|
Re: zero-hour protection: msg#00016security.virus.clamav.devel
Lars Roland wrote: On 11/22/05, sj@xxxxxxxxxx <sj@xxxxxxxxxx> wrote: There are other vectors to cover instead of taking the heuristics route. One thing we know, when outbreaks happen, they `normally` are in tidal waves. ClamAV already unpacks all attachments for scanning, if we were to keep a hash for each attachment in a database and monitor the rate of incoming MD5 hashes, we could detect when an outbreak has happened. Ie, if we have an incoming executable/pif/<whatever criteria> is seen more than 1000 times in the period of 5 minutes, a quarantine of the mail can take place, or it can be submitted automatically (provided its under N size, Y file type, etc..) ClamAV can use the same method DCC uses, and talk to a network of ClamAV servers (distributed) who's sole responsibility is to keep track of these MD5 hashes. Hashes expire after 15 minutes for example. This would allow you to keep millions and millions of file hashes without having any slowdown in hash lookups. Cami _______________________________________________ http://lurker.clamav.net/list/clamav-devel.html |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: zero-hour protection: 00016, Lars Roland |
|---|---|
| Next by Date: | Re: zero-hour protection: 00016, sj |
| Previous by Thread: | Re: zero-hour protectioni: 00016, Lars Roland |
| Next by Thread: | Re: zero-hour protection: 00016, Damian Menscher |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |