Larry you and I are exactly on the same page.
Steve Pitcher
iTech Solutions Group, LLC
p: (203) 744-7854 Ext. 176 | m: (902) 301-0810
www.itechsol.com | www.iInTheCloud.com
-----Original Message-----
From: MIDRANGE-L [mailto:midrange-l-bounces@xxxxxxxxxxxxxxxxxx] On Behalf Of Larry "DrFranken" Bolhuis
Sent: Friday, January 22, 2021 1:16 PM
To: Midrange Systems Technical Discussion <midrange-l@xxxxxxxxxxxxxxxxxx>; Rob Berendt <rob@xxxxxxxxx>
Subject: Re: Ransomware on Power
<snip>
On-demand - go scan selected directories/files.
On-access - real time scanning on ifs file opens and closes.
</snip>
This is important and a good clear distinction. I know that Patrick disagrees with me (dnd Steve too I think) but this description truly makes the distinction.
But the on-access is where you get the immediate stop.
And THAT is the key. No matter how often you scan no matter how up to date that scan was. Files could be placed with a virus, then accessed with that virus and the spread is on. Rather like testing negative for COVID and then not wearing a mask, after all you can't spread what you don't have, right? BUT that test was only a moment in time.
With the scan on write and scan on open it gets scanned every time AND no matter where it lives. New directories need not be added to some scan and no specific knowledge of what files are stored where is required.
- L
On 1/22/2021 7:16 AM, Rob Berendt wrote:
The on-demand is useful for:
- getting started
- After an outage of the on-access like a system restore, upgrade, or
other outage
- if you suspect you may have some files which got corrupted by a "day
1" virus and now you have the new pattern file
See also
WRKREGINF EXITPNT(QIBM_QP0L_SCAN*)
Rob Berendt
--
IBM Champion for Power Systems
www.iInTheCloud.com - Commercial IBM i and Power System Hosting www.iDevCloud.com - Personal IBM i Hosting www.Frankeni.com - IBM i and Power Systems Consulting.
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list To post a message email: MIDRANGE-L@xxxxxxxxxxxxxxxxxx To subscribe, unsubscribe, or change list options,
visit:
https://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives at
https://archive.midrange.com/midrange-l.
Please contact support@xxxxxxxxxxxxxxxxxxxx for any subscription related questions.
Help support midrange.com by shopping at amazon.com with our affiliate link:
https://amazon.midrange.com
As an Amazon Associate we earn from qualifying purchases.