Re: VirusHammer data structure
Nick FitzGerald <nick-jd3pj1bJWvoG2Il/[email protected]> Tue, 23 Mar 2004 21:21:06 +1200
| Newsgroups | gmane.comp.security.virus.openantivirus.devel |
|---|---|
| Organization | Personal account |
| Message-ID | <4060AA42.21167.21FAD902@localhost> |
Fridrik Skulason <[email protected]> wrote: > For some information read http://www.securityfocus.com/infocus/1650, which > is a pretty good article by Costin Raiu. Ah yes, forgot about that article. For those who don't know, Costin was probably the last person who (largely) wrote a full-blown detection engine from scratch. I've seen teams re-architect (and/or partially re-implement) existing engines into much more flexible, extensible systems (and also, usually, with the goal of making them much more portable as well) and based on that, I'd say that Costin's estimate of ten years work to do an entire engine from scratch seems about right (at least, assuming that one or two of the team doing it did not have extensive, closely relevant experience). Regards, Nick FitzGerald ------------------------------------------------------- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything from fundamentals to system administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click