式和DS有一些共同特征,所以两者无法同时运行(如果你要这么做,加强模式也永远优先于DS)
简单来说,加强模式是一种可执行文件的来源控制。
加强模式启用后,会在后台检查在机器中运行的每个进程,文件的运行判断基于云信誉。(由VLab实验室控制)
在激进模式下,只有那些高信誉的文件允许被运行,其余所有文件将被阻止运行。
另一方面,中等模式依靠其不良信誉去拦截文件(以及拦截那些还没有信誉信息的新文件)
The DeepScreen, when active, works similarly in the background and checks all the executable files being launched. It also works with the cloud data about their reputations.
However, unlike the Hardened Mode, this tool is also capable of running a file which has no rating (or insufficient number of ratings – usually below 20-50, depending on the file) in the sandbox to test its behavior (compare it with malicious patterns) and then decide whether to allow or block it.
Thus:
•all files with known good or average ratings are automatically allowed;
•all files with known bad ratings are automatically blocked as malware (even if they are not in the VPS yet and therefore not blocked by the webshield) and the data on such incidents are sent to the VLab (to include in the VPS, if appropriate);
•lastly, files which are “unknown” or “not known well enough” are tested in the sandbox, allowed or blocked accordingly, and the rating resulting from the DeepScreen testing gets added to the cloud of reputations.
当DeepScreen运行时,同样在后台检查被加载的可执行文件,DS的运行同样基于这些文件的云信誉。但是,跟加强模式不同的是,DS可以在沙箱环境中运行那些没有信誉的新文件(或信誉值低的文件,通常信誉值在20~50,取决于文件的不同)来测试这些文件的行为,之后再决定是否允许其运行或拦截。
因此
所有高信誉文件或平均信誉值的文件将会被允许运行
所有低信誉的文件将会被作为恶意软件拦截,其数据将被发送到VLab
最后,那些未知文件或流行度不高的文件将会在沙盒中运行,根据情况放行或拦截,其结果将由DS加入云信誉数据中。
----------------------------------------------------------------------------------------------------------------------------------------------
整篇下来我给大家总结下
即,加强模式完全靠云信誉拦截
中等模式:不良信誉和没有信誉信息的新文件会被拦截
激进模式:只允许运行信誉高的文件,其余文件将被拦截
另外关于DS,我想,用过小a的应该是很清楚了,之前小a的DS如果要启用,双击文件后,会弹出正在分析(而不是拦截),通常DS弹窗出来后要转圈,等个几十秒甚至一分钟,最后才会出来DS的分析结果。(顺便说下,现在的小a已经没有本地DS了)
可以看到,加强模式本身没有任何行为分析和拦截的功能,所以之前qftest在那声称加强模式检测到了软件异常动作,不是在鬼扯是什么?还编造一堆根据官方对加强模式的解释,根据某某官人对加强模式的解释,来给自己胡说的加强模式可以检测行为的说法找论据,被驭龙亲自打脸加强模式不是行为后好像自己很高尚,懒得争论一样,难道不对自己的胡诌道歉?我坚持真相,给大家普及真相反倒要讽刺我。
与其认定自己所认定的在那鬼扯误导别人,不如承认下真相,让更多人知道如何?
|