05.08.2013 Views

OfficeScan 10 Administrator's Guide - Online Help Home - Trend Micro

OfficeScan 10 Administrator's Guide - Online Help Home - Trend Micro

OfficeScan 10 Administrator's Guide - Online Help Home - Trend Micro

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Behavior Monitoring Components<br />

Behavior Monitoring Detection Pattern<br />

This pattern contains the rules for detecting suspicious threat behavior.<br />

Keeping Protection Up-to-Date<br />

Behavior Monitoring Driver<br />

This kernel mode driver monitors system events and passes them to Behavior<br />

Monitoring Core Service for policy enforcement.<br />

Behavior Monitoring Core Service<br />

This user mode service has the following functions:<br />

• Provides rootkit detection<br />

• Regulates access to external devices<br />

• Protects files, registry keys, and services<br />

Behavior Monitoring Configuration Pattern<br />

The Behavior Monitoring Driver uses this pattern to identify normal system events and<br />

exclude them from policy enforcement.<br />

Digital Signature Pattern<br />

This pattern contains a list of valid digital signatures that are used by the Behavior<br />

Monitoring Core Service to determine whether a program responsible for a system<br />

event is safe.<br />

Policy Enforcement Pattern<br />

The Behavior Monitoring Core Service checks system events against the policies in this<br />

pattern.<br />

4-7

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!