Jump to content

toxinon12345

ESET Insiders
  • Posts

    165
  • Joined

  • Last visited

  • Days Won

    5

Posts posted by toxinon12345

  1. Well, I guess Similarity digests are what extend a cloud for effective classification; in addition to reputation metadata (age/users). Of course, you should not expect blocking every executable out there with the premise of "Low reputation" only: that would create tons on FPs e.g. for developers; but an hybrid approach combining core routines with cloud classifier should readjust threshold levels for threat determination.

    The problem with a dynamic whitelisting is the performance overhead, e.g. querying the cloud for every new installed PE program [ *.exe | *.dll ], if we add script execution: PowerShell, Batch, VBscript it would mean another filegroup to look at. Some other products claimed to have resolved, at least partially, that problem with what they call "prefetch scan", "solid asynchronous packet", and other sort of weird terms. Maybe it makes sense for interactive windows : PUA's for example.

  2. Well, not only internet connectivity could be the problem; sometimes the updater got stuck at big files e.g. em002_*_*.nup and the update process restart. Sometimes is interrupted After the mentioned filename, but then resuming comes into play for subsequent connections.

    For the above mentioned issue, I increased the update sync to 24 hours because the unneeded interference in my limited bandwidth causes excessive lag at my browsing exp.

×
×
  • Create New...