Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 19, 2013, 06:14:04 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
669085
Posts
71142
Topics
145754
Members
Latest Member:
JennyAlex
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
General Category
Melih's Corner - CEO Talk/Discussions/Blog
What you need to know for your Computer Security
« previous
next »
Pages:
1
2
[
3
]
4
Author
Topic: What you need to know for your Computer Security (Read 47725 times)
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12949
Re: What you need to know for your Computer Security
«
Reply #30 on:
June 06, 2010, 08:58:45 PM »
Quote from: Tech on June 06, 2010, 04:10:24 PM
I think you (Melih) reduce the potential of the antivirus in the article. At least, some of modern antivirus. You can have more than just file protection (as it the oldies). The http traffic scanning, the heuristic analysis, the generic signatures, the sandbox and coding emulation are some of the weapons of the new arsenal.
Of course, you need more than just an antivirus. Firewall, safe browser, safe browsing habits (the most difficult thing to achieve...), a HIPS tool will help and contribute. I tend to think in layered defense way.
Does your Antivirus (and whatever it may have in it) allow "unknown" application to execute?
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: What you need to know for your Computer Security
«
Reply #31 on:
June 06, 2010, 09:03:28 PM »
What do you mean with unknown? If the antivirus has a whilelist and then block the applications out of it? No, for sure not.
But the antivirus could block infections by its behavior and not classified/named yet (unknown).
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
Chiron
Global Moderator
Comodo's Hero
Offline
Posts: 5780
Re: What you need to know for your Computer Security
«
Reply #32 on:
June 06, 2010, 09:59:49 PM »
Quote from: Tech on June 06, 2010, 09:03:28 PM
What do you mean with unknown? If the antivirus has a whilelist and then block the applications out of it? No, for sure not.
But the antivirus could block infections by its behavior and not classified/named yet (unknown).
I don't think Melih is implying that an antivirus has no place in computer security. (If this were true than Comodo Antivirus would be a bit of an enigma.)
I believe his point is that you cannot trust any
detection
based technology to solely defend your computer. Something may get through, and as malware writers test their creations to ensure they won't be detected by most antiviruses when they are released into the wild, then it's very likely that many people will be infected before the detections are updated. Behavioral analyzers can also be fooled, although I still think they're a great layer in addition to a HIPS and a traditional AV. Thus a HIPS is the only type of protection that can actually stop almost 100% of even the most advanced and newly created malware.
I think that's his point, but I could be wrong.
Logged
How To Install Comodo Firewall
How To Stay Safe While Online
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: What you need to know for your Computer Security
«
Reply #33 on:
June 07, 2010, 06:22:10 AM »
Quote from: Chiron on June 06, 2010, 09:59:49 PM
I believe his point is that you cannot trust any
detection
based technology to solely defend your computer.
If so, I fully agree. I believe in layered defense and think people should give the best to do
something
the best possible. Focus.
Quote from: Chiron on June 06, 2010, 09:59:49 PM
Thus a HIPS is the only type of protection that can actually stop almost 100% of even the most advanced and newly created malware.
If fact, it's not in the real world... you can answer a question badly and then...
HIPS is a very good weapon against malware, I know, but it's not the panacea in my opinion.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12949
Re: What you need to know for your Computer Security
«
Reply #34 on:
June 07, 2010, 07:22:31 AM »
Quote from: Tech on June 06, 2010, 09:03:28 PM
What do you mean with unknown? If the antivirus has a whilelist and then block the applications out of it? No, for sure not.
But the antivirus could block infections by its behavior and not classified/named yet (unknown).
I am trying to point out if your security product is built on "default deny" or "default allow" architecture.
If your system allows an unknown application/file to run..then its default alow...
so try it...with other products and see...
if its default allow system....then let me know and we can talk the problems of Default allow systems...
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: What you need to know for your Computer Security
«
Reply #35 on:
June 07, 2010, 07:31:55 AM »
I have UAC turned on.
I use ThreatFire with the standard configuration (not that many questions).
avast shields on (scanning all files/memory).
I don't know if you consider such system as "default allow".
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12949
Re: What you need to know for your Computer Security
«
Reply #36 on:
June 07, 2010, 07:35:17 AM »
Quote from: Tech on June 07, 2010, 07:31:55 AM
I have UAC turned on.
I use ThreatFire with the standard configuration (not that many questions).
avast shields on (scanning all files/memory).
I don't know if you consider such system as "default allow".
simple test: Run an "unknown" application or file... (eg: create a hello world application exe and run) if not ask someone to provide it to you..lets see if your system stops it..
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: What you need to know for your Computer Security
«
Reply #37 on:
June 07, 2010, 07:37:56 AM »
Quote from: Melih on June 07, 2010, 07:35:17 AM
if not ask someone to provide it to you
Can you give me a link to download it?
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
brucine
Comodo's Hero
Offline
Posts: 1533
Re: What you need to know for your Computer Security
«
Reply #38 on:
June 07, 2010, 08:51:22 AM »
http://www.win.tue.nl/hashclash/SoftIntCodeSign/
Note: it is of course of no use, because before having downloaded an run "hello world" or whatever exe, one knows it shall be intercepted by defense+, but not by a "database" antivirus.
