20. BAD GOOD
Reputation
LOW HI
Prevalence
OR
NEW OLD
Age
OR
為什麼 Insight 可以增加安全性?
傳統的防毒採用的是無罪推定論方式直到證明有罪
假使檔案並沒有符合『指紋特徵』 . . . 准許該檔案使用
? 但是如果您能夠知道…
? 相信能夠更能保護您在各種情境之下
端點安全教戰守則 - SEP 與 SCSP 如何協助 20
28. 支援 Mac OS X 10.8 作業系統
? 支援 Mac OS X v10.8
? 支援對大小寫格式敏感的 HSFX 磁碟
? 支援全新的 “Gatekeeper” 功能
? 針對 Mac 用戶端安裝程式有相關異動
? 針對 Mac 的 SEP 安裝程式會透過全新的 Apple Developer
ID 憑證進行簽署
? 安裝程式本身也會被全新的 Apple Developer ID 簽署
端點安全教戰守則 - SEP 與 SCSP 如何協助 28
29. 自動化的第三方產品移轉功能
* 不同平台或語系會有相關限制 (詳情請參考 KB)
AhnLab V3 Internet Security 8.0 AntiSpyware 8.x* Rising Internet Security 21.x
AhnLab V3 Internet Security 8.0 8.x* Rising AntiVirus 23.x
AhnLab V3 Internet Security 7.0 Platinum Enterprise AntiSpyware 7.x Rising Personal Firewall 20.x
AhnLab V3 Internet Security 7.0 Platinum Enterprise 7.x Rising Internet Security 23.x
avast! Antivirus 4.x BitDefender Business Client 3.x*
avast! Free Antivirus 5.x CA eTrust Antivirus 7.x
avast! Antivirus Professional 4.8.x CA eTrustITM Agent 8.x
avast! Pro Antivirus 5.x CA eTrustITM Agent (AntiSpyware) 8.x
AVG 10 [AntiVirus] 10.x CA Total Defense 12.x
Avira AntiVir Premium 10.x CA Anti-Virus 9.x
Avira Premium Security Suite 10.x ESET NOD32 Antivirus 3.x
Avira Antivirus Premium 12.x ESET NOD32 Antivirus 4.x
ESET Smart Security 3.x*
端點安全教戰守則 - SEP 與 SCSP 如何協助 29
32. vSIC 溝通流程: 未知檔案
端點安全教戰守則 - SEP 與 SCSP 如何協助 32
vShield
Manager
SVA
vShield drivers (part of VMTOOLS)
SEP 12.1.2
VM (client)
Scan
Request
Get
EFA
EFA:
Extended File
attribute.
Check for
reputation
and whitelist
flag
Submit
Sending some
EFA attribute
via the vShield
“plumbing”
Check if in
chache:
The file is
unknown
Scan the file:
The file is
Clean
Update the
chache
Adding the
hash, clean
statut, AV defs
sequence
number
掃瞄檔案:
進一步執行
病毒掃瞄動
作
33. vSIC 溝通流程: 已知檔案
端點安全教戰守則 - SEP 與 SCSP 如何協助 33
vShield
Manager
SVA
vShield drivers (part of VMTOOLS)
SEP 12.1.2
VM (client)
Scan
Request
Get
EFA
EFA:
Extended File
attribute.
Check for
reputation
and whitelist
flag
Submit
Sending some
EFA attribute
via the vShield
“plumbing”
Check if in
chache:
The file is
known
跳過此檔案:
掃毒引擎將
掃瞄要求停
止 並處理下
一個檔案.
49. Thank you!
Copyright ? 2010 Symantec Corporation. All rights reserved. Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in
the U.S. and other countries. Other names may be trademarks of their respective owners.
This document is provided for informational purposes only and is not intended as advertising. All warranties relating to the information in this document, either express or implied,
are disclaimed to the maximum extent allowed by law. The information in this document is subject to change without notice.
Thank you!
端點安全教戰守則 - SEP 與 SCSP 如何協助 49
Wales Chen (陳瑞文)