Endpoint Protection

 View Only
  • 1.  Engine and Signature

    Posted Jul 13, 2011 06:12 AM

    Can some please tell me diffrence between Signature and Enginee



  • 2.  RE: Engine and Signature

    Posted Jul 13, 2011 06:38 AM

    One who does the task of scanning using different techniques is called Engine

    https://www-secure.symantec.com/connect/articles/building-anti-virus-engine

    it relies on definitions to perform the above task; that is called signatures; :



  • 3.  RE: Engine and Signature
    Best Answer

    Trusted Advisor
    Posted Jul 13, 2011 10:01 AM

    Hello,

     

    In the antivirus world, a signature is an algorithm or hash (a number derived from a string of text) that uniquely identifies a specific virus. Depending on the type of scanner being used, it may be a static hash which, in its simplest form, is a calculated numerical value of a snippet of code unique to the virus. Or, less commonly, the algorithm may be behavior-based, i.e. if this file tries to do X,Y,Z, flag it as suspicious and prompt the user for a decision. Depending on the antivirus vendor, a signature may be referred to as a signature, a definition file, or a DAT file.
     
    A single signature may be consistent among a large number of viruses. This allows the scanner to detect a brand new virus it has never even seen before. This ability is commonly referred to as either heuristics or generic detection. 
     
    For Symantec AV Engine, read this Symantec Blog;
     


  • 4.  RE: Engine and Signature

    Posted Jul 13, 2011 11:07 AM

    On a lighter note, Engine is the engine for the AV for scanning and signature is the petrol with which it runs and do the job.