Chapter
12
12. Inspector: Monitoring
Filesystem Integrity
12.1. Function and Features
The Inspector program is an integrity checker running under the Sun
Solaris operating system. Inspector performs the following functions:
•
monitors the defined location for changes.
•
checks for viruses in the defined location and removes them.
Unlike the Scanner and the Daemon programs, while searching
for viruses Inspector is not guided by virus-definitions in the
corresponding databases. The program identifies viruses in an
object with respect to the methods that have been used by a
virus to penetrate the file.
•
removes the detected virus (including the unknown viruses) from
the object or transfers it to the Daemon program.
While checking for changes in the defined location, Inspector collects the
location details and saves them to the database. Whenever started up
again Inspector rescans the location and checks the newly collected data
against the database. If it detects new or modified files with a structure that
is identified as suspicious or unknown, the program tries to cure them (to
189