Re: [malware-list] scanner interface proposal was: [TALPA] Intro to a linux interface for on access scanning

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

On Mon, 18 Aug 2008, douglas.leeder@sophos.com wrote:


it gets even worse if you have more scanners.

you may have a OS package manager scanner that knows the checksums of the 
files that were installed via packages,plus you may have multiple 
anti-virus scanners (people want to try and run more then one so that what 
one misses another may catch), plus a HIDS scanner to check that config 
files haven't changed (seperate from the package manager scanner)

then you can add on top of this one or more indexers.

you don't want to run all of these just becouse you updated one of them.

and if you subscribe to multiple anti-virus scanner updates, they are not 
going to be in sync with each other, so one may update at noon (triggering 
a full rescan), and another at 12:30 (triggering another)

David Lang
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [malware-list] scanner interface proposal was: [TALPA] ..., david, (Mon Aug 18, 5:13 am)