Who Am I

Hyderabad,Manipal,Bangalore, Andhra Pradesh,Karnataka, United States
Pursuing Masters from Manipal Institute of Technology,Intern at VMWare,A dangerous a Geek,a Freak,a Sneak and a Nerd.

Friday, February 18, 2005

L4Learn

Hi
A possibilty very common and interesting.... is that a even a computer catches virus ... actually this possibility is well know .... but what is not known is how we tackle them ... or how say an antivirus kicks the butt .....
what we often do is see the type of virus ....google it and search for the remedy ..... (some people dont even do tht .. if u r among those ... hit alt+ tab scan ur system .. get a virus .. get its type ... gooogle and then again clean ur system using help there...) But have u ever thought how is it possible for antivirus to detect what type of virus is it .. and how does it actually recognises a virus .....
Well i thought about it .. and found it possibel to share with u .....
Every file has its signatures .... Every file has its own signatures ... A signatures is the functioinality expected by the file .... If a file is .exe file ,,, then it must satisfy certain constraints ..... such as it must use protected memory given to it ... should keep in track of its child processes or tasks ... must chack that it shuts and surenders for deallocation all of its spawned processes .. etc ... if a file misbehaves ie does something apart from its signature signifies it is called a virus ...if it communicates(means listen to commands from user level) it is called a trojan .... if it gives birth to any trojans or viruses then it is called a worm(that is the parent whose child misbehaves is called a worm )... typically a parent which infects even its own children may be called a virus ...
Now sometimes even though the signatures matches it is is termed as a virus, as the action specified by the signature may not be secure ... Now whther the process trying to do an unacceptable job is a virus or a user mismatch can be decided based on the application and system software constructs....
An anti viruses always contains a data base ..with definitions for various possible file signatures ... which are not acceptable .... if there is any match they are computed thouroughly and handled ... it may be possible for a better explanatin of the antiviruses but bot here .. If u have any corrrections or better explanations .. please do post it on the comments ... for those who crave for more possibilities theres lot to come in lots of mroe posts ..
hold tite and keep waiting ...
Dhaval Bhanushali...

1 comment:

oremuna said...

Nice blog

make it a bit more readable by introducing paragraphs and dividing lines according to topic.

Don't just flood the bits, but make them bytes.

Blog Archive