Verify All Running Applications and Library Modules

Orthrus is an intrusion prevention application that stops malware infection mainly by malware behavior analysis. Since it does not posses a set of malware signature patterns, Orthrus may not identify existing malwares in a client computer. It does, however, have a collection of cryptographic signatures of commonly used legitimate applications.

This collection of legitimate signatures, in combination with the File Protection security feature in Windows operating systems, allows Orthrus to prove the legitimacy of the majority of running applications and library modules.

Orthrus uses the Microsoft .net WATCHER technique to examine all processes and library modules that may be malicious when they are started. For those that are unknown to Orthrus and are not part of the operating system, Orthrus sends their identity information to WNSC's secure web server for verification. If the executable is determined malicious, Orthrus will be instructed to quarantine it. Orthrus communicates with the web server according to this schedule: after the first two minutes of a machine restart; after 30:00 min; then seven times in the next 28 hours; and thereafter every 8:00:00 hours. Whenever an unverified executable or library module starts, Orthrus will send the file identity information to the web server within 5 seconds and the above timeline of communication schedule repeats.

Security analysts at WNSC verify the executables by looking up file name references on the Internet. If there is no reference or there are only negative references, i.e., the executable has been reported malicious by other security vendors, then this executable is classified as malicious.

A proprietary cryptographic signature of the executable (the ImageID), which is included in the information package sent to the web server is used to identify this executable. If there are conflicting references in the Internet search results of the file name, then identifying information such as the file version, file size, vendor, and last modified time of this executable will be compared against those sent by Orthrus. If the executable is available to download from the manufacturer's web site, it will be downloaded and its signature calculated and compared.


 
   
    Free Orthrus Download | System Requirements | About Us | FAQ | Site License | Home