![]() |
![]() | I'm so curious about virus signatures | ![]() |
Traversal
![]() |
![]() |
Anybody can tell me the details?
How to select a correct signature form a virus sample? |
|||||||||||
|
![]() |
![]() | Re: I'm so curious about virus signatures | ![]() |
![]() |
![]() | Virus Signatures | ![]() |
GuitarBob
![]() |
![]() |
Below is a link to a search I did on the ClamAV Web site for "sasser" virus signatures:
https://clamav-du.securesites.net/cgi-bin/clamgrok?virus=sasser&search-type=contains&case-sensitivity=No&database=daily&database=main&display=database&display=virus&display=signature&.submit=Submit+Query&.cgifields=database&.cgifields=case-sensitivity&.cgifields=search-type&.cgifields=display At one time ClamAV was using an algorithm in virus scans that was originally developed in medical research to identify patterns of protein families. I don't know if they are still using it. Theoretically, I guess it should be very helpful, but it appears that they still need to identify most viruses separately--even slightly changed versions. They are really developing a good database--they've up to about 85,000 signatures now, which is more than some commercial antivirus firms. If you are able to identify virus families, however, the sheer number of signatures isn't that important. Regards, |
|||||||||||
|
![]() |
![]() | I'm so curious about virus signatures | ![]() |
|
||
![]() |
![]() |
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.