First layer includes ever-expanding white list and black list approach to determine in early phase if a launching program is suspicious or safe. If this program is not found in either list DriveSentry switches to second layer of defense which is HIPS similar to ThreatFire. This means it constantly watches running processes of all active programs as a whole entity in contrast to Defense+ to find out if host is using tactics and approach similar to malware.Third layer involves real-time virus scanning.
Besides DS even refuses to be terminated via task manager and some more advanced termination techniques which means it has a decent self-termination shield.
Seeing DriveSentry in action convinced me this fellow is worth receiving a chance to stay on one's computer for further revision. Unfortunately like many other similar programs it seems to be vulnerable to certain buffer overflow techniques.
DriveSentry uses around 75 MB of memory and utilizes around 1-3% CPU in average.
Download DriveSentry next generation antivirus





0 Comments:
Post a Comment