Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 12, 2008, 08:08:56 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
199774
Posts
22931
Topics
55028
Members
Latest Member:
otter36
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Vulnerability Analyzer
CVA improvement suggestions & Wish-List
« previous
next »
Pages:
[
1
]
2
3
Author
Topic: CVA improvement suggestions & Wish-List (Read 8669 times)
LeoniAquila
Über Minimalist™ Defender of Resources Bloatware Fighter
Global Moderator
Comodo's Hero
Offline
Posts: 3608
Leone & Aquila
CVA improvement suggestions & Wish-List
«
on:
May 06, 2008, 03:29:36 PM »
Please post your CVA improvement suggestions and wishes in this thread! Thank you.
I'm first out:
1) Present a scan log which programs and system details CVA has scanned. If CVA, for example, doesn't know anything about a certain program - it would be nice to know that. Like a warning "this program isn't recognized by CVA, you should i) look for updates manually and ii) submit it to Comodo so we can add it to our database". In case there already is a log available (I haven't completely checked out the features of CVA), please ignore this suggestion.
2) Tell me that I had Defense+ disabled!
3) If CVA doesn't already check for the latest Microsoft hotfixes, maybe this could be a useful feature? I know that most people have Windows Automatic Updates, but if that feature for some reason misses a patch or two, CVA could cover that.
Thanks!
LA
«
Last Edit: July 11, 2008, 05:14:44 AM by LeoniAquila
»
Logged
» Windows XP Home Edition SP3 nLite
» COMODO Firewall Pro
LeoniAquila
Über Minimalist™ Defender of Resources Bloatware Fighter
Global Moderator
Comodo's Hero
Offline
Posts: 3608
Leone & Aquila
Re: CVA improvement suggestions
«
Reply #1 on:
May 14, 2008, 03:01:06 AM »
Umesh replied here, but now his post is gone? Anyway, Umesh confirmed that my first and third suggestions are planned to be part of CVA (that's how I remember it, if I'm wrong, please correct me).
LA
Logged
» Windows XP Home Edition SP3 nLite
» COMODO Firewall Pro
herman the german
Newbie
Offline
Posts: 14
Re: CVA improvement suggestions
«
Reply #2 on:
May 28, 2008, 01:55:23 AM »
i've got a sugestion as well. i've been using rival secunia's PSI which is in rc2 atm i think and when it detects something is out of date it offers a direct link to the website where the updated version can be found i was wondering if the vulnerability advisor could do the same?
cheers
herman the german
Logged
umesh
Global Moderator
Comodo's Hero
Offline
Posts: 313
Re: CVA improvement suggestions
«
Reply #3 on:
June 03, 2008, 07:18:37 AM »
Hi LeoniAquila,
I also wonder where my post has gone!
Yes we will have 1st and 3rd requests covered in forthcoming versions. Next version which we plan by 3rd week of June, 2008 is expected to have missing Windows patches information.
Regarding 2nd request, it was kind of connecting two products which we won't like to do, may be CFP can be improved to show you some balloon messages every often if D+ is disabled.
Regarding herman the german question if we take user as from where he can download latest version,
please check attached snap where CVA takes user to
http://www.rarlab.com/download.htm
when it finds an old version of Winrar is installed.
So CVA also has this feature.
Thanks
-umesh
Logged
Zero3K
Comodo Member
Offline
Posts: 48
Installed Programs
«
Reply #4 on:
June 08, 2008, 05:45:08 PM »
It should show a list of the ones that it knows about.
Logged
Ronny
Global Moderator
Comodo's Hero
Offline
Posts: 670
Re: CVA improvement suggestions
«
Reply #5 on:
June 10, 2008, 04:20:57 AM »
In reply to the 2nd request, i also found that a lack of CPF, the icon doesn't change if you disable the firewall or D+ to something with a red cross in it so you can see it's disabled. Therefore i wrote a small program that check's the Firewall and D+ State in the Registry and shows a balloon when the config is not in my own "default" state.
I think this would be a nice feature for an upcomming CPF release.
