Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This article is for students, faculty, and staff . It provides a background on who would like to learn about various antivirus software types, their importance, and their benefits.

Note
iconfalse

This article will focus mainly on antivirus programs as they apply to desktop devices. For more information specifically about threat prevention on mobile devices, review the article, see Security and Threat Prevention.

Overview

Antivirus software is a type of program that is meant to prevent malware infections, detect existing threats or attacks, and eradicate them from singular computing devices, networks, and entire IT systems. Antivirus programs work by analyzing websites, files, installed software or applications, and other user data to parse for known threats. They automatically monitor day-to-day program behavior, which enables the software to flag anything that is out of the ordinary and alert the user; they confirm the status of the device in question, and users can typically use the program to scan a single file or their entire device on demand.

...

Standalone antivirus programs, like malware signature programs, are used to target and eliminate specific, known threats. However, standalone software is designed to be installed on a portable device, like a USB drive, and is commonly used by administrators to scan a compromised system in an emergency. Standalone antivirus software is similar to malware signature antivirus programs , in that it is not meant to provide roundaround-the-clock, real time protection or download new viral signatures every day.

...

  • Attempts to connect to an unfamiliar or suspicious website.
  • Attempts to gain access to a large number of files.
  • An unusually large increase in data usage.

When these or other similar behaviors arise, the program will generate an alert. System monitoring , since it operates continuously, can provide real-time protection to users.

...

A security software suite is a set of software tools , managed by a central control panel that is designed to prevent devices, networks,and systems from malware infection. From this control panel, the user can access not only the antivirus software, but also other additional features in the suite. Suites often offer extra functionalities , like anti-spam software, password storage, identity theft protection, and VPNs, among multiple others. 

...

Machine learning antivirus software uses, as the name would suggest, machine learning techniques to determine what constitutes normal behavior for a given device, network or system. The software monitors user activity, and using the data it gathers, limits or even disables tasks if they are deemed to be suspicious.

...

A cloud is a collection of servers that are operated and accessed remotely over the Internet instead of locally , via computer , and includes any of the software and databases that are run on those servers. Cloud-based antivirus software works in much the same way: a similar manner; instead of operating locally on a device (which takes up a great deal of often limited storage space and slows down tasks), this form of antivirus protection analyzes files remotely in the cloud.

These programs usually have two components , a desktop client that operates locally on your computer , and a web service. The desktop client acts as a light version of a system monitoring program, : periodically gathering data, and scanning the device for viruses and other malware without excessively taking up memory. The web service then processes this information in the cloud, comparing it to its virus and malware database to identify matches.

Info
For more information about the types of malware and other threats that antivirus software is designed to protect against, review the article, see /wiki/spaces/IKB/pages/10809901143

...