Why is the anti-virus engine so important? It has been nearly half a month since 360 was revoked by AV-C, AV-TEST and Virus Bulletin, the three major anti-virus software testing organizations. After half a month of precipitation and calm thinking, we want to put the event itself aside, to talk about the anti-virus software from the perspective of ordinary users, how should we treat it. The 360 "and the accident" is the main problem in the two versions of the different engines, which allows the evaluation agency to determine the behavior of cheating, visible anti-virus engine plays a vital role in anti-virus software. So what is the antivirus engine? Simply put, the antivirus engine is a technical mechanism for determining whether a particular program behaves as a virus program. This is a relatively complex and sophisticated technology, and the virus is generally investigated by a variety of methods. The most important one is the signature scan, which compares the scan information with the virus database. If the information matches any of the virus signatures, the antivirus software will determine that the file is infected by the virus. When anti-virus software is used for killing, it will select one or several pieces of code inside the file as the way to identify the virus. This code is called the signature of the virus. There is also a file checksum, that is, after the engine scans the file, the contents of the normal file can be calculated, the checksum is calculated, and the checksum is written into the file or written in another file. Then, during the use of the file, periodically or before using the file, check whether the checksum calculated by the current content of the file is consistent with the originally saved checksum, thereby determining whether the file is infected with a virus. Process behavior monitoring is to summarize the common behavior of a set of viruses through observation and research on the virus for many years. These behaviors are rare in normal procedures. When the program is running, it monitors the various behaviors of its processes and alerts you if it detects a virus behavior. Finally, it is active defense technology, which is also the mainstream technology in recent years. This technology does not require virus signature support, as long as the engine can analyze and scan the behavior of the target program, and determine whether it should be cleared according to preset rules. operating. However, all of these methods have their own advantages and disadvantages at the same time. Therefore, whether the anti-virus engine can effectively use these technologies to achieve better defense effects is the key to judging the quality of an anti-virus engine. Generally speaking, judging whether the anti-virus engine is good or bad should be considered in many aspects, including: scanning speed, resource occupation, virus-removing ability, detection of polymorphic viruses, shelling ability, decryption ability, anti-flower command ability, and confrontation The ability of the point variant virus to fight against variant viruses, killing, stability, and compatibility. To say this is just to let everyone know why the three major evaluation agencies and 360 are catching up with the engine. Why AV-C thinks that 360 is just an engine is an unforgivable cheating. It can be said that using different engines is completely different products.