Eliminate hidden dangers from the root cause of server virus removal

  

There are many network users who are plagiarized by their computer being repeatedly infected by one or even several viruses. In fact, we can analyze through a very vivid example: If a family has been infected with a disease for a period of time, each time it is the right medicine, but it can't avoid repeated infections. What is the reason? No one has thought of eliminating it. The source of the disease - the tableware. In today's networked society, computer virus protection is not a simple matter for enterprises or individuals to install a set of anti-virus software on the machine. Many virus infections occur on network file sharing servers.

On the eve of Christmas last year, the highly contagious "Remote Explorer" virus was discovered, not only cast a shadow over the festive atmosphere, but also broke the long-standing virus that did not directly attack the server. This traditional point of view. The breaking of this point of view not only refers to the anti-virus of the server to a more important position, but also protects the network virus from deepening the point of view that the first step is to cure the problem, that is, the first step is to make the server a key point, and to solve the network anti-virus. The first step is to lay the foundation so that the spread of the virus throughout the network is effectively controlled.

Many users have encountered a lot of problems when doing network anti-virus work. There is bound to be data sharing in a network. If a machine is toxic, the virus will form a large area of ​​infection through the server. Network administrators can only shuttle between these machines to treat diseases and kill poisons. Recurrence is still unknown. The upgrade problem is even more of a headache. Hundreds of thousands of machines need to be upgraded one by one. The work is simple but extremely cumbersome. Therefore, users need network anti-virus products, especially on the server side to achieve a certain level of management, and the manual operation into the active operation of the machine will greatly reduce the burden on the system administrator.

Performance is a major issue for any server-based product, including anti-virus software. For server-based and user-based anti-virus protection, the meaning of performance is different. For user-based products, the primary performance criterion is the time it takes to scan the hard drive, but for server-based products, real-time scanning of all files on the network and its management control capabilities are even more important. This performance indicator fully reflects the strong management capabilities of anti-virus software, and can control the spread of the virus. Therefore, to measure the performance of anti-virus products, in addition to the anti-virus software's virus removal capabilities, but also focus on the server's management functions.

Since the enterprise network is a complex system, there may be hundreds or thousands of nodes (servers and workstations) in the network. Therefore, the system must centralize all nodes (servers and workstations) in the entire domain. Management and control, an anti-virus system control program installed on one or several computers that responds to and controls changes to the entire network or any of its nodes through real-time and timed scans, accessing virus information, setting up and operating. In other words, anti-virus software should be able to provide a central configuration of the server, enabling network users to determine the various tasks to be performed at different times, and to allow users to schedule and scan multiple servers and platforms. The interconnection of multiple server and platform events greatly simplifies many events in a large environment.

For the protection of network viruses, the goal of preventing viruses through the powerful management functions of the server is the key. Just like people get a cold and know how to take medicine and take medicine, but why not avoid viruses from attacking the human body? Therefore, starting from the server to improve their own resistance, preventing the emergence and spread of the virus is the root of corporate anti-virus.

Judging the "Yes and No" of Enterprise Network Anti-Virus

China's corporate network is developing rapidly. At present, there are more than 200,000 LANs built, and Internet users have exceeded 1.17 million. If such a large network user does not have a high-efficiency anti-virus product as a barrier, it is likely to become a hotbed of computer viruses, and the consequences will be unimaginable. Many companies have recognized the importance of network antivirus and have put network virus prevention work on the agenda. However, having some understanding does not mean having a professional understanding. When many users in China talk about anti-drug awareness, they still don't understand what is the basic concept of enterprise network anti-virus, and even in a state of ignorance. Many users' awareness of enterprise network anti-virus is only a simple concept: Is enterprise network anti-virus not the same as stand-alone anti-virus? Anti-virus software installed on the machine can be safe. Objectively speaking, the guidance of this misconception is not unrelated to China's anti-virus vendors. In China's anti-virus industry, many manufacturers have directly added single-unit anti-virus products to the network anti-virus battle, so in the publicity. Inevitably, the user will be mistakenly guided. Then, can the network environment install a single anti-virus software to truly achieve the purpose of virus protection? Users should pay attention to the function of anti-virus products when choosing network anti-virus products?

