20.08.2013 Views

User Guide - Kaspersky Lab

User Guide - Kaspersky Lab

User Guide - Kaspersky Lab

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

90 <strong>Kaspersky</strong> Internet Security 7.0<br />

Figure 22. Creating an application list<br />

7.2.4. Using Heuristic Analysis<br />

Heuristic methods are utilized by several real-time protection components, such<br />

as File, Mail, Web Anti-Virus, as well as virus scan tasks.<br />

Of course, scanning using the signature method with a database created<br />

previously containing a description of known threats and methods for treating<br />

them will give you a definite answer regarding whether a scanned object is<br />

malicious and what dangerous program class it is classified as. The heuristic<br />

method, unlike the signature method, is aimed at detecting typical behavior of<br />

operations rather than malicious code signatures that allow the program to make<br />

a conclusion on a file with a certain likelihood. The advantage of the heuristic<br />

method is that it does not require prepopulated databases to function. Because<br />

of this, new threats are detected before virus analysts have encountered them.<br />

• In the event of a potential threat, the heuristic analyzer emulates object<br />

execution in the <strong>Kaspersky</strong> Internet Security secure virtual environment. If<br />

suspicious activity is discovered as the object executes, the object will be<br />

deemed malicious and will not be allowed to run on the host or a<br />

message will be displayed requesting further instructions from the user:<br />

• Quarantine the new threat to be scanned and processed later using<br />

updated databases<br />

• Delete the object<br />

• Skip (if you are positive that the object cannot be malicious).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!