PDA

View Full Version : CH, Antivir/KIS behaviour blocking


Iangh
November 11th, 2006, 06:54 PM
As I understand it CH is a behaviour blocker but isn't Antivir/KIS suite the same when it is using heuristics?

What are the differences?

Ian

lucas1985
November 11th, 2006, 07:14 PM
Heuristics searchs code patterns
Behaviour searchs actions

Yes, there are overlaps. Norman Sandbox uses both. I believe NOD 32 uses both too

Iangh
November 11th, 2006, 07:16 PM
Function is the same: spot zero-day effects?

lucas1985
November 11th, 2006, 07:21 PM
-{ Quote: "Function is the same: spot zero-day effects?" }-
Yes, find unknown malware and prevent exploits