ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Cheap Heuristics
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Does a portion of code inspected by ClamWin have to contain the exact signature of a known virus before it is flagged as a virus? If it does require the exact signature, then would it be possible to determine if a piece of code contains a certain percentage of the code found in a known virus signature? If this could be done, you could set a "tolerance" of 95 % or so to minimize false positives and then make an intelligent guess as to whether or not there is a virus.

This might not apply to all situations, so you might only want to use it in special situations.

Regards,
View user's profileSend private message
Re: Cheap Heuristics
Anandir


Joined: 03 Dec 2005
Posts: 0
Location: Italy
Reply with quote
GuitarBob wrote:
Does a portion of code inspected by ClamWin have to contain the exact signature of a known virus before it is flagged as a virus? If it does require the exact signature, then would it be possible to determine if a piece of code contains a certain percentage of the code found in a known virus signature? If this could be done, you could set a "tolerance" of 95 % or so to minimize false positives and then make an intelligent guess as to whether or not there is a virus.

This might not apply to all situations, so you might only want to use it in special situations.

Regards,


I think that feature must be implemented in ClamAV, as a extra feature.
Maybe looking in ClamAV site/forum/wiki/mailinglist Smile.
View user's profileSend private message
Cheap Heuristics
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic