Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 18, 2013, 01:17:53 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
668638
Posts
71101
Topics
145706
Members
Latest Member:
aydreej143
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Defense+ / Sandbox Help - CIS
Defense+ / Sandbox FAQ - CIS
Introduction to the 4.x sandbox
« previous
next »
Pages:
[
1
]
Author
Topic: Introduction to the 4.x sandbox (Read 26276 times)
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
Introduction to the 4.x sandbox
«
on:
March 11, 2010, 02:27:19 PM »
INTRODUCTION TO THE 4.x SANDBOX
This topic was drafted to provide an introduction to the 4.x sandbox. It may help you understand the 5.x sandbox, but some information will not be correct.
What is it for?
How does it work?
What is it not for?
Something wants 'unlimited access', what should I do?
How do I know what has been sandboxed?
How can I prevent software being sandboxed?
So.. is the sandbox really secure?
And.. Is it mature software?
What if I want to known more?
Will the sandbox work on 64 bit systems?
Please help us improve this introduction by posting suggestions to the 'Sandbox help materials - Feedback topic'
here
.
This introduction has been prepared by a volunteer moderator – with input from many other moderators (Thanks everyone, especially: Ronny, Omletguy, Dennis2, Arkangyal). It has been produced on a best endeavours basis - it will be added to and corrected as we find out more about the sandbox. Please note that I am not a member of staff and therefore cannot speak on behalf of Comodo.
Updated: 12 June 2010, to reflect changes up to CIS version 4.1.xxx.920
«
Last Edit: May 17, 2011, 01:38:31 PM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
What is it for?
«
Reply #1 on:
March 11, 2010, 02:28:46 PM »
The CIS sandbox helps CIS provide 'good enough security' with minimum inconvenience. It does this by automatically restricting what unknown software can do until it’s been checked out by Comodo. Because restrictions are automatic, there are almost no alerts [1]. Because restrictions are not severe, the software can (in the main) be used while analysis is pending.
[1] Global hook, certain COM interface, and internet access alerts may still occur for some programs in version 4.1. Comodo is working on this.
«
Last Edit: June 12, 2010, 08:09:13 AM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
How does it work?
«
Reply #2 on:
March 11, 2010, 02:30:04 PM »
Software unknown to CIS is, by default,
automatically
sandboxed unless it is installation software. The user is alerted [1]. Known safe software started by unknown software is also sandboxed, but without an alert [4]. Automatic sandboxing means that it runs with restricted operating system and defence plus privileges [2], greatly restricting the damage it can do if it is malware. It does not mean that files and registry keys created by the software are stored in the sandbox. The software is then sent to Comodo for analysis [3]. If it is pronounced safe then the software is automatically removed from the sandbox. If it's malware then the antivirus database will be updated, and you'll be offered the normal options to deal with it next time the software is run or scanned.
You can also choose to sandbox suspect software in the sandbox
manually
, but this facility is still very much under development. (Despite this, rather strangely, the GUI devotes most space to these facilities - 'Run a program in the sandbox' and 'Add a program to the sandbox' deal exclusively with manual sandboxing). If you sandbox software manually, some file and registry keys are, by default, stored or copied in the sandbox. Please see the Virtualisation FAQ
here
for further information on this facility. A range of other options are also available.
Footnote
[1] Automatic sandboxing is the default, it can be turned off by using the relevant tick box in 'Sandbox Settings'. Installation software is identified through file characteristics and by asking for administrator privileges in Windows.
[2] Technically, automatically sandboxed software can write to the disk but it cannot cannot a) write to (ie infect) existing protected files or registry keys b) take admin privileges c) consume too many resources d) key log or screen grab, set windows hooks, access protected COM interfaces or access non-sandboxed applications in memory e) access the internet without asking
[3] In early versions the submission service may not be continuously available, submissions may not be automatic, and files may take some time to be processed. Further info
here
.
[4] Even if it is in My Safe Files, & presumably, even if it is an installer
«
Last Edit: June 12, 2010, 08:53:42 AM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
What is it not for (yet)?
«
Reply #3 on:
March 11, 2010, 02:32:08 PM »
Although you can choose to sandbox software yourself, the current version of the CIS sandbox is not intended to be an alternative to a traditional sandbox like Sandboxie. The CIS sandbox does not intercept *all* actions by sandboxed software. It does not sandbox installation software, or installed program files and so cannot wipe all traces of installed software from your system if you decide to uninstall it. However it does provide good protection in other ways (see how the sandbox works) and these facilities are being constantly improved.
«
Last Edit: March 19, 2010, 09:18:36 AM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
Something wants 'unlimited access', what should I do?
