首先感谢yu88480朋友的分享:
http://bbs.kafan.cn/viewthread.php?tid=138876&highlight=%D7%AA%D4%D8%D2%BB%C6%AA
关于“主动防御”,“HIPS”,“启发式查杀”和“沙盒”的概念,在卡饭中已经讨论很久了,不过好像没有最终定论。
今天读完了yu88480朋友分享的那篇关于自我保护技术在恶意软件中的进展的文章,里面有这么一段:
“
However, behavior analysis can get confusing when it comes to terminology, and it's not always easy to get things straightened out. For example, a behavioral analyzer may go by different names: HIPS, proactive protection, heuristic, or sandbox… However, regardless of the term, one thing remains clear: malicious programs are ultimately powerless in the face of behavioral analysis. This vulnerability will probably have an influence on the future evolution of malicious programs. 很显然,在卡巴分析师眼里,这几个概念纯粹是“terminology”(术语学)上的区别,还有后面一句“However, regardless of the term,。。。”(然而,不管术语上怎么说。。。)。可见,在他眼里,这几个概念意思是一致的。 |