<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-6932487252591907254.post3183081616907187467..comments</id><updated>2008-10-15T04:10:23.753-07:00</updated><title type='text'>Comments on 有時候‧那時候: 安全廠商所該思考的問題</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://kresirys.blogspot.com/feeds/3183081616907187467/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default'/><link rel='alternate' type='text/html' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html'/><author><name>Kresirys</name><uri>http://www.blogger.com/profile/06452859784453829820</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>9</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6932487252591907254.post-3687560337762837187</id><published>2008-10-15T04:10:00.000-07:00</published><updated>2008-10-15T04:10:00.000-07:00</updated><title type='text'>好文章ㄚ我喜歡受教了</title><content type='html'>好文章ㄚ我喜歡&lt;BR/&gt;&lt;BR/&gt;受教了</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/3687560337762837187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/3687560337762837187'/><link rel='alternate' type='text/html' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html?showComment=1224069000000#c3687560337762837187' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html' ref='tag:blogger.com,1999:blog-6932487252591907254.post-3183081616907187467' source='http://www.blogger.com/feeds/6932487252591907254/posts/default/3183081616907187467' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6932487252591907254.post-3338582134165138398</id><published>2008-09-25T05:19:00.000-07:00</published><updated>2008-09-25T05:19:00.000-07:00</updated><title type='text'>To 匿名雲端技術跟引擎是沒啥大關係的。幾百萬個(一百萬還好,兩三百萬的就有點誇張)威脅特徵碼，是因...</title><content type='html'>To 匿名&lt;BR/&gt;雲端技術跟引擎是沒啥大關係的。&lt;BR/&gt;&lt;BR/&gt;幾百萬個(一百萬還好,兩三百萬的就有點誇張)威脅特徵碼，是因為威脅特徵碼取得不好。&lt;BR/&gt;&lt;BR/&gt;Kaspersky也提倡只要威脅特徵碼就能偵測，不用更新引擎，可它威脅特徵碼取得不好，跟引擎並無關係。</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/3338582134165138398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/3338582134165138398'/><link rel='alternate' type='text/html' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html?showComment=1222345140000#c3338582134165138398' title=''/><author><name>Kresirys</name><uri>http://www.blogger.com/profile/06452859784453829820</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13716396324841412427'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html' ref='tag:blogger.com,1999:blog-6932487252591907254.post-3183081616907187467' source='http://www.blogger.com/feeds/6932487252591907254/posts/default/3183081616907187467' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6932487252591907254.post-51476455492166435</id><published>2008-09-25T04:58:00.000-07:00</published><updated>2008-09-25T04:58:00.000-07:00</updated><title type='text'>雲端技術可以是個解決方案，但如果安全廠商不懂得節制自己所製造出原本幾十萬變成幾百萬的威脅特徵碼。那也...</title><content type='html'>雲端技術可以是個解決方案，但如果安全廠商不懂得節制自己所製造出原本幾十萬變成幾百萬的威脅特徵碼。那也只是安全廠商偷懶的一招而已。&lt;BR/&gt;&lt;BR/&gt;-----------------------------&lt;BR/&gt;&lt;BR/&gt;這要取決於引擎的好壞才對吧!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/51476455492166435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/51476455492166435'/><link rel='alternate' type='text/html' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html?showComment=1222343880000#c51476455492166435' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html' ref='tag:blogger.com,1999:blog-6932487252591907254.post-3183081616907187467' source='http://www.blogger.com/feeds/6932487252591907254/posts/default/3183081616907187467' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6932487252591907254.post-543992858527652977</id><published>2008-09-24T02:50:00.000-07:00</published><updated>2008-09-24T02:50:00.000-07:00</updated><title type='text'>To 茂伯人工更會出錯，在人數不夠跟品質不一的時候，自動分析相對是一個有力的助手，當然面對誤報一樣需...</title><content type='html'>To 茂伯&lt;BR/&gt;&lt;BR/&gt;人工更會出錯，在人數不夠跟品質不一的時候，自動分析相對是一個有力的助手，當然面對誤報一樣需要人工解決。&lt;BR/&gt;&lt;BR/&gt;在卡飯論壇(夠大了吧？)那些樣本除非HIPS來偵測，否則第一時間Kaspersky很少偵測到，這是目前主流現象，我想我沒說錯。</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/543992858527652977'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/543992858527652977'/><link rel='alternate' type='text/html' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html?showComment=1222249800000#c543992858527652977' title=''/><author><name>Kresirys</name><uri>http://www.blogger.com/profile/06452859784453829820</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13716396324841412427'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html' ref='tag:blogger.com,1999:blog-6932487252591907254.post-3183081616907187467' source='http://www.blogger.com/feeds/6932487252591907254/posts/default/3183081616907187467' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6932487252591907254.post-7242018740148532866</id><published>2008-09-24T02:49:00.000-07:00</published><updated>2008-09-24T02:49:00.000-07:00</updated><title type='text'>To Lawliet哈哈，感謝ㄚ一捧場，文章沒被修正真好0.0。</title><content type='html'>To Lawliet&lt;BR/&gt;&lt;BR/&gt;哈哈，感謝ㄚ一捧場，文章沒被修正真好0.0。