«
Reply #4 on:
March 11, 2010, 02:32:53 PM »
You get 'unlimited access' alerts when CIS is faced with unknown
installation
software. The installation software needs greater Defense+ and operating system privileges than the CIS sandbox normally grants unknown software. If the setting 'Automatically recognise installer....' is checked, CIS grants installation software almost total freedom and suppresses all alerts (though it still makes log entries). You should say yes if you fully trust the vendor of the software, no or 'sandbox' otherwise.
If you say 'no' you can uncheck ''Automatically recognise' and re-run the installer with all Defense+ alerts enabled. If you say 'sandbox' the installer software will be sandboxed, and thus unable to damage your system, but the files that it installs, and registry keys it creates will be created in their normal locations (ie virtual copies will not be created in the sandbox). The installed files wil not be able to harm your system
unless you run the software from the installer
- so it's best not to do this.
«
Last Edit: June 12, 2010, 08:23:26 AM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
How do I know what has been sandboxed?
«
Reply #5 on:
March 11, 2010, 02:33:42 PM »
CIS will normally alert you, and make a D+ log entry everytime it automatically sandboxes software and when it removes software from the sandbox. Automatically sandboxed software also shows up in 'My pending files' alongside other software which has been submitted to Comodo for analysis. Automatically sandboxed files do not show up in 'Programs in the sandbox', which shows only manually sandboxed files added via 'Programs in the sandbox'.
However CIS will not generate an alert or a log entry when files are automatically sandboxed just because they are run by other files which are sandboxed. Nor will such files appear in my pending files.
More detail in the FAQ
here
.
«
Last Edit: May 31, 2010, 02:53:43 AM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
How can I prevent software being sandboxed?
«
Reply #6 on:
March 11, 2010, 02:34:23 PM »
When CIS tells you it wants to sandbox software, you can decline this, but you will have to re-start the software concerned to take it out of the sandbox. Alternatively you can unsandbox software by adding it to My Safe Files, either by using 'Move to' in 'My Pending Files' (details
here
) or by using 'Add' in 'My Safe Files', and restarting the software. Sometimes it can be difficult to remove files from the sandbox - information on how to get over this is
here
. NB Defining a file as a trusted file in the Computer Security Policy does not remove it from the sandbox.
«
Last Edit: June 12, 2010, 08:25:29 AM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
So.. is the sandbox really secure?
«
Reply #7 on:
March 11, 2010, 02:35:10 PM »
The CIS sandbox is designed to provide a good level of security in practice to a wide range of people, not the highest level of security in principle to a small number of experts.
Currently, using the sandbox is probably a good idea for less expert users operating in normal internet environments, as it reduces the tendency to automatically 'allow' possibly puzzling Defense+ alerts because of their frequency. More expert users operating in high risk internet zones should probably disable the sandbox and rely on their own expertise to make judgements on the basis of the Defense+ alerts that the sandbox suppresses. I am a reasonably experienced computer user but I have it enabled because it provides 'good enough' security, and leads to lower hassle computer use. It's facilities will doubtless become more secure over time.
«
Last Edit: March 11, 2010, 02:59:58 PM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
And.. is it mature software?
«
Reply #8 on:
March 11, 2010, 02:35:56 PM »
Not yet. It’s useful as it is, but we are promised that it will improve greatly both in usability and security in forthcoming releases.
«
Last Edit: March 13, 2010, 03:32:18 AM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
What if I want to known more?
«
Reply #9 on:
March 11, 2010, 02:36:46 PM »
As I find out more I'll edit this topic. A detailed screen by screen guide to all the settings is available in CIS help text, under 'Defense+ Tasks ~ Sandbox' and 'Introduction ~ Understanding alerts'. A faq is being developed
here
.
«
Last Edit: June 12, 2010, 08:36:57 AM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
Will the Comodo sandbox work on 64bit systems?
«
Reply #10 on:
March 19, 2010, 07:57:58 AM »
Yes it will. Except that
registry
virtualisation is disabled in 64bit Windows
XP
. The user is not currently informed about this - Comodo is considering adding an alert.
This is one of the main reasons why it is designed as it is. Most sandboxes will not work on 64 bit systems because they use undocumented OS facilities (which do not work in 64bit) to intercept program to program communications. The CIS sandbox avoids this by not creating virtual copies of installed programs, which means it does not need to intercept these communications.
«
Last Edit: June 12, 2010, 08:27:22 AM by mouse1
»
Logged
Please see the
Introduction to the sandbox
.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7506
Re: Introduction to the Sandbox
«
Reply #11 on:
June 12, 2010, 09:21:54 AM »
BUMP to top
Logged
Please see the
Introduction to the sandbox
.
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.05 seconds with 23 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com