Quote:
|
Originally Posted by ichito
PCA 1.5 protects me the same on-line and off-line?
|
Obviously not, detection is improved while online, which is the infection vector of 99,9% of malware today. For the remaining threats PCAV offers different layers of offline protection:
* Local synch'ed cache of Collective Intelligence signatures of prevalent threats.
* Generic signatures.
* Signatures for non-PE files.
* Static heuristic with emulation (codename Nereus)
* Static behavioural blocking engine.
* Dynamic behavioural analysis engine.
* Autorun & USB vaccination.
When connected it adds a few more layers:
* Cloud-based signatures (specific and generic)
* Cloud-based heuristics (codenamed Nereus.net)
* Age heuristics, aka prevalence
* Whitelisting