Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 11, 2008, 12:47:05 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
199117
Posts
22882
Topics
54918
Members
Latest Member:
bithost
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
HIPS (Host Intrusion Prevention Systems)
HIPS in the upcoming CPF
« previous
next »
Pages:
1
2
3
[
4
]
5
Author
Topic: HIPS in the upcoming CPF (Read 27498 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5677
Re: HIPS in the upcoming CPF
«
Reply #45 on:
May 05, 2007, 09:31:51 PM »
Quote from: MattLee on May 05, 2007, 12:44:43 PM
will the hips someday end up a lot like whats in ghost security suite by ghost security?
no!
Logged
Visit Melih's Blog
kailasa108
Newbie
Offline
Posts: 12
Re: HIPS in the upcoming CPF
«
Reply #46 on:
May 14, 2007, 11:21:10 AM »
I've been playing with all of the HIPS style programs for the last few months.
Here's what I would like to see -
a totally BEHAVIOR-based (i.e. NON-signature & NON-list-based, NON-scanning) real-time monitor;
that completely interfaces with a firewall;
AND ***** that automatically sandboxes new installs AND updates for a selected amount of time
(until the software "proves" itself), and then is released to the actual environment
or otherwise the installation is "rolled-back" and undone. *****
My ideal HIPS is complete, and automatic. I really don't think most people are savvy enough to use a HIPS otherwise, so, that HIPS becomes the "boy-who-cried-Wolf" and they just blow through all of the warnings and the advantages are lost.
CyberHawk and SanaSecurity SafeConnect do the behavioral-based best job I've seen so far...but they don't have the installation sandboxing. Having this would put the COMODO product in a class by it self!!!!!
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: HIPS in the upcoming CPF
«
Reply #47 on:
May 14, 2007, 01:20:10 PM »
Quote from: kailasa108 on May 14, 2007, 11:21:10 AM
Here's what I would like to see -
a totally BEHAVIOR-based (i.e. NON-signature & NON-list-based, NON-scanning) real-time monitor;
***
My ideal HIPS is complete, and automatic. I really don't think most people are savvy enough to use a HIPS otherwise, so, that HIPS becomes the "boy-who-cried-Wolf" and they just blow through all of the warnings and the advantages are lost.
kailasa108,
Can you explain how you would like to see a HIPS that is completely behavior-based, and yet automatic? As a concept, the two seem exclusive of each other... if it's automatic, it's based on a list of some sort; if it's behavioral, it's based on a user-response (because there are safe actions that seem suspicious; thus user reaction is required).
I know CH has both aspects - a blacklist/definitions for automatic protection, and heuristics/behavioral analysis requiring user response. I'm not familiar with SafeConnect.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
kailasa108
Newbie
Offline
Posts: 12
Re: HIPS in the upcoming CPF
«
Reply #48 on:
May 19, 2007, 01:49:21 PM »
LM,
Well, IMHO, here's what I see. First of all, this pure HIPS system would be ONLY that - a "host intrusion prevention".. It would NOT try to be an A/V, an A/S, a firewall, a network monitor or anything else. So, it would NOT concern itself with getting rid of currently present "live" infections. It WOULD catch inactive infections.
It would do this by a combination of a heuristic artificial intelligence that utilizes an application/process database containing things like version #s, file dates, checksums, dependencies, call routines, file accesses, registry keys, etc. The HIPS would build this database upon install, by executing each installed program and routine in a virtual environment (sandbox) and "observing" them. Yeah, it might take a while to run this, but I'm used to doing full scans when installing an A/V or A/S, so this would be no different.
Once the database is built it would be securely resident in RAM (protected from tampering or shutdown by zero-day/rootkit attacks), and the HIPS would watch everything. If anything changes, the entire suspect program, its processes and dependencies would be sandboxed, automatically. The user would be
informed
, not questioned. The user would be allowed to
override
the HIPS system if they are certain the changes are safe (as in installed from a reliable media). Otherwise, the new or modified program would be re-"processed" in the sandbox. The heuristic AI would determine if anything was "bad". If so, the install/modification would be rolled back and removed. If not, the install/mod would be "released" into the real environment, its info added into the database and observed for any changes like the rest.
I've seen bits and pieces of this approach in different HIPS-type programs, but not all together at the same time. SanaSecurities Safe Connect and the new SafenSec Pro comes the closest. But I think COMODO could "just do it" and be the one that everyone else plays "catch-up" with - like their firewall.
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: HIPS in the upcoming CPF
«
Reply #49 on:
May 19, 2007, 05:43:37 PM »
That'd sure be a piece of work! There has been other mention of having a sandbox aspect to the HIPS, and I mentioned earlier basically the same thing about the installation monitoring. I think some sort of install mode is a crucial thing, in order to keep users from turning the HIPS off while installing applications.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
terbev
Newbie
Offline
Posts: 20
Re: HIPS in the upcoming CPF
«
Reply #50 on:
May 19, 2007, 06:07:14 PM »
This may be a dumb question, but I am good at them. With the CPF 3 being so powerful, will we still have a use for BOCleaner?
Logged
kailasa108
Newbie
Offline
Posts: 12
Re: HIPS in the upcoming CPF
«
Reply #51 on:
May 19, 2007, 09:55:40 PM »
Quote from: terbev on May 19, 2007, 06:07:14 PM
This may be a dumb question, but I am good at them. With the CPF 3 being so powerful, will we still have a use for BOCleaner?
Terbev, I don't think your question is dumb at all! Again, IMHO, there is STILL a need for BOClean in this scenario....
You've probably seen movies where a security perimeter is set up AFTER the "bad guy" is ALREADY inside right? Which makes the perimeter guard pointless, except to stop another "baddie" from coming in.
Well, let's say CPF 3 contains my ideal HIPS mentioned above. The HIPS is the perimeter guard. First, I would use something like BOC to sweep through and see if anything "bad" ALREADY was present, and remove it.
So, in the security suite that I have seen users asking COMODO to develop, the suite would initiate BOC to do a "clean sweep" BEFORE initiating the HIPS system.
Logged
carioca
Comodo Family Member
Offline
Posts: 67
Re: HIPS in the upcoming CPF
«
Reply #52 on:
May 20, 2007, 09:33:53 AM »
BY the way, When will CPF version 3.0 be released? Might you forescast the previewand final launching date? Best Regards.
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5677
Re: HIPS in the upcoming CPF
«
Reply #53 on:
May 20, 2007, 09:41:39 AM »
Quote from: carioca on May 20, 2007, 09:33:53 AM
BY the way, When will CPF version 3.0 be released? Might you forescast the previewand final launching date? Best Regards.
7th june beta..
end of june for production all being well.
Melih
Logged
Visit Melih's Blog
wilpower
Comodo Loves me
Offline
Posts: 157
LIVE LIKE YOU MEAN IT, THINK LIKE YOU CARE.
Re: HIPS in the upcoming CPF
«
Reply #54 on:
May 20, 2007, 12:24:32 PM »
Quote from: Little Mac on May 19, 2007, 05:43:37 PM
That'd sure be a piece of work! There has been other mention of having a sandbox aspect to the HIPS, and I mentioned earlier basically the same thing about the installation monitoring. I think some sort of install mode is a crucial thing, in order to keep users from turning the HIPS off while installing applications.
LM
Hey all> Can this be done?...if so...Would it then not be absolutely essential to secure the talent and get it done?
I'm only a 'programer' in my dreams........heehee.
Logged
Holy Crap!!...More then one star.
"Use of COMODO Security Programs is not only Advised" Use is Highly Recommend!!
Paweu
Newbie
Offline
Posts: 1
Re: HIPS in the upcoming CPF
«
Reply #55 on:
June 04, 2007, 11:09:06 AM »
Hello.
I would rather see not only whitelist HIPS. Apart of safety - in my opinion, HIPS may be very usefull to make life of computer user easier. For example: I use HIPS features of GMER to block from running some processes which are combined with many software and which - when ther are many of them - slow down PC very very much.
Man installs java - nobody asks him whether he wants to have java update scheduler beeing autostarted or not. Same with printer driver updater and some stupid printer manager, same with some strange "nerocheck", same with strange process from one of the office suites, same with mobile phone software... And when man allows those and many others to run - he needs P4 4Ghz to make his PC boot in less than 5 minutes. In most cases it is possible to turn them off, but not anytime (like some processes or services from Nokia 6630 software if I remember correctly
). Rule based HIPS give information and allows user to prevent nuisanance of "good" software.
Greetings
Ps. Sorry for my bad English.
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: HIPS in the upcoming CPF
«
Reply #56 on:
June 04, 2007, 12:18:06 PM »
Welcome, Paweu
Melih has stated that in addition to the safelist aspect of the HIPS, there will be a high level of control available through user configuration. In my mind, based on some things he has said in the past, this will take it to a level far beyond what applications like ProcessGuard have done in the past. I think there's a very good chance that it will do what you are looking for.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
kailasa108
Newbie
Offline
Posts: 12
Re: HIPS in the upcoming CPF
«
Reply #57 on:
June 04, 2007, 04:26:31 PM »
Quote from: wilpower on May 20, 2007, 12:24:32 PM
Hey all> Can this be done?...if so...Would it then not be absolutely essential to secure the talent and get it done?
I'm only a 'programer' in my dreams........heehee.
Not only can it be done...someone has started doing it!! Both PREVX2 and SafenSec Pro is doing their versions of what I suggested above. BUT, neither one of them is a firewall.
PREVX2 has taken the lead as a superHIPS at this time (IMHO)...SEVEN signature engines, and COMMUNITY-based white/black-listing, PLUS the sandboxing! Wow!
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5677
Re: HIPS in the upcoming CPF
«
Reply #58 on:
June 05, 2007, 01:53:58 PM »
what is a seven signature engine?
thanks
Melih
«
Last Edit: June 05, 2007, 04:27:10 PM by Melih
»
Logged
Visit Melih's Blog
carioca
Comodo Family Member
Offline
Posts: 67
Re: HIPS in the upcoming CPF
«
Reply #59 on:
June 05, 2007, 03:04:44 PM »
Quote from: kailasa108 on June 04, 2007, 04:26:31 PM
Not only can it be done...someone has started doing it!! Both PREVX2 and SafenSec Pro is doing their versions of what I suggested above. BUT, neither one of them is a firewall.
PREVX2 has taken the lead as a superHIPS at this time (IMHO)...SEVEN signature engines, and COMMUNITY-based white/black-listing, PLUS the sandboxing! Wow!
Hi, buddy! When I used Prevx and safe'n'sec pro FYI my computer got a mule or a turtoise and I had had with the second one too many splash screens that I almost went bananas! Thus, I woudn't like CFP got that way! I think in my humble opinion it's too much aggressive for a security stuff ! I have the ghost security licenses but I stopped using because a lot of popups. It's annoying.Best Regards.
Logged
Tags:
HIPS
Pages:
1
2
3
[
4
]
5
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.165 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com