CISA Made Easy

                                           - easy CISA preparation

Tuesday, August 12, 2008

10 things you must remember about Antivirus

The application software/hardware which works against viruses is called Anti-virus. A lot of questions can be framed on this topic. Here are some important points all CISA aspirants and Information Security Professionals are required to know about anti-viruses.

1. Virus signature / database/data mask/ is an algorithm or a set of algorithms which calculate a hash to distinctively identify the strains of a virus.

2. A generic anti-virus checks the database or virus signature and a heuristic anti-virus uses heuristic algorithm and checks malicious character in virus behaviour by different statistical and other advanced means.

3. Common place where a virus may reside are

RAM
Boot Records
Master Boot records
Different type of files

4. A good anti-virus should have the following capabilities:

Script checking
Compressed Files/folder checking
Quarantine capability
Email and web mail checking
P2P/File Sharing Protection
Registry checking
Macro protection


5. Inoculators calculate snapshot of a fresh program and checks any change thereafter. This is one of the best ways to counter virus but think what will happen if snapshot is calculated on infected file/program. ?



6. Integrity checker anti-virus calculates Calculates Cyclic Redundancy Checks (CRC).

7. Immunizer inserts a small piece of malicious code to provide protection against that malicious agent.

8. How Behaviour blocker anti-viruses work?. I leave this point for my readers to answer.

9. False positive condition means anti-virus reports a virus when actually no virus is there.


10. False negative is actually reverse of the false positive. In false negative is a situation where anti-virus fails to find a virus when virus actually exists in the system.

Readers who visited this post also read :

2 comments:

Sorry, I can't find a proper subject appropriate for my question, so I post it here.
The question:
Which of the following is the best description of nonvolatile data?
A. Contents of random access memory
B. Data on the hard disk
C. Data acquired by forensic recovery
D. Data from logical disk backups
The book answer is B, but I thought the answer c, data acquired by forensic recovery is the most nonvolatile data.
Can PassCISA please correct my thoughts, thanks a lot.

The answer/explanation is being published as the next post.

Thanks.

 

Home | | | | |

CISA made Easy - Easy CISA Preparation