On Thu, 22 Apr 2010 17:56:48 +0700 sonjaya <sonjaya@gmail.com> wrote:
Signature based detection has always been flawed, and worse, as the
volume of malware increases, so does the number of "illegal" byte
sequences. The result is obvious; more and more stuff will be blocked
due to false positives.
Using encryption (ssh, scp, ssl) is a way around this problem, and if
it does happen when using encryption, then just change to using a
different cypher (resulting in a different byte sequence).
jcr
--
The OpenBSD Journal - http://www.undeadly.org