Preventing network viruses with stand-alone anti-virus software What are the consequences for this problem, in fact, as long as we carefully analyze, we will come to a very clear conclusion. The network environment is very complicated, and its multi-platform structure requires anti-virus software to have anti-virus capabilities for various platforms. That is to say, anti-virus software must be able to be embedded in the bottom layer of various operating system platforms in the network to enable the system to have anti-virus capabilities. This alone factor is something that stand-alone antivirus software can't do. In addition, even if the anti-virus software can protect the client from viruses, the important interface of the virus transmission on the server side and the mail group will still cause the entire network system to be attacked by viruses, because there will be data sharing in the network. If a machine in the network is toxic, the virus will form a large-scale infection through the server, but the stand-alone anti-virus software can only prevent the virus on its own machine, and does not have the defense function against viruses such as servers and mail groupware. Even if each client is equipped with anti-virus software, the server is poisoned, and when the user exchanges data, it will inevitably be repeatedly infected with the virus, and the virus will never be removed from the network. The important way for these viruses to spread, stand-alone anti-virus software is unable to defend, can not help. It is the presence of these viruses that spread the back door, causing the network virus to be inexhaustible. A virus repeatedly spreads infections in the network system. The danger of this unprotected system being destroyed by viruses can be enormous.

Therefore, in this case, the user has no way to talk about the security of the corporate network. We can analyze it through a very vivid example: If a family has infected a disease for a period of time, each The second time is the right medicine, but it still can't avoid repeated infections. What is the reason? No one has thought of eliminating the source of the disease--tableware. In today's networked society, network system virus protection is not a simple matter of installing a set of anti-virus software on the machine. Many virus infections occur on network file sharing servers. On the eve of Christmas last year, the highly contagious "remote explorer" virus was discovered, breaking the traditional view that the long-established virus did not directly attack the server. The breaking of this point of view not only proves that the use of stand-alone anti-virus is powerless to the network, but also deepens the view that network anti-virus must strictly control the various ways of transmission of the virus. Only by first achieving this goal can the virus be The spread in the network is effectively controlled. //This article transferred from www.45it.com computer software and hardware application network

Second, multi-platform architecture requires multi-platform network anti-virus software.

Anti-virus software belongs to the support layer software. Therefore, when installing, the anti-virus software must be able to analyze the underlying operating system platforms in the network system, and then find the required modules based on the analysis results. Inserted into the operating system, becomes a patch into the system, so that the operating system itself has a virus defense capability, thereby achieving comprehensive protection against the network system. If this is not possible, anti-virus software will not only affect the operating efficiency of the network system, but also cause unnecessary system burden and overhead for the entire network. Moreover, if it cannot be embedded in the bottom layer of the system, the anti-virus software will not be able to prevent the underlying system. The virus still cannot achieve the purpose of preventing the virus. Therefore, for heterogeneous operating platforms in the network, anti-virus software is required to have software for each platform.

Third, network anti-virus needs "active"

Looking at the development of anti-virus technology in China, from anti-virus card to its own upgraded software anti-virus products, to timed anti-virus technology The business is always a passive defense concept. The biggest shortcoming of this concept is that the foundation of the virus prevention system is established after the virus invades the operating system or the network system. The anti-virus product can only be used as the upper-layer application software, and passively control the virus by means of the functions provided by the operating system or the network system. This practice has caused a lot of loopholes in the security and reliability of computer systems. In the past, traditional anti-virus technologies, even "passive reactions" can not be called, because they actually only have anti-virus function, and do not have the ability to protect - they will not react when the virus invades the system, after the system is infected by the virus The user can only passively start the anti-virus program to perform anti-virus check and kill on the system. With real-time anti-virus technology, the virus can be actively processed without the user's clarity.

Fourth, complex network anti-virus management should be completed by network anti-virus software. Due to the complexity of network management itself, plus anti-virus problems that require a lot of manual time to solve, such as: virus scanning work, virus removal Work, network anti-virus software upgrades on all machines, anti-virus management of remote machines... make the management of network administrators more complicated and busy. It is also a single-machine anti-virus software that does not have management functions, and a network anti-virus software with insufficient management functions to create an anti-virus management obstacle for network administrators. Moreover, these tasks that need to be done manually are not only cumbersome, but if there is a slight negligence, which machine is not scanned or upgraded, it will leave an opportunity for virus invasion. This requires network anti-virus software to have powerful management functions to reduce the pressure on anti-virus work for network users.

We can see that the technical nature of anti-virus products directly affects the preventive effect of network viruses. Therefore, when users choose network anti-virus software, they should first make clear what anti-virus software is truly capable of implementing network virus protection. Mastering the "right and wrong" standard, not only will the user's anti-virus work become simple, but the virus prevention work will also achieve the desired results.

Copyright © Windows knowledge All Rights Reserved