查看: 3848|回复: 3
收起左侧

[转帖] Behavior Shield: our newest behavioral analysis technology

[复制链接]
Q1628393554
发表于 2017-2-21 22:18:30 | 显示全部楼层 |阅读模式
自己好久没活动了,转个帖子吧,其实我也没时间看,不知道到底有多少干活,更别说翻译了。大家随便瞅瞅吧

另外,avast blog改版了。

Behavior Shield comes standard in all versions of Avast 2017, protecting you from zero-second threats, ransomware and other malicious programs

We recently released a new version of our flagship PC product, Avast 2017, which uses various engines, including CyberCapture, to scan for threats. Our engines are protection layers, that can step in at different stages to safeguard you from threats. An additional layer we added to Avast 2017 is a patent-pending technology that we call Behavior Shield.

Behavior Shield can be compared to real-life security that is on patrol duty at a major event. As real-life security would observe a crowd for suspicious or dangerous behavior, Behavior Shield monitors all the programs running on your PC that have passed through initial security checks. It carefully observes program behavior and if it notices something uncharacteristic, it starts looking even closer. Once it identifies something really fishy, it stops the action and reports the behavior to you, before any damage can be done. So, if for example, your mail client starts a javascript interpreter connecting to the internet, Behavior Shield will step in, as this isn’t normal behavior for a mail client and could lead to a malicious download.

This may sound relatively easy to do, but in fact, Behavior Shield is very complex under the hood. At the heart of it is a real-time graph that describes all the actions that the individual processes in the operating system are doing, including their relations, code injections, etc. On top of that, there is a lot of logic that allows us to distinguish good from bad – and for that, we rely on artifical intelligence, namely neural networks. And finally, there’s the powerful Avast cloud that puts all the actions in a global context and allows for ultra-fast reactions across all the protected endpoints.

With Behavior Shield we can protect against zero-second threats, malicious programs and cyber spying on passwords and bank account details that would normally not be possible using traditional detection methods. But the best thing about it is that it has proven to be especially powerful against ransomware. Although ransomware samples evolve and morph rapidly, they still exhibit specific behaviors that can be identified. Behavior Shield is capable of detecting and stopping new ransowmare variants that haven’t been seen before – something that’s been inherently difficult using other protection mechanisms.

While powerful, one would suspect Behavior Shield has a greater chance to report false positives. However, using a huge cloud-based database, we can filter these out as well. If there’s a program you absolutely trust, you can easily add it to exclusions and Behavior Shield will leave it unsupervised. Additionally, a copy of all reported files get sent to Avast for manual inspection, so any false positives won’t happen more than once.

Behavior Shield comes standards in all versions of Avast, including Avast Free Antivirus, and doesn’t need to be activated or set-up to start protecting you. It is yet another innovation brought to you by Avast to deliver on its mission of protecting you online, because we know you have better things to do.

来源:https://blog.avast.com/behavior- ... analysis-technology
pal家族
发表于 2017-2-21 22:41:17 | 显示全部楼层
本帖最后由 pal家族 于 2017-2-21 22:42 编辑

看了下,貌似就是一般的智能主防吧
也没用提到idp的回滚
Q1628393554
 楼主| 发表于 2017-2-22 20:08:35 | 显示全部楼层
pal家族 发表于 2017-2-21 22:41
看了下,貌似就是一般的智能主防吧
也没用提到idp的回滚

刚才看了下,没发现什么有用的描述,后来提到点Behavior Shield误报高,基于云去辅助判断。
驭龙
发表于 2017-2-24 15:23:48 | 显示全部楼层
好像没有提到关键性的内容,只是介绍一下功能,这也已经不错了
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-26 11:11 , Processed in 0.116311 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表