本帖最后由 c291354239 于 2011-11-12 21:15 编辑
3楼
Avira Firewall is not a standalone application, it's a built-in in Avira Premium Security Suite. It’s a robust firewall that lets the user allow or deny Internet access to your applications, allow or deny data traffic, allow or deny incoming and/or outgoing IP, TCP or UDP packets, allow or deny passive listening to the application of ports, allow or deny code injection*, allows creation of rules for your network, prevent modification of the HOSTS file, among other possibilities. Summarizing: It's a complete firewall.
AviraFirewall不是一个独立的应用程序,它是内置在Avira安全套装内的一个有机组件。这是一个强大的防火墙,它可以让用户允许或拒绝应用程序接入互联网,允许或拒绝应用程序的数据,允许或拒绝本机出入的IP,TCP或UDP数据包,允许或拒绝应用程序的端口监听,允许或拒绝代码注入*,它允许用户创建属于自己的网络的规则,防止修改主机文件,和其他可能的威胁。总结:它是一个功能完整的防火墙。
Avira Firewall doesn’t have a built-in HIPS, but since Avira 10 has introduced a new behavior-based detection technology called Avira AntiVir ProActiv in the Avira's Guard (now Realtime Protection). AntiVir ProActiv constantly monitors the behavior of the system in real-time and looks for unusual events. An integrated rule-system is able to decide proactively if a certain event (or a combination of events) indicates that the system is currently under attack from a new or unknown malware. If a rule matches the user is then able to decide what to do with this suspicious file, i.e. to trust it, to block it once, to block it always or to ignore it. More information here. (http://www.avira.com/en/proactiv)
Avira防火墙没有内置主动防御系统,但自从Avira 10版本开始,一种新型的行为检测技术“Avira 反病毒主动防御技术”已在Avira Guard中集成(现在实时保护)。AntiVir ProActiv采用实时监控监视着系统内不正常的软件行为。AntiVir ProActiv能够通过一个完整的系统行为分析判定一个特殊的事件(或一些列事件),来表明该系统目前正在被一个新的或者未知的恶意程序威胁。如果规则匹配,用户可以自行决定采取的行动,是相信该可疑文件还是阻止他这一个,或者总是阻止/忽视它。更多的信息可以查看这里(http://www.avira.com/en/proactiv)
* Code injection is a technique for introducing code into the address space of another process to execute actions, forcing this process to load a dynamic link library (DLL). Code injection is used by malware, amongst other things, to execute code under cover of another program. In this way, access to the Internet in front of the Firewall can be hidden. In default mode, code injection is enabled for all signed applications. - from Avira Help Guide.
*代码注入技术是把特定的代码加载到另一个进程的地址执行,迫使动态链接库加载代码指定的dll。代码注入通常被恶意软件使用,除了其他的行为外,通过别的程序来掩护恶意软件。通过这种方式,在访问互联网时可以在防火墙前“隐身”。默认情况下,所有应用程序均可以使用代码注入技术。--来自于Avira 帮助向导
Avira Personal 10 / Avira Free Antivirus包括的组件表: alg.exe, apnstub.exe*, avcenter.exe, avconfig.exe, avgnt.exe, avguard.exe, avnotify.exe, avscan.exe, avshadow.exe, avupgsvc.exe, avwebgrd.exe*, ipmgui.exe**, sched.exe, update.exe and updrgui.exe**
Avira Premium / Antivirus Premium & Security Suite / Internet Security包括的组件表: alg.exe, avcenter.exe, avconfig.exe, avgnt.exe, avguard.exe, avmailc.exe, avnotify.exe, avscan.exe, avshadow.exe, avupgsvc.exe, avwebgrd.exe, ipmgui.exe**, sched.exe, update.exe and updrgui.exe**
* 当安装了Avira toolbar+webguard后才有的
**当安装了Avira 2012软件才有的
*Avira Premium Security Suite / Avira Internet Security should not have the Firewall module installed, since you should not use two firewalls on the same machine. It's important to highlight that, so also read: Do I have to deactivate all installed Firewalls, in order to use Avira FireWall? (same applies to the Avira 10 versions).
*If you’re installing Avira 10 / 2012 products, the process called fact.exe should be allowed in your firewall.
Avira Premium Security Suite / Avira Internet Security 在您的计算机上同时存在两款防火墙软件时不应安装防火墙模块。这是很重要的一方面,所以建议阅读Do I have to deactivate all installed Firewalls, in order to use Avira FireWall? (同样适用于v10版本).
如果您在安装Avira v10/2012产品时,fact.exe进程应该在您的防火墙规则中被允许。
附上用户手册对于antivir proactive的说明:
Avira ProActiv
可抵御新的未知威胁,对于这些威胁,还没有任何病毒定义或启发式信息可用。ProActiv
技术集成在 Realtime Protection
组件中,可观察并分析所执行的程序操作。此技术会针对典型的恶意软件操作模式来检查程
序的行为:操作和操作序列的类型。如果程序表现出了恶意软件的典型行为,则视为检测到
病毒:您可以选择阻止此程序,或者忽略通知并继续使用此程序。您可以将此程序分类为可
靠,并将其添加到允许程序的应用程序过滤器中。可以使用始终阻止命令,将此程序添加到
阻止程序的应用程序过滤器中。
ProActiv 组件使用 Avira 恶意软件研究中心开发的规则集来识别可疑行为。此规则集由
Avira 数据库提供。Avira ProActiv 会将检测到的任何可疑程序的相关信息发送到 Avira
数据库中以作记录。您可以选择禁止将数据传输到 Avira 数据库中
(本人非专业,技术名词翻译不准请赐教) |