12
返回列表 发新帖
楼主: 皮可西
收起左侧

[新手上路] MSE对Rootkit的防御怎么样

[复制链接]
尘梦幽然
发表于 2014-5-10 19:10:23 | 显示全部楼层
驭龙 发表于 2014-5-10 19:03
不是吧,那不就是高级威胁保护吗,这东西是Norton 2014的最重要变化呀

恕我无知,你有帖子介绍这个吗?
驭龙
发表于 2014-5-10 19:12:13 | 显示全部楼层
尘梦幽然 发表于 2014-5-10 19:10
恕我无知,你有帖子介绍这个吗?

我忘记是2013还是2014的版本改进的这个功能了,不过,我不怎么关注,实际上还是SONAR的一部分吧
尘梦幽然
发表于 2014-5-10 19:17:18 | 显示全部楼层
驭龙 发表于 2014-5-10 19:12
我忘记是2013还是2014的版本改进的这个功能了,不过,我不怎么关注,实际上还是SONAR的一部分吧


我在STAR介绍里面找到的关于rookits的内容,前两个是基于文件,最后一个基于行为:
ERASER Engine
Symantec’s ERASER engine provides repair and removal capability for threats found on a customer’s system by our various detection technologies. ERASER is also responsible for checking that drivers and applications that run at startup are not malicious. To ensure that our product is not being tricked by rootkits or other malware, ERASER uses a number of techniques that bypass regular system registry and disk lookups. These technologies allow ERASER to perform direct registry and direct disk access.

Anti-Rootkit Technology
Symantec has 3 different anti-rootkit technologies designed to find and remove even the most stubborn rootkits like Tidserv and ZeroAccess, working around stealthing techniques commonly used by rootkits. The techniques include:
Directly access the hard drive volumes Direct Registry Hive scanning.
Kernel memory scanning.

Top Threat Vectors Symantec’s Behavior-Based technology protects against:
Targeted Attacks including Advanced Persistent Threats (APTs), Trojans, Spyware, Keyloggers and general Malware
Social Engineering Attacks – FakeAV, Rogue Key Generators and Fake Codecs
Bots and Botnets
Non-Process and Injected Threats (NPTs)
Zero-day threats
Malware as the result of drive-by downloads that bypassed other layers of protection
Malware using rootkit techniques to hide
驭龙
发表于 2014-5-10 19:20:44 | 显示全部楼层
尘梦幽然 发表于 2014-5-10 19:17
我在STAR介绍里面找到的关于rookits的内容,前两个是基于文件,最后一个基于行为:

第二个不就已经说是直接扫描内存和硬盘吗,那应该是监控的了。我们下次在Symantec区聊吧
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-28 02:17 , Processed in 0.113708 second(s), 13 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表