查看: 30562|回复: 6
收起左侧

[交流探讨] 关于“卡巴斯基网络威胁实时地图”这个网站,卡巴官方是怎么收集数据的?

[复制链接]
十送鸿钧
发表于 2016-3-18 22:29:33 | 显示全部楼层 |阅读模式
本帖最后由 十送鸿钧 于 2016-3-18 22:30 编辑

https://cybermap.kaspersky.com/

链接在此,可能这里不少人也知道
我对专有名词也不太清楚,有人介绍一下那几类缩写单词代表的含义吗?
顺道想问一下,卡巴主要是怎么收集这些数据的?
ccboxes
发表于 2016-3-18 22:48:58 | 显示全部楼层
本帖最后由 ccboxes 于 2016-3-18 23:01 编辑

很简单,你安装的卡巴斯基在不断检测并上传你电脑上的文件和使用情况到KSN(均为匿名发送),这是云的强大之处。

PS:那个地图下面一排是卡巴斯基的组件检测到的威胁,从左到右分别是
实时监控,右键扫描,网页反病毒,邮件反病毒,入侵检测,漏洞扫描,反垃圾邮件和僵尸网络检测。

PPS:谢pal家族更正。

评分

参与人数 1人气 +1 收起 理由
pal家族 + 1 版区有你更精彩: )

查看全部评分

pal家族
发表于 2016-3-18 22:53:18 | 显示全部楼层
擦!刚回复一大堆,结果手抖关掉了。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。MD!

oas 实时扫描
ods 按需扫描
wav 网页反病毒
mav 邮件反病毒
ids 入侵防护,反网络攻击
vul 漏洞检测
kas 卡巴反垃圾邮件
bad 僵尸网络检测

卡巴斯基所以组件,功能模块如下:

版本
Usually the following naming schema is used: [product][version][language].exe. Example: KIS17.0.0.225en-US.exe
Explanation:
Product:
    KFA = Kaspersky Free (free version of Kaspersky Anti-Virus, currently only available in Chinese and Russian)
    KAV = Kaspersky Anti-Virus
    KIS = Kaspersky Internet Security (like KAV but with additional protection components)
    KTS = Kaspersky Total Security (formerly known as PURE, like KIS but with additional features)
    KSOS = Kaspersky Small Office Security (for small business)
Version:
    [major].[minor].[minor].[build]
    major = usually corresponds to product version (2017 -> 17)
    minor = can be used to designate bug fix or maintenance releases
    build = number is increased for bug fixes and other small changes, will change often during beta-testing
Language:
    Most commonly: de = German, en = English, fr = French, ru = Russian, zh-Hans = Chinese (Simplified)

软件测试时的几大问题:

Installation, removal, updates [KFA\KAV\KIS\KTS\KSOS]
- standard installer tasks (install/delete, Force Update)
- migration: KFA <-> KAV <-> KIS <-> KTS
- bases update

File Scan (ODS/OAS/Vulnerability Scan/Quarantine…) [KFA\KAV\KIS\KTS\KSOS]
- On Demand Scaner (ODS)
- On Access Scaner (OAS)
- Quick Scan (QScan)
- Vulnerability Scan
- CleanUp
- Quarantine and Storage

Traffic checking (Web/Mail/IM/PC) [KFA\KAV\KIS\KTS\KSOS]
- Web Anti-Virus (WebAV)
- Mail Anti-Virus (MailAV)
- Antispam (AS)
- Instant messagers Anti-Virus (IMAV)
- AntiBanner (AB)
- Parental Control (PC)
- general settings of ports control

Application Control (HIPS, SW, Firewall, IDS, TAM) [KFA\KAV\KIS\KTS\KSOS]
- Application control (HIPS)
- Firewall (FW)
- System Watcher (SW)
- Intrusion detection system (IDS)
- Trusted applications manager (TAM), except KSOS

Safe Money (SM/VK/SK) [KFA\KAV\KIS\KTS\KSOS]
- Safe Money (SM)
- Virtual keyboard (VK)
- Secure keyboard (SK)

Crashes, Dumps, BSOD [KFA\KAV\KIS\KTS\KSOS]
- OS (operation system) crashes
- crashes of KFA\KAV\KIS\KTS
- OS freezes cause of KFA\KAV\KIS\KTS(no such problem without product)
- KFA\KAV\KIS\KTS hangings

GUI and Help [KFA\KAV\KIS\KTS\KSOS]
- Graphic User Interface (GUI)
- Help file of product

Performance/Compatibility [KFA\KAV\KIS\KTS\KSOS]
- performance
- Compatibility with 3rd party software

Other (AVZ/RD/MasterCD) [KFA\KAV\KIS\KTS\KSOS]
- AVZ scripts processing;
- devices management and KPC (Kaspersky Protection Center) Management Console;
- problems that are not connected to other topics

Encryption/Backup/PM/Shredder/UDC [KTS\KSOS]
- "Data Encryption" component
- "Backup" component
- "Password Manager" component (PM)
- "File Shredder" tool
- "Unused Data Center" (UDC)