Logged
LeoniAquila
Über Minimalist™ Defender of Resources Bloatware Fighter
Global Moderator
Comodo's Hero
Offline
Posts: 3608
Leone & Aquila
Re: CVA improvement suggestions
«
Reply #6 on:
June 10, 2008, 05:19:33 AM »
Quote from: rhgtyink on June 10, 2008, 04:20:57 AM
In reply to the 2nd request, i also found that a lack of CPF, the icon doesn't change if you disable the firewall or D+ to something with a red cross in it so you can see it's disabled. Therefore i wrote a small program that check's the Firewall and D+ State in the Registry and shows a balloon when the config is not in my own "default" state.
I think this would be a nice feature for an upcomming CPF release.
I agree, but now you've gone off the CVA topic, so I suggest you put this on the CFP 3 wishlist!
Thanks,
LA
Logged
» Windows XP Home Edition SP3 nLite
» COMODO Firewall Pro
spasserfan
Newbie
Offline
Posts: 21
Re: CVA improvement suggestions
«
Reply #7 on:
July 01, 2008, 04:11:49 AM »
It would be nice if one could schedule scans. Since I do not want the program to run all the time these schedules should start the program, and if there is any updates prompt the user. When the job is finished the program should automatically close
As an addition to the above it would also be a great feature if CVA could be set to automatically install the updates by prompting the user when they are found: "updates has been found, will you update these programs now, later or manually?"
Logged
umesh
Global Moderator
Comodo's Hero
Offline
Posts: 313
Re: CVA improvement suggestions
«
Reply #8 on:
July 02, 2008, 01:22:26 AM »
Hi spasserfan,
Quote
* It would be nice if one could schedule scans. Since I do not want the program to run all the time these schedules should start the program, and if there is any updates prompt the user. When the job is finished the program should automatically close
would you like to see this implemented as Windows Tasks? That means CVA can provide an interface and using that details like they are entered in Windows Tasks about timing can be entered. So CVA is run by Windows at that time and generates the report under specified folder.
Quote
* As an addition to the above it would also be a great feature if CVA could be set to automatically install the updates by prompting the user when they are found: "updates has been found, will you update these programs now, later or manually?"
This is not trivial thing, updates vary from product to product and they can be very product specific. Like no other product can provide updates for Comodo Firewall Pro, b'caz the nature of updates, similarly can be the case for many other products.
Even if we venture out in this, we won't be able to cover all products, so the best is product in question updates itself which is done best by itself rather any other product.
Thanks
-umesh
Logged
gibran
Forum Member
Global Moderator
Comodo's Hero
Offline
Posts: 3834
Sometimes words are meaningless indeed...
Re: CVA improvement suggestions
«
Reply #9 on:
July 02, 2008, 03:22:31 PM »
I guess I'll add mine too.
Making CVA act as a frontend to Windows tasks would be nice but if possible I wish for a realtime vulnerability check too.
Secunia PSI beta had a something like this (although it didn't appear to be really realtime).
Maybe some sort of realtime scanning could be added making CVA-aware a future version of CFP.
Another nice feature would be to make CMF CVA-aware that is if there is a chance to let CMF know if a specific BO event can be linked to a specific exploit/advisory.
Logged
Read First
~
FAQs
~
Forum Policy
~
CFP3 Configuration Report
THE CORE RULES OF NETIQUETTE
umesh
Global Moderator
Comodo's Hero
Offline
Posts: 313
Re: CVA improvement suggestions
«
Reply #10 on:
July 02, 2008, 11:49:52 PM »
Hi gibran,
Real time scanning is in the pipeline, we will have it.
We although can change CMF so when it detects any vulnerability, it can send information about it to comodo.
But even though CMF alerts about any vulnerability, that product has to be analyzed and vulnerability has to be confirmed.
As of now role of CVA is just to inform users about known vulnerabilities and as of now Comodo is not in the business of exposing vulnerabilities and publish them.
Thanks
-umesh
«
Last Edit: July 02, 2008, 11:52:23 PM by umesh
»
Logged
gibran
Forum Member
Global Moderator
Comodo's Hero
Offline
Posts: 3834
Sometimes words are meaningless indeed...
Re: CVA improvement suggestions
«
Reply #11 on:
July 03, 2008, 03:27:38 AM »
Quote from: umesh on July 02, 2008, 11:49:52 PM
Real time scanning is in the pipeline, we will have it.
That's great news
Quote from: umesh on July 02, 2008, 11:49:52 PM
We although can change CMF so when it detects any vulnerability, it can send information about it to comodo.
