Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Virus
[Top] [All Lists]

RE: generic detection

Subject: RE: generic detection
Date: Thu, 7 Jul 2005 16:44:28 +0530
Hi Salim,

I'll try to explain one of the many reasons which are behind this:

xyz1_Worm       pattern 111111a:
xyz2_Worm       pattern 111111b:
xyz3_Worm       pattern 111111c:
xyz4_Worm       pattern 111111d:
xyz5_Worm       pattern 111111e:

Given the above scenario, I can choose to write 5 different (specific) 
signatures to detect these worms or can write one generic signature which can 
detect all of them (this can be done by just looking for the pattern 111111, 
which is common for all).

Now, this approach may not fit all possible scenarios (false positive issues) 
and moreover it has its own pros and cons.

to give you an example:

advantage:
It will stop any new xyz variant which has a similar pattern (so I  get 
zero-day attack protection without doing anything extra) 

disadvantage
less info: the concern that you are facing.


Vipul Kumra


-----Original Message-----
From: Hussain Salim [mailto:bo_ali90@hotmail.com]
Sent: Thursday, July 07, 2005 10:38 AM
To: focus-virus@securityfocus.com
Subject: generic detection


hi,
i want to know somenthing about generic detecion for example symantec detect 
some viruses and trojans as trojan.horse or backdoor.trojan why? why don't 
they detect them as a special name to know more information about them to 
fix what they do and thx.

im asking this question because i got many trojan.horse and backdoor.trojan 
and there is no technical details for them to know more information to fix 
what they do in my computer :( .

_________________________________________________________________
Want to block unwanted pop-ups? Download the free MSN Toolbar now!  
http://toolbar.msn.co.uk/


<Prev in Thread] Current Thread [Next in Thread>