
Proactive Defense
109
Proactive Defense tracks and blocks all dangerous operations by using the set of
rules together with a list of excluded applications.
In operation, Proactive Defense uses a set of rules included with the program, as
well as rules created by the user while using the program. A
rule
is a set of crite-
ria that determine a set of suspicious behaviors and Kaspersky Anti-Virus's reac-
tion to them.
Individual rules are provided for application activity and monitoring changes to
the system registry and programs run on the computer. You can edit the rules at
your own discretion by adding, deleting, or editing them. Rules can block actions
or grant permissions.
Let‟s examine the Proactive Defense algorithms:
1. Immediately after the computer is started, Proactive Defense analyzes
the following factors, using the set of rules and exclusions:
Actions of each application running on the computer
. Proactive De-
fense records a history of actions taken in order and compares
them with sequences characteristic of dangerous activity (a data-