All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
About Hackers
Analysis
News
Glossary
Weblog

 
Latest Glossary Additions

12 06
    Keylogger

06 20
    World Wide Web

06 20
    WildList

06 20
    WiFi

06 20
    Whitelist
 
Most Popular Glossary Items



Backdoor Trojans



False positive



Riskware



Keylogger



Trojan
 
About Hackers
About Hackers

Find out more about hackers and vulnerabilities in our About Hackers and Vulnerabilities section.

 

  Home / Hackers / Glossary

Behavioral analysis

This refers to the technique of deciding whether an application is malicious or not, according to what it does. If an application does something that falls outside the range of ‘acceptable’ actions, its operation is restricted. For example, trying to write to certain parts of the system registry, or writing to pre-defined folders, may be defined as a threat. The action can be blocked, or the user notified about the attempted action. This fairly simple approach can be further refined. It's possible, for example, to restrict the access of one application (let's say allowing a web browser read-only access to limited portions of the system registry) while giving unrestricted access to other programs that do not use the Internet.

An alternative behavioral method is to 'wrap' a downloaded application and restrict its action on the local system. Here the application is run in a protective 'sandbox' [sometimes called a ‘playground’, or ‘secure cache’] to limit its actions according to a pre-defined policy. The activity performed by the program is checked against a set of rules. Depending on the policy, the program’s actions may be considered a violation of the policy, in which case the rogue action is blocked.

 

Copyright © 1996 - 2009
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com