But even though CMF alerts about any vulnerability, that product has to be analyzed and vulnerability has to be confirmed.
As of now role of CVA is just to inform users about known vulnerabilities and as of now Comodo is not in the business of exposing vulnerabilities and publish them.
Sorry I didn't explain myself as I know nearly nothing about BO and exploits. As I understand Vulnerability research require a cooperative approach and I understand that there is no way for a single company to take such a heavy task.
I always wondered if there could be a different way to warn user about a specific exploit attack. Usually AV signature-based approach can identify specific exploit code and alert the user.
However this type of detection is somewhat limited as changing the code to leverage on the same vulnerability could be undetected.
CMF instead trap BO on the fly and it can detect even new exploit code on the act. However as end user there is no sure-strike way to know if an alert was due to a malicious attempt.
As I don't have the necessary know-how I don't know it an existing BO vulnerability is able to trigger a well defined range of alerts regardless of the exploit code or end-user machine specific setups.
If there is a way to to bind an existing reported exploit/vulnerability to a specific set of alert characteristics then there would be an alternate way to detect exploits without relying on exploit code signatures.
Since CMF is monitoring BO events I wondered if there could be something like a BO signature (based for example only on memory range exception addresses, exploitable component name/signature and type of BO) specific enough to link a specific BO alert to an existing reported vulnerability (if that vulnerability provided exploit code to gather such data).
I don't know if there is a way to define something like a BO signature but I imagined if something like this was possible then it could be used an a way to complement existing AV code signature based approach (creating a chance for researchers to add such BO signature to new full disclosure advisories).
«
Last Edit: July 03, 2008, 03:29:29 AM by gibran
»
Logged
Read First
~
FAQs
~
Forum Policy
~
CFP3 Configuration Report
THE CORE RULES OF NETIQUETTE
spasserfan
Newbie
Offline
Posts: 21
Re: CVA improvement suggestions
«
Reply #12 on:
July 04, 2008, 01:02:30 PM »
Quote from: umesh on July 02, 2008, 01:22:26 AM
Hi spasserfan,
would you like to see this implemented as Windows Tasks? That means CVA can provide an interface and using that details like they are entered in Windows Tasks about timing can be entered. So CVA is run by Windows at that time and generates the report under specified folder.
This is not trivial thing, updates vary from product to product and they can be very product specific. Like no other product can provide updates for Comodo Firewall Pro, b'caz the nature of updates, similarly can be the case for many other products.
Even if we venture out in this, we won't be able to cover all products, so the best is product in question updates itself which is done best by itself rather any other product.
Thanks
-umesh
Implementing as windows task was just what I wanted, that way the check could be done when the system is idle. If CVA doesn't find any vulnerabilities then the program just shuts down silently, but if any vulnerabilities has been found it prompts the user.
As for updating programs automatically, it would be nice if one could specify a command line which CVA should run if vulnerabilities is found in a particular program (many programs has an external updater or some could be updated by using a command line switch). Of course the command line should be an option (deselected by standard) to make CVA user friendly but also making a good program for professionals.
The way you could implement this could be like this: The first time a vulnerability has been found in a program CVA would prompt the user (if the command line option is selected
) if he wanted to:
Set a command line for this program
Not to run a command line with this program
And of course an "remember" option (like in CFP) to let CVA run the specified command line every time a vulnerability has been found for that particular program or never run a command line for that particular program but instead prompt the user to manually update.
«
Last Edit: July 04, 2008, 01:53:48 PM by spasserfan
»
Logged
umesh
Global Moderator
Comodo's Hero
Offline
Posts: 313
Re: CVA improvement suggestions
«
Reply #13 on:
July 10, 2008, 11:16:41 PM »
Hi gibran,
Your ideas are great, we would consider it down the road.
Thanks
-umesh
Logged
3xist
Global Moderator
Comodo's Hero
Offline
Posts: 2707
Re: CVA improvement suggestions & Wish-List
«
Reply #14 on:
July 11, 2008, 02:39:02 AM »
Hi Guys,
I made this a sticky. This is now also the wish list for CVA.
Josh
Logged
||
***Please Read The Forum Policy Before Posting ANYTHING, Thanks!***
||
Tags:
Pages:
[
1
]
2
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.178 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com