Long time no post, all.
Anyways, I just wanted to start a general discussion on IPS, and your guy's thoughts and views on it.
Since I recently started working for a antivirus company, this roughly new technology has fallen into my lap. For those who dont know what IPS is, Basically Intrusion Prevention Systems do pattern matching, looks for "suspicious" strings, and kills the processes they believe could potenitally be viruses, trojans, etc. IPS can be fully customizable, and with Panda Software, they even boast killing processes of programs that show signs of buffer overflows, with thier TruPrevent Technologies.
http://www.pandasoftware.com/products/truprevent_tec/
McAfee has a similar technology called Entercept, however like always with McAfee, they are way more picky about what they add to thier signature file, based on cost, effectiveness of the virus, etc.
http://www.networkassociates.com/us/...rd_edition.htm
[EDIT]These things can also act as a mid wife before a suitable definition for a virus fix can be written to the signature file, which also helps with viruses that have not yet been known to the AV companies.[/EDIT]
Anyways, I just wanted to get this out there and let me know what you guys think about these programs, if you can see any possible exploits, etc.
Anyways, I just wanted to start a general discussion on IPS, and your guy's thoughts and views on it.
Since I recently started working for a antivirus company, this roughly new technology has fallen into my lap. For those who dont know what IPS is, Basically Intrusion Prevention Systems do pattern matching, looks for "suspicious" strings, and kills the processes they believe could potenitally be viruses, trojans, etc. IPS can be fully customizable, and with Panda Software, they even boast killing processes of programs that show signs of buffer overflows, with thier TruPrevent Technologies.
http://www.pandasoftware.com/products/truprevent_tec/
McAfee has a similar technology called Entercept, however like always with McAfee, they are way more picky about what they add to thier signature file, based on cost, effectiveness of the virus, etc.
http://www.networkassociates.com/us/...rd_edition.htm
[EDIT]These things can also act as a mid wife before a suitable definition for a virus fix can be written to the signature file, which also helps with viruses that have not yet been known to the AV companies.[/EDIT]
Anyways, I just wanted to get this out there and let me know what you guys think about these programs, if you can see any possible exploits, etc.
Comment