Welcome, Guest. Please login or register.
July 09, 2008, 04:53:28 AM

Login with username, password and session length

171787 Posts
20493 Topics
49867 Members

Latest Member: rampage

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  General Category
| |-+  Melih's Corner - CEO Talk/Discussions/Blog
| | |-+  A Door, A Burglar Alarm and Insurance - All you need for Computer Security!
« previous next »
Pages: [1] Go Down Print
Author Topic: A Door, A Burglar Alarm and Insurance - All you need for Computer Security!  (Read 1296 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5037



WWW
« on: May 05, 2008, 08:58:09 PM »

Layered Security in laymans terms. Please feel free to comment.

thanks
Melih
Logged

triple x
Comodo's Hero
*****
Offline Offline

Posts: 718


Everything in life comes to an end, exept life


« Reply #1 on: June 15, 2008, 05:51:22 PM »

An antivirus solution does actually act as a prevention utility because when it "knows" a threath it will prevent it from executing.

But a tradittional antivirus solution can only act as a prevention solution when a threath has occured to somebody and then the programmers make detection signatures and distribute them to their costumors. For the persons who have been hit for the first time by an unknown threath, the tradittional antivirus did not act as a prevention solution, but will act as a cure when the signature has been released to them. For the others it will act as a prevention solution because the signatures have been written after the damage has been done.

So a tradittional av solution works in two ways as a detection and as a prevention when it knows a threath.

I do agree that a full featured HIPS is the only piece of software that can be called a prevention solution, but  can not cure u when u have been infected.

So indeed Melih: Prevention, detection and cure are the ways to keep you safe!
Logged

Triple x says: "The path of success and progress is not to be reached by the things you have done, but by the things you will do, so think before you act, the voice of your history will confirm this fact... "

Triple X says: "Your system is as secure as the weakest link in your entire security..."
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5037



WWW
« Reply #2 on: June 16, 2008, 08:30:47 AM »

I must respectfully disagree that AV can prevent in a manner described by you.

The reason why it can stop a malware is because it "detects" it in the first place. And it can only prevent the ones it can "detect".

i thank you for your time triple x Smiley

Melih
Logged

gibran
Forum Member
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2847


Sometimes words are meaningless indeed...


« Reply #3 on: June 16, 2008, 10:03:08 AM »

There are many security products out there and if we account for detection, prevention and cure each one implement them at various degree.

AV comes in many flavors and are bundled in suites too.
There are plain AVs with no real-time scanning functionalities too.
There are AVs that cannot remove all kind of threats too.

I guess that we can all agree a the common denominator of AVs is detection.

HIPS on the other hand focus on prevention.

In my own experience I ran my system with only CFP for two months and I got no badware though this outcome was a result of my habits, security practices and I guess proper CFP usage.

During those two months I usually relied on CFP whitelist, Trusted Vendors and submit to comodo for analysis responses (I guess we can agree this is a sort of detection).
This way I was able to run trusted software without issues (meaning software I trusted or trusted by Comodo).

When I found software I did not know or Comodo did not analyze yet I relied on HIPS alerts in order to check installed software behaviours.
Still there were some cases an AV would have come in handy when I had to decide if some software was able to run/install kernel drivers.
If i didn't know much about that software I simply denied those requests and uninstalled that software.

I installed an AV again though because even if CFP features provided me a good security, AV detection could make my life easier.

Anyway I think that possible CFP3 future evolution and enhancements could compensate my need for AV detection.
« Last Edit: June 16, 2008, 10:35:49 AM by gibran » Logged

triple x
Comodo's Hero
*****
Offline Offline

Posts: 718


Everything in life comes to an end, exept life


« Reply #4 on: June 16, 2008, 10:20:38 AM »

So we all can agree that software that relies on detection can not be called a prevention solution because it lacks a good behaviour analyses.

We all can agree that the current cfp version needs the partners: "detection" and "cure" when prevention did not did it task, and the evolving cfp could make these partners in the future unnecessary.
Logged

Triple x says: "The path of success and progress is not to be reached by the things you have done, but by the things you will do, so think before you act, the voice of your history will confirm this fact... "

Triple X says: "Your system is as secure as the weakest link in your entire security..."
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5037



WWW
« Reply #5 on: June 16, 2008, 11:05:00 AM »

Very much so...

The "Detection" element to supplement CFP will be many fold, from the firewall alerting to files making a call, to the heuristic built in already into CFP v3 and all the way to CAV3 when fully integrated..

And the Cure will be

1)Backup (That exists today)
2)Comodo DiskShield (possible in certain scenerios) (only in beta today)
3)Comodo Sandbox (soon Smiley )
4)Comodo Security Experts manually fixing things for you! (that exists today btw)

So we have a very strong Prevention and very a strong Cure offering already today! With CAV3 the detection will also be strengthened further...

Melih
Logged

Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.096 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com