</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/7242018740148532866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/7242018740148532866'/><link rel='alternate' type='text/html' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html?showComment=1222249740000#c7242018740148532866' title=''/><author><name>Kresirys</name><uri>http://www.blogger.com/profile/06452859784453829820</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13716396324841412427'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html' ref='tag:blogger.com,1999:blog-6932487252591907254.post-3183081616907187467' source='http://www.blogger.com/feeds/6932487252591907254/posts/default/3183081616907187467' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6932487252591907254.post-6135101450010807801</id><published>2008-09-22T03:29:00.000-07:00</published><updated>2008-09-22T03:29:00.000-07:00</updated><title type='text'>我來給你澎場了！我是誰你應該知道吧？</title><content type='html'>我來給你澎場了！&lt;BR/&gt;我是誰你應該知道吧？</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/6135101450010807801'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/6135101450010807801'/><link rel='alternate' type='text/html' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html?showComment=1222079340000#c6135101450010807801' title=''/><author><name>Lawliet</name><uri>http://www.blogger.com/profile/10973650840951262053</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html' ref='tag:blogger.com,1999:blog-6932487252591907254.post-3183081616907187467' source='http://www.blogger.com/feeds/6932487252591907254/posts/default/3183081616907187467' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6932487252591907254.post-2625134321841485762</id><published>2008-09-20T06:14:00.000-07:00</published><updated>2008-09-20T06:14:00.000-07:00</updated><title type='text'>上面的人兄，你有看清楚嗎？他只說：造就 Kaspersky 在 AVPClub 的偵測率超過 90%...</title><content type='html'>上面的人兄，你有看清楚嗎？&lt;BR/&gt;他只說：造就 &lt;A HREF="http://www.kaspersky.com/" REL="nofollow"&gt;Kaspersky&lt;/A&gt; 在 &lt;A HREF="http://www.avpclub.ddns.info/discuz/index.php" REL="nofollow"&gt;AVPClub&lt;/A&gt; 的偵測率超過 90% 而不是整體偵測率。&lt;BR/&gt;&lt;BR/&gt;另外「安全廠商所該思考的問題」應該是如何應付惡意程式爆發的未來，其中雲端技術只不過是其中一項應對的方案&lt;BR/&gt;&lt;BR/&gt;然而，雲端技術需要各方的配合：使用者本身的意願、安全廠商的使用者量、技術支援人員等都是值得考量。&lt;BR/&gt;但要成功，前兩項是重要的，使用者的多少將會左右雲端技術所取得的資源的類別、多少（儘管雲端技術是用作白名單還是輔助補足特徵庫），但這不是最重要，使用者本身的意願更重要，使用者不參與雲端技術也是徙然。</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/2625134321841485762'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/2625134321841485762'/><link rel='alternate' type='text/html' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html?showComment=1221916440000#c2625134321841485762' title=''/><author><name>User</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html' ref='tag:blogger.com,1999:blog-6932487252591907254.post-3183081616907187467' source='http://www.blogger.com/feeds/6932487252591907254/posts/default/3183081616907187467' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6932487252591907254.post-7870328900675064016</id><published>2008-09-19T22:51:00.000-07:00</published><updated>2008-09-19T22:51:00.000-07:00</updated><title type='text'>未免太誇張了...一個小論壇就可以決定了Kaspersky偵測率是否超過90?那對岸一堆超大型論壇，...</title><content type='html'>未免太誇張了...&lt;BR/&gt;&lt;BR/&gt;一個小論壇就可以決定了Kaspersky偵測率是否超過90?&lt;BR/&gt;&lt;BR/&gt;那對岸一堆超大型論壇，成千上萬的樣本該怎麼辦?&lt;BR/&gt;&lt;BR/&gt;要品質就需要較多人工分析，要人工就不能同時兼顧迅速，在病毒爆炸時代，迅速還是比較重要，所以先加進特徵庫中，能先偵測再說，之後再慢慢整理，就像各大防毒軟體一段時間後會整理、縮小特徵庫...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/7870328900675064016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/7870328900675064016'/><link rel='alternate' type='text/html' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html?showComment=1221889860000#c7870328900675064016' title=''/><author><name>茂伯</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html' ref='tag:blogger.com,1999:blog-6932487252591907254.post-3183081616907187467' source='http://www.blogger.com/feeds/6932487252591907254/posts/default/3183081616907187467' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6932487252591907254.post-3629335245145036225</id><published>2008-09-19T22:25:00.000-07:00</published><updated>2008-09-19T22:25:00.000-07:00</updated><title type='text'>防毒軟體絕對脫離不了特徵碼的如果有加殼，報成基因庫就能以一擋百雖然誤報率可能會增加，不過我相信這是可...</title><content type='html'>防毒軟體絕對脫離不了特徵碼的&lt;BR/&gt;如果有加殼，報成基因庫就能以一擋百&lt;BR/&gt;雖然誤報率可能會增加，不過我相信這是可以降低的，只是看你要不要做而已&lt;BR/&gt;&lt;BR/&gt;而「全自動分析」，會有誤報的風險，基本上還是要配合人工分析才對&lt;BR/&gt;&lt;BR/&gt;那個雲端技術，說實話，趨勢主打了那麼久，偵測率一樣低，但是對於網頁防護倒是比較行&lt;BR/&gt;&lt;BR/&gt;所以，也要看防毒廠商如何運用這個技術</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/3629335245145036225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6932487252591907254/3183081616907187467/comments/default/3629335245145036225'/><link rel='alternate' type='text/html' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html?showComment=1221888300000#c3629335245145036225' title=''/><author><name>阿宅</name><uri>http://www.blogger.com/profile/11739843386978960870</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kresirys.blogspot.com/2008/09/blog-post_18.html' ref='tag:blogger.com,1999:blog-6932487252591907254.post-3183081616907187467' source='http://www.blogger.com/feeds/6932487252591907254/posts/default/3183081616907187467' type='text/html'/></entry></feed>