1988, quack, there is a procedure known Inflatable Folder as the Morris Worm, a time to stir up trouble and cause panic of the network sector. After the survey showed that the virus is not malicious attacks. This process of copying speeds so fast in so short a time of the destruction is still in the initial stage of the Internet. Its inventor Robert Morris Jr. At that time, do not want to deliberate attacks on the Internet, just want to know the number of networked computers only.
However, 20 years later, the situation Inflatable Folder has undergone great changes. More malicious hackers to use procedures for ulterior motives. These people not only to the world the ability to show off their computer is more important to take profits. We call it Baijin hackers.
The world seems to be always relative, came into being the anti-malicious software programs. From then on a network seems to be a world of endless disputes, the fight Bukekaijiao, quack no longer peace. To the current situation, it seems that force Mogaoyizhang Road. Malicious software is beyond our imagination to the speed of development.
The corner of the Internet, provocateurs are……:
Perhaps the word malicious software simply not enough to express the content of the current network threats. Previously, viruses, worms are good at fighting guerrilla warfare. Their access to computers, infected files, and then was cleared. Now, the virus is often when you do not pay attention to quietly hide in your system, is not to destroy your computer or paper. Also unlike the infamous "I Love You" (ILOVEYOU) virus, like the great harm this virus in 2000 destroyed the countless Windows operating system.
They are really so good? «No, you were wrong. They are just waiting for opportunities and dynamic, access to important password Inflatable Folder or credit card account, or your computer into a spam generator, and the destruction of your user data, rather than the computer itself. You can not even be the main target. Xiao political arena even dust on the rumors that the malicious software is not cyber-crime groups, but terrorist acts or government organizations. However, no conclusive evidence.
Melissa, ILOVEYOU Sasser and malicious programs have caused great loss. However, users can take simple measures to prevent infection of malicious software. For example, do not open e-mail sent by the use of an executable file annex; Do not use porous outlook. Also, the use of real-time updates of the testing procedure can also reduce the risk of infection.
However, as these threats linger around us. For example, in the form of postcards to spread the Trojan horses, hot news for the community that message. Some users ignored warnings, like click on the site unidentified floating window.
But the real problem is that existing methods of detection of the 21st century is not enough to deal with malicious software. In the past they use e-mail attachments, mobile media as a mode of transmission. Now more malicious software is in your visit to the site under threat, the general contains cross-site scripting attacks or not least on social networks being used hidden cross-site request disguised attack. You think that he is Inflatable Folder a visit to the target site, in fact you have an attack, the latest attack code has been injected into your computer.
There is another problem, people generally believe the security of the Macintosh computer operating system was also found that hackers have a lot of loopholes, at the same time, windows of Vista is porous. The next step is «Most of the researchers predicted that the next target is the mobile phone users. The forthcoming large-scale outbreak.
Defense team is action
According to Symantec's report, 2007, about 70 percent of the attacks were detected. It can be expected in 2008 we will do better. Some experts have estimated that in 2009 the number of viruses and Trojans will reach 1 million orders of magnitude. These new virus will be harder to detect, antivirus experts will set higher requirements, not only have to face the emerging viruses, and also will have to fight against the virus.
The past, the antivirus software detected the virus only need a simple sample, and then set off, to be a paradise on ok. The only previous case, the times have changed. The malicious software are changing. This moment of change in their antivirus software can not be identified by their samples. There is also a noteworthy trend is that these malicious use of server-side of the variance, that is infected your machine before they have achieved variation, so your antivirus software and even harder to find these procedures carry a mutation tool.
Another common deception techniques malicious software is hidden in the packing process. You extract the document, in due course, these loopholes in the document will come out to harm your computer. Is also available in the use of encryption technology, script-based attack or confusing tactics.
Antivirus software expert analysis of the old
Inflatable Folder and new viruses a wide range of features. You may think it is very difficult. Indeed is the case. Some antivirus software companies around-the-clock surveillance of the virus characteristics of the new upgrade your antivirus library.
A more modern and effective methods of dealing with malicious software is malicious Bu Quguan what kind of long, but attention to what they can do, this technology is called heuristic antivirus technology. The Greek word itself means "the way alone experience." This approach, as the awareness of the human brain, is the combination of creativity and knowledge of. Antivirus software in the brain, it stressed that more is not a simple code of conduct in the form of matching.
For example, your antivirus software scanner may be found a suspicious to be made without the permission of the user open outlook and Gmail-mail recipients. Scanner may be self-analysis, although this appears not too good, but it is normal.
Another way is to be suspicious of the procedures put in this virtual space to protect the rest of the system. This is called Sandbox - to work, what happened to be observed. If these programs try in your financial information in a folder Daogui the case, we know what they are not a good thing. There are some procedural default this feature, and some need to set up their own management staff.
0day & Heroes
You may have noticed that these anti-virus technology in common, they are reactive (Houfazhiren). This is not so good. But on the current situation, engineers noted that the only issue before we can solve the problem. 0-day attacks targeting the patch is not the loopholes in procedures. Learn 0 - day of the attack contributed to a better guard against the virus.
Malicious software to prepare the general staff in the preparation of the software threatened the officers found a few days or one week before the discovery of software vulnerabilities. In some cases, some independent researchers found that the software problem but did not draw attention to relevant, and it did not add patches.
If not 0 - day attacks, the game continues. Vista repair in a 0 - day of the attacks on the same day, hackers have started to look for beaver-like speed patch loopholes.
What if you have a good say «Why add patches, they have to do» The reason is very simple, use the windows system users too much, as long as they restored a little of malicious software can be revitalized so that you will find There are many loopholes in the existing computer.
The reason is that, because of the existing operating systems and procedures sometimes on the security issue is not too clear. Logically, if no one knows the loopholes, there will be no people will find loopholes. As long as there are loopholes in it, some people will find loopholes. However, if some people do know that there are many loopholes in circumstances, the loopholes will appear immediately after the patch, since the malicious software writers before the communication of information is so smooth, so there is no security to speak of. Logically, if the researchers pointed out that a week or a month of a loophole in the system, then business will be tight security at the string.
The first reaction is to block as much as possible the escalation of the latest virus software and keep pace. If you are a network or system administrators, always concerned about 0 - day of the attack site news. If you find the above have the relevant information on software vulnerabilities, hackers may find problems before, manufacturers will release a patch to fix the underlying problem. These sites will remind you of the software concern abnormal behavior. This does not mean that manufacturers will be immediately issued a patch, but found that the issue of third-party organizations or researchers will be restored as soon as possible loopholes.