查看: 2175|回复: 5
收起左侧

[技术探讨] 关于DSS(Dynamic Signature Service 动态签名)的部分技术原理

[复制链接]
Continue
发表于 2010-12-21 16:35:45 | 显示全部楼层 |阅读模式
Microsoft is far ahead of these archaic techniques of asking the user, which have been proven by their own telemetry not to work well for the typical consumer.
Instead, MSE monitors all files and behavior on the PC and if something new occurs that isn't included in its signatures it will upload this information using the Dynamic Signature Service (DSS) to SpyNet.  If the file and/or activity are known to be malware by SpyNet, MSE will download the 'new' definition provided by SpyNet and deal with it.  If it's unknown, the information will be sent by SpyNet to the Microsoft Anti-Malware Team analysts to determine whether the new item is malware or not and add it to the definitions if so or whitelist it if it's not.
You should also recognize from this that not all definitions need to be stored on each PC, only those for the most common threats currently 'in the wild'.  So the signature database on your local PC is simply treated as a cache of the most common items that you're likely to encounter at this point in time and the combination of SpyNet and DSS acts as a much larger and more complete database of all known threats or whitelisted items that your PC can access whenever it's required.
This is exactly what you're asking for, but it doesn't spend time asking the user something that in most cases they are technically incapable of answering or understanding.  It just does what it knows is best for the user and in general speeds the response time for the protection of all users while reducing the number of false positive responses by not 'guessing' based on its heuristics.  It simply uses these systems to help it determine more quickly if the potential threat is known and speeds the required information to the Anti-Malware team if it's not.



http://social.answers.microsoft.com/Forums/en-US/msestart/thread/af8e8e6c-6159-4d1a-a23b-d0caab5582a4
看来DSS和SpyNet是密不可分的
MSE的白皮书好像没有,不过很多技术都是从ForeFront EndPoint上面挖下来了,所以去找了下FE的相关资料
最后找到了个PPT,里面有FE的相关资料,DSS应该算是是基于行为检测&虚拟化技术的云引擎吧.


最后有个问题,不知道关闭行为监控后DSS是否继续生效.


评分

参与人数 1经验 +30 收起 理由
帅就是帅 + 30 感谢分享~

查看全部评分

帅就是帅
发表于 2010-12-21 17:06:19 | 显示全部楼层
关于dss的文献确实比较少
至于最后那个问题,依然生效,因为dss不仅是在实时监控中程序触发,即使在扫描过程中也会触发,一方面也和动态虚拟相印证
黯夜
发表于 2010-12-21 17:29:09 | 显示全部楼层
偶居然能看懂了!
Continue
 楼主| 发表于 2010-12-21 17:48:24 | 显示全部楼层
行为&虚拟化重定向(微软叫Dynamic Translation,区别于完全的虚拟化,速度更快,因为转换过的代码是在真实CPU上运行的)配合SpyNet云应该能达到响应速度,安全,正确率上的最佳平衡
个人和家庭使用MSE+Win7完全够了
PS.仔细看了下,DSS是Behavior+Properties两种,更加全面,估计更详细的资料是找不到了,暂时到此为止了.
飞机
发表于 2010-12-21 17:58:47 | 显示全部楼层
表示看不懂英文
klinxun
发表于 2010-12-22 12:09:25 | 显示全部楼层
求翻译……
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-28 12:30 , Processed in 0.130778 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表