How do Heuritic Scanners Work?
Results 1 to 6 of 6

Thread: How do Heuritic Scanners Work?

  1. #1
    Banned
    Join Date
    Aug 2002
    Posts
    5

    How do Heuritic Scanners Work?

    Any idea how heuristic scanners work? I read a lot about how how the infected file is put in a "sandbox" and is checked for any activity...Wat exactly takes place??And secondly...is this really effective in detecting viruses?
    Share on Google+

  2. #2
    Senior Member
    Join Date
    Dec 2003
    Location
    Pacific Northwest
    Posts
    1,675
    Neorage,

    A heuristic scanner searches elementary assembly language, in the hopes of detecting little known infections. They’re many false positives with this type of scanner because it tries to learn and make assumptions based on the behavior of the virus.

    cheerios

    edit: here's some links of interest for you:

    http://www.itsecurity.com/asktecs/oct2802.htm

    http://vx.netlux.org/lib/static/vdat/epheurs2.htm

    http://www.choice.com.au/goArticle.aspx?id=103097&p=1
    Share on Google+

  3. #3
    Senior Member nihil's Avatar
    Join Date
    Jul 2003
    Location
    United Kingdom: Bridlington
    Posts
    17,190
    Well Neorage,

    Your heuristic scanner works on "algorithms" or rules............like if something tries to amend the registry, prepend or append to an executable, and so on............it will give you a warning.

    Now, your "sandbox" is a different concept.............here, an incoming executable is put in an area where it's activity is monitored...........if it tries to access areas outside the sandbox.............it is a cheater.

    A bit like home and away games...........heuristics are at home...........the sandbox is away?

    I hope that explains
    Share on Google+

  4. #4
    Senior Member
    Join Date
    Dec 2003
    Location
    Pacific Northwest
    Posts
    1,675
    Nihil,

    Thanks for cleaning it up and finishing his questions.
    Share on Google+

  5. #5
    Senior Member therenegade's Avatar
    Join Date
    Apr 2003
    Posts
    400
    good post nihil
    Share on Google+

  6. #6
    Banned
    Join Date
    Apr 2004
    Posts
    94
    think i got a solution for that! and not only that if u want to know about working of anything you can just visit the website:


    www.howstuffworks.com

    happy surfing
    Share on Google+

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •