January 09, 2012

HOW WORKS ANTI VIRUS

Most antivirus works with some methods like below:
1.Detection using virus signature database (virus signature database): How the virus is an approach that is widely used by old version antivirus  , looking for signs of the presence of the virus with small use a half of the virus code that has been analyzed by antivirus vendors, and appropriate have been catalogue the type, size, power and some category destruction. This method is fairly quick and reliable way to detect viruses wherewith analyzed by antivirus vendors, but can not detect new viruses until the virus signature database into the newly installed system. Virus signature The database can be obtained from the antivirus vendor and can generally be obtained by free via download or through a subscription (subscription).

2.Detection by looking at how the virus works: How the antivirus like this a new approach borrowed from the technology applied in Intrusion Detection System (IDS). This method is often referred to as a Behavior-blocking detection. How to use the policy (policies) that must be applied to detect the presence of a virus. If there is a software behavior that is "unnatural" according to the policy being applied, as well as software that try to access the address book to send out a mass e-mail to the e-mail list that is in the address book (the method is often used by virus to transmit the virus via e-mail), then the antivirus will stop yang doing by software.

3.Antivirus also can isolate codes of suspected viral until administrator decide what to do next. The advantage of the way. This is antivirus can detect new viruses that have not been recognized by the virus signature database. The downside, obviously because antivirus software to monitor how the overall (not monitor file), then the frequency of false alarms antivirus make or "False Alarm" (if the antivirus configuration is too "hard"), or even allow the virus to multiply in the system (if configures antivirus too "soft"), false positive occurs. Some manufacturers call this for heuristic scanning techniques