, let me explain:
a "classic style" HIPS it's:
1) a list of apps,
2) a list of permissions,
3) a list of protected areas and
4) a relational web betwen them.
It can't b simplified not because "menthality" but because "a nature of things"
. Sorry, but it's reality where we lives.
All U can do to "simlify" (in quotes) that -- is to group some "list items" together and make user to make decision not about every
relation item but a group of relations
instead. It's just one more level of abstraction. But when U abstract something U drop out some details, isn't it? And all this dropped details fails into categ. "potential
hole" (two words in a one term, read them together). Will this "potentials" b promoted into "real" -- it's other talk, but they are exists
A good sample of abowe it's CFP "Alert Freq"
It's only groups many
possible decisions into one
. Yes it's simplifies a decision making but
for a price of creating potential holes. If U didn't agreed then reread the previous paragraph again.
For example when U r in a default "allert freq" mode and runs some... well, "the some" that needs a bit of network
and U plans use this "some" again - U allows it activity, "remembers" it and... Welcome, BackOrifice and Co - I have a bunch of allowed ports and addresses!..
A way to really
simplify CFP config is
1) a nested
Here under "rule" i mean a set
of "elementhary rules" created according to real world activity templates (mix together udp/tcp/icmp and different addresses regardless "simplification"
2) a turns from total control of a system to something like MAC-based
almost any prog almost everything
(of course while still watching for it
they really tries to do something wrongMelih
, it's good that Mods reads this -- I hope they can give something to devels. Pls note that all my opinions abowe are based on a many competetive products from DefenceWall and Symantec to Kerio and ProSecurity (and many other). And all the best things in that set (regardelss users group they are aimed to) are never mix flies and beefs and focuses entirely on that aimed in general regardless what it is -- a simplest isolation (DW) or totally detailed contorl of everything (PS).
PS. Currently CFP tries to sit on two chairs simultaneously. May b it's better to create two completely different UI modes (housewife-mode and geek-mode
) and devel them independedly?