Well, to be honest, you can’t make a behavior detection any other way than everyone are already doing it (more or less). You can just twist, modify and redesign the basics and make something more flexible and better, but it will still operate in a very similar way.
Wow, Kaspersky has very advanced roll back mechanisms - The roll-back system works with created and modified executable files, MBR modifications, important Windows files and registry keys.
Systemwatcher can also roll back changes that where made before a reboot. I wonder in virusscope can do that or that it only stores changes made in the current windows session.
Systemwatcher is also much more than detecting virusses by dangerous activity patterns and roll back the actions. For example it also contains the exploit prevention module, heuristic analysing , module for screen locker detection/protection etc. They have a 3-4 years lead. Hope Comodo can make it usefull and maybe even better ;D
The question is : Have they implemented all these features for SystemWatcher as soon as it got released ? (I don’t know which version they released it though)
No it was a long way. Screenlocker protection for 2014 suite. Exploit prevention in 2013 suite. Remember changes even when the system has reboots wasn’t there in the first release but i don’t know when it was added.
I can see why Kaspersky is considered one of the best, they even use Zeta shield which use to be used for business clients, but is now implemented in to KIS 2014.