Newsletters Welcome, Guest Log In | Register


Join the Community

Exchange

Get full access to our community's expertise and resources.

Register Now >

Currently Being Moderated

Definitions: Antivirus

0

Created on: Jan 25, 2009 6:44 PM by CrystalBedell - Last Modified:  Jan 30, 2009 12:08 PM by CrystalBedell

Definition

Antivirus is software that scans a personal computer for  evidence of malicious software. When it finds a file infected by a virus or  other type of malware, antivirus software either neutralizes or eliminates the  file to prevent the infection from spreading and damaging systems. Antivirus  programs can protect systems against a variety of malicious code, including  worms, Trojans, spyware, rootkits and more.

 

Business applications

Businesses should deploy antivirus on all personal computers  as one of many layers in a defense-in-depth security strategy. Many security vendors offer antivirus products, and while  there are small variations in the way they respond to viruses, antivirus  products ultimately perform the same function. Some of the more popular vendors  include McAfee, Symantec, CA and Sophos. When choosing an antivirus  vendor, businesses may consider price, recommendations, features or  availability.

 

Deployment Concerns

Stand-alone antivirus software is no longer enough to  protect systems against the barrage of malware that constantly attempts to  undermine systems. Experts recommend deploying a suite of applications, including  antivirus, for more complete protection against malware.

 

Antivirus software also has been found to have its own  vulnerabilities that could pose a danger to the very systems it’s meant to  protect. A consulting firm found that many antivirus programs can be exploited through vulnerabilities within the malware-scanning process  known as parsing. That’s yet another good reason to deploy  defense-in-depth.

 

Technical details

Antivirus software can perform manual and automatic scans.  Best practices dictate running a complete scan immediately after installing the  software, configuring full automatic scans to run periodically and running  manual scans on incoming files (for example, e-mail attachments or Web  downloads).

 

Antivirus programs can also use two methods for detecting  malware: matching signature files and heuristic analysis. When matching  signature files, antivirus software compares the code in a file to a dictionary  of known virus signatures. When it finds a match, the antivirus software either  repairs, deletes or quarantines the file. This type of antivirus software must  be regularly updated to include the latest virus signatures. New viruses are  constantly being created so antivirus vendors are challenged to keep up by  creating signatures for each new virus.

 

Heuristic analysis is the examination of suspicious behavior  to determine whether it’s being caused by a virus. For example, if one program  attempts to write data to an executable program, the antivirus software may  raise a warning to the user. Because this method does not rely on current  signatures, it is used to detect new viruses for which signatures are not yet  available, and variants of old viruses. However, heuristic analysis requires  user action when suspicious behavior is flagged. That can be a problem if the antivirus  software has a high false-positive rate and users begin to ignore the warnings.

Average User Rating
(0 ratings)




Add a comment Leave some feedback about this document.

There are no comments on this document

ITIL V3 Foundation - Complete Certification Kit

Enhance your IT career by getting your ITIL Foundation Certificate. It's fast and easy with this complete resource. The 186-page eBook and companion online training course is guaranteed to help you pass the ITIL exam.

Learn more >

Social Media Policies Toolkit

Define the rules at your company for the proper use of social media platforms such as Blogs, Twitter, Facebook and Youtube. Ensure your users are spending their time productively and company resources are being used for the business.

Learn more >

Data Loss Protection

Data-loss prevention tactics, technologies and best practices to protect your sensitive and valuable company data.

Tape Storage

Disaster recovery and business continuation that includes encryption, all at a manageable TCO.

Security Information and Event Management

Best practices, strategies and technologies to help you use security information and event log management efficiently and effectively in order to get business value in terms of increased security, reduced risk, regulatory compliance and increased business agility.

Optimized Infrastructure

Hardware and software tools to create an enterprise infrastructure for data and business optimization.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Lowering Your IT Costs with Oracle Database 11g Release 2

This white paper identifies the key capabilities a database management solution needs to successfully deliver more information with higher quality of service, make more efficient use of IT budgets, and reduce the risk of change in data centers.