Also note that, without speaking of HIPS, the default firewall behavior (unknown application) should be deny.
If i allow the defense+ request, cis firewall doesn't say anything (general configuration, it would be a serious failure, or only my special lan rules, the exe is run from my desktop?).
«
Last Edit: June 07, 2010, 09:05:26 AM by brucine
»
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: What you need to know for your Computer Security
«
Reply #39 on:
June 07, 2010, 10:17:21 AM »
Indeed, a clean file for the antivirus (
http://www.virustotal.com/analisis/15b1161906ef5f59d1c3f804e5ae6ba69d201a8092ec93d05ea81663c1e2f274-1267311620
).
Isn't it a proof of concept only? Who am I to talk with prof. Wang... I'm far behind this knowledge, but seems that you can't exploit that so easily to infect a computer, that is why I am asking if it is not only a proof of concept. He reported some use of it, are the antivirus companies just "lazy" to find a way to protect this?
How will HIPS behave in this situation?
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
brucine
Comodo's Hero
Offline
Posts: 1533
Re: What you need to know for your Computer Security
«
Reply #40 on:
June 07, 2010, 11:51:42 AM »
Professor Wang is .... a Professor and a searcher, and as such wrote something yes, quite theoric, but that could be easily exploited.
And the "goodbye world" thing has not to be intercepted by AV since it is innocuous: it merely serves as an example to show that 2 different files can have the same MD5, to conclude that MD5 is not a safe protection anymore.
In the same time, load eicar.exe to virus total or download it, and everyone shall jump altough eicar is also perfectly innocuous.
The problem is that AV rely on databases and sometimes "heuristic behavior", but that even "heuristic behavior" relies on a database: not in the database, not caught, and it is the reason of the "hello world" suggestion by Melih, but where if you were writing yourself your own malicious "hello world" program, it would never be caught, the only line of defense remaining a "unknown file default blocking behavior".
I don't use CIS AV, but i believe it wouldn't be more efficient against this kind of threat than Avira, failing.
I also get no warning whatsoever from CIS firewall, but of course, when i try to run "hello world", defense+ warns me that it is unknown.
We also must remind that, if not getting fooled by one file between many in a downloaded compressed folder, the best line of defense is betweeen our ears: no one should be fool enough to run a file he is not sure of.
The "compressed folder" situation is somewhat more difficult, and can be compared to mail attachements: if one does not deliberately click the unknown file, he stays safe if he forbids default scripting (IE Active X and so on, calling the malicious file when you meant to open plain html).
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: What you need to know for your Computer Security
«
Reply #41 on:
June 07, 2010, 12:34:29 PM »
Quote from: brucine on June 07, 2010, 11:51:42 AM
To conclude that MD5 is not a safe protection anymore.
I've received the following answer from Igor (an avast developer):
Quote
Still, I don't see the problem as that critical... I mean, for an successful attack, you have to deliver an executable on your machine, let the user allow that in the firewall, and then
replace
the file with the other one. Who would perform that replacement, however... a malicious code, already running on the computer? If so, then there's probably an easier way than abusing MD5 collisions.
Quote from: brucine on June 07, 2010, 11:51:42 AM
and it is the reason of the "hello world" suggestion by Melih
Does he really mean just that? Or something else?
Quote from: brucine on June 07, 2010, 11:51:42 AM
but where if you were writing yourself your own malicious "hello world" program, it would never be caught, the only line of defense remaining a "unknown file default blocking behavior".
Well... not exactly. The malware behavior of "my" "hello world" could be caught by other antimalware techniques besides the signatures...
Quote from: brucine on June 07, 2010, 11:51:42 AM
I don't use CIS AV, but i believe it wouldn't be more efficient against this kind of threat than Avira, failing.
For sure it won't...
Quote from: brucine on June 07, 2010, 11:51:42 AM
I also get no warning whatsoever from CIS firewall, but of course, when i try to run "hello world", defense+ warns me that it is unknown.
And what if the user clicks "ok"...? Such a no-fool technology is to be developed.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
davidfcabral
Newbie
Offline
Posts: 1
Re: What you need to know for your Computer Security
«
Reply #42 on:
June 07, 2010, 01:01:19 PM »
[Mr Melih. Call free Comodo Internet Security Supplement for a year, i'm unemployed and i can not afford. Thanks
«
Last Edit: June 07, 2010, 01:05:07 PM by davidfcabral
»
Logged
brucine
Comodo's Hero
Offline
Posts: 1533
Re: What you need to know for your Computer Security
«
Reply #43 on:
June 07, 2010, 01:41:40 PM »
Quote
And what if the user clicks "ok"...? Such a no-fool technology is to be developed.
On what behalf, excepting an infinite database?
In the conditions you are speaking of, i would forever be thrown out of some dos utilities, and i definitely wouldn't like it.
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: What you need to know for your Computer Security
«
Reply #44 on:
June 07, 2010, 01:55:30 PM »
Quote from: brucine on June 07, 2010, 01:41:40 PM
On what behalf, excepting an infinite database?
Indeed. It's a problem: databases increases indefinitely.
Behavior blocker helps. Generic signatures and algorithm detection reduces the size of the database.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
Tags:
Pages:
1
2
[
3
]
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.056 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com