所有组件

Components of the product
Anti-Banner = component that blocks advertising information located on banners built into interfaces of various programs installed on your computer or displayed online.
Anti-Phishing = component that tracks attempts to open phishing websites and blocks them
Anti-Spam = component that allows detection of unwanted messages (spam)
AVZ = scripts to solve problems in the system
Exclusions & Trusted Zone = Exclusion is an object excluded from scanning by the product. Trusted zone is the user-created list of objects which should not be controlled by the product.
GUI = Graphical user interface
HIPS, Application Control = component that logs the actions performed by applications in the system, and manages the applications' activities, based on which group they belong to. A set of rules is defined for each group of applications.
IDS = Network Attack Blocker
IM AV = component that scans traffic of instant messengers (such as ICQ, AIM etc.)
Installer = the program installing the product or an application
Mail AV = Mail Anti-Virus scans incoming and outgoing messages for the presence of malicious objects
OAS = File Anti-Virus (On Access Scan)
ODS = On Demand Scan
PC, Parental Control = component that monitors the users' access to the Internet, in order to restrict access to some kind of resources or certain URLs.
PDM = Proactive defense
Qscan, Rootkit scan = technology of scanning hard-to-detect threats which hide the traces of their activity
Quarantine = folder where objects are saved in encrypted form, which rules out the threat of infection. It also stores backup copies of objects created before disinfection or deletion.
RD, Rescue Disk = component that creates a bootable disk to be able to boot a computer that is extremely infected and cannot be disinfected by anti-virus program.
Self-Defense = module that blocks closing the product or changing its settings independently from user's wish
SK, Safe Keyboard = technology allowing you to type personal data (such as passwords or credit card numbers) using your hardware keyboard while avoiding its interception by keyloggers, which are programs that register keystrokes.
SM, Safe Money = starts the browser in an isolated environment for safe online banking.
SW, System Watcher = system events monitor. It collects and saves different events logs and provides it to the product's components in order to detect events sequences that are characteristic to malware.
Updater = module for updating databases or the product's modules
VK, Virtual Keyboard = special tool for typing personal data (such as passwords or credit card numbers) to avoid its interception by keyloggers, which are programs that register keystrokes.
Vulnerability scan = scanning of vulnerabilities in the installed programs
Web AV, Web Anti-Virus = component that scans internet traffic.
WMUF = database of dangerous URLs

Version designations
Build = assembly, also last number of the product's version
Alpha-version = the beginning state of product's development, a version that may miss most of new functionality
Beta-version = a version that has the complete functionality and is ready to be tested by components
RC, Release Candidate = a build that can become the release
TR, Technical Release = a build technically ready to go in production (pending printing boxes, writing knowledge base or help content etc.)
CR, Commercial Release = the product on sale, the moment Technical support is responsible for the product
CF, Critical Fix = build fixing critical bugs in the product and possibly some new functionality
MP, Maintenance Pack / MR, Maintenance Release = package of updates. Found bugs are fixed as well as new functionality can be added there. This is analogous to Service Packs of Microsoft products.
Hotfix, Patch = urgent update fixing critical bugs

Other common terms
Alert = informational pop-up of the product that allows to choose an action
Balloon = informational window of the product
BSOD, Blue Screen of Death = window of blue colour that is shown on crash of the operating system
Bug = error in function of program or its interface
Case = scenario of testing or steps to reproduce a bug
Change log = list of changes of a certain build
Crash = abnormal closing of an application or operating system
GBT, Gold Beta Tester = the title the most active beta-testers are awarded with in the end of the product's development cycle
KL = Kaspersky Lab
Memory dump = file containing the complete data about system memory state at the moment of crash
Screenshot = image file taken by the computer to record the visible items displayed on the monitor
Traces = log files with all the actions performed by the product which help developers to localize and solve an issue
Tray = the area of taskbar (next to the system time) with icons of running applications
VirLab = Virus laboratory of KL

评分

参与人数 1人气 +1 收起 理由
dongwenqi + 1 版区有你更精彩: )

查看全部评分

pal家族
发表于 2016-3-18 22:54:49 | 显示全部楼层
ccboxes 发表于 2016-3-18 22:48
很简单,你安装的卡巴斯基在不断检测并上传你电脑上的文件和使用情况到KSN(均为匿名发送),这是云的强大 ...

BAD:
botnet activity detection
僵尸网络检测
pal家族
发表于 2016-3-18 22:55:39 | 显示全部楼层
本帖最后由 pal家族 于 2016-3-18 22:57 编辑

可以参阅这里的3和7L
https://forum.kaspersky.com/index.php?showtopic=161942

另外这里8L:
http://bbs.kaspersky.com.cn/foru ... &extra=page%3D8

揭秘卡巴数据库:感谢蚊子!

klava- 卡巴斯基反病毒产品威胁数据库动态加载数据清单,含黑名单加载数据清单等验证数据,KL anti-virus activity。
wmuf- 恶意网址过滤数据动态加载数据清单,web malicious url filter。
Parctl- 家长控制模块数据动态加载数据清单。
Apd- 卡巴斯基内容过滤数据库动态加载数据清单,反钓鱼启发式分析 Anti-phishing DATA。
Apu- 卡巴斯基内容过滤数据库动态加载数据清单,反钓鱼地址分析 Anti-phishing URL 。
Adbu- 卡巴斯基反广告数据库动态加载模块组件清单,Anti-banner url。
vkc- 卡巴斯基漏洞防护组件动态加载数据组件清单,vulnerability kit control。

KLAVA 组件关注于所有引擎文件、威胁特征数据库更新、黑名单更新等更新加载到缓存时清单,更新一旦有问题出现,KLAVA 组件必然报错。

评分

参与人数 1人气 +1 收起 理由
dongwenqi + 1 感谢解答: )

查看全部评分

pal家族
发表于 2016-3-18 23:02:31 | 显示全部楼层
一个小问题被我写了这么多,,,,,,实际上是“摘抄了”那么多。。。。
慢慢看吧。。。。。。。。。。。。。。。。。。。。。。。
看完你就成了半个卡巴小专家了
qq1249412680
发表于 2016-3-18 23:30:58 | 显示全部楼层
我只觉得好漂亮
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-6 22:15 , Processed in 0.120333 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表