The Plug‐ins System
Joxean Koret, Elias Bachaalany · 2015
This chapter covers some loading implementations of typical antivirus plug-ins and analyzes the loading process. Heuristic-based detection algorithms, emulators, and script-based plug-ins are also covered. The chapter explains the working of plug-in loaders, and analyzes a plug-in's code. The heuristic engine uses all of the information to determine that the buffer or file under analysis is "suspicious" enough to raise an alert, according to the heuristic level specified. Later in the chapter, the dynamic heuristic engines category is discussed. The chapter explains some of the simpler heuristic engines an antivirus can offer. There are two types of memory scanners: userland and kernel-land memory-based scanners. Antivirus kernels are almost always written in C or C++ languages for performance reasons. Bayesian networks are the heuristic engines that classify potentially malicious files as candidates to be sent to antivirus companies for analysis.