Welcome, Guest. Please login or register.
October 11, 2008, 11:34:02 PM

Login with username, password and session length

199494 Posts
22905 Topics
54978 Members

Latest Member: ravendruid1

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  General Category
| |-+  Melih's Corner - CEO Talk/Discussions/Blog
| | |-+  A Door, A Burglar Alarm and Insurance - All you need for Computer Security!
« previous next »
Pages: [1] Go Down Print
Author Topic: A Door, A Burglar Alarm and Insurance - All you need for Computer Security!  (Read 2805 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5686



WWW
« on: May 05, 2008, 08:58:09 PM »

Layered Security in laymans terms. Please feel free to comment.

thanks
Melih
Logged

Fake vegeta
Comodo's Hero
*****
Offline Offline

Posts: 1071


Everything in life comes to an end, exept life


« Reply #1 on: June 15, 2008, 05:51:22 PM »

An antivirus solution does actually act as a prevention utility because when it "knows" a threath it will prevent it from executing.

But a tradittional antivirus solution can only act as a prevention solution when a threath has occured to somebody and then the programmers make detection signatures and distribute them to their costumors. For the persons who have been hit for the first time by an unknown threath, the tradittional antivirus did not act as a prevention solution, but will act as a cure when the signature has been released to them. For the others it will act as a prevention solution because the signatures have been written after the damage has been done.

So a tradittional av solution works in two ways as a detection and as a prevention when it knows a threath.

I do agree that a full featured HIPS is the only piece of software that can be called a prevention solution, but  can not cure u when u have been infected.

So indeed Melih: Prevention, detection and cure are the ways to keep you safe!
Logged

Vegeta says: "The path of success and progress is not to be reached by the things you have done, but by the things you will do, so think before you act, the voice of your history will confirm this fact... "

Vegeta says: "Your system is as secure as the weakest link in your entire security..."
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5686



WWW
« Reply #2 on: June 16, 2008, 08:30:47 AM »

I must respectfully disagree that AV can prevent in a manner described by you.

The reason why it can stop a malware is because it "detects" it in the first place. And it can only prevent the ones it can "detect".

i thank you for your time triple x Smiley

Melih
Logged

gibran
Forum Member
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3819


Sometimes words are meaningless indeed...


« Reply #3 on: June 16, 2008, 10:03:08 AM »

There are many security products out there and if we account for detection, prevention and cure each one implement them at various degree.

AV comes in many flavors and are bundled in suites too.
There are plain AVs with no real-time scanning functionalities too.
There are AVs that cannot remove all kind of threats too.

I guess that we can all agree a the common denominator of AVs is detection.

HIPS on the other hand focus on prevention.

In my own experience I ran my system with only CFP for two months and I got no badware though this outcome was a result of my habits, security practices and I guess proper CFP usage.

During those two months I usually relied on CFP whitelist, Trusted Vendors and submit to comodo for analysis responses (I guess we can agree this is a sort of detection).
This way I was able to run trusted software without issues (meaning software I trusted or trusted by Comodo).

When I found software I did not know or Comodo did not analyze yet I relied on HIPS alerts in order to check installed software behaviours.
Still there were some cases an AV would have come in handy when I had to decide if some software was able to run/install kernel drivers.
If i didn't know much about that software I simply denied those requests and uninstalled that software.

I installed an AV again though because even if CFP features provided me a good security, AV detection could make my life easier.

Anyway I think that possible CFP3 future evolution and enhancements could compensate my need for AV detection.
« Last Edit: June 16, 2008, 10:35:49 AM by gibran » Logged

Fake vegeta
Comodo's Hero
*****
Offline Offline

Posts: 1071


Everything in life comes to an end, exept life


« Reply #4 on: June 16, 2008, 10:20:38 AM »

So we all can agree that software that relies on detection can not be called a prevention solution because it lacks a good behaviour analyses.

We all can agree that the current cfp version needs the partners: "detection" and "cure" when prevention did not did it task, and the evolving cfp could make these partners in the future unnecessary.
Logged

Vegeta says: "The path of success and progress is not to be reached by the things you have done, but by the things you will do, so think before you act, the voice of your history will confirm this fact... "

Vegeta says: "Your system is as secure as the weakest link in your entire security..."
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5686



WWW
« Reply #5 on: June 16, 2008, 11:05:00 AM »

Very much so...

The "Detection" element to supplement CFP will be many fold, from the firewall alerting to files making a call, to the heuristic built in already into CFP v3 and all the way to CAV3 when fully integrated..

And the Cure will be

1)Backup (That exists today)
2)Comodo DiskShield (possible in certain scenerios) (only in beta today)
3)Comodo Sandbox (soon Smiley )
4)Comodo Security Experts manually fixing things for you! (that exists today btw)

So we have a very strong Prevention and very a strong Cure offering already today! With CAV3 the detection will also be strengthened further...

Melih
Logged

sweetlife2005
Newbie
*
Offline Offline

Posts: 1



« Reply #6 on: October 06, 2008, 10:29:49 AM »

Your home computer is a popular target for intruders. Why? Because intruders want what you’ve stored there. They look for credit card numbers, bank account information, and anything else they can find. By stealing that information, intruders can use your money to buy themselves goods and services.

Before diving into the tasks you need to do to secure your home computer, let’s first think about the problem by relating it to something you already know how to do. In this way, you can apply your experience to this new area.  Nerd
Logged

Rednose
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 1329


Ganda's sleepy ( in his wildest dreams )


« Reply #7 on: October 06, 2008, 11:24:02 AM »

And the Cure will be

1)Backup (That exists today)
2)Comodo DiskShield (possible in certain scenerios) (only in beta today)
3)Comodo Sandbox (soon Smiley )
4)Comodo Security Experts manually fixing things for you! (that exists today btw)

So we have a very strong Prevention and very a strong Cure offering already today! With CAV3 the detection will also be strengthened further...

Hi Melih Smiley

Interesting you put them in that order, I would have done the same : From the best option to the ... No I don't want to be negative about your or other Security Experts on other forums who try to help people with Malware infections, but in my opinion you can never be sure that a seriously compromised system will be 100% clean again. So should you offer that as a cure ?

Greetz, Red.
« Last Edit: October 06, 2008, 11:27:25 AM by Rednose » Logged

XP 32x SP3  CFP 2.4  SSM 2.0 Free  Avast! 4.8 Home  CBOClean 4.27  CMF 2.0  SAS 4.21 Free  MBAM 1.28
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5686



WWW
« Reply #8 on: October 06, 2008, 11:30:39 AM »

re-formatting is always an option Smiley

Melih
Logged

Rednose
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 1329


Ganda's sleepy ( in his wildest dreams )


« Reply #9 on: October 06, 2008, 11:42:56 AM »

Ofcource, Lol Smiley

But do your clients want to hear that Roll Eyes

Greetz, Red.
Logged

XP 32x SP3  CFP 2.4  SSM 2.0 Free  Avast! 4.8 Home  CBOClean 4.27  CMF 2.0  SAS 4.21 Free  MBAM 1.28
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5686



WWW
« Reply #10 on: October 06, 2008, 11:44:57 AM »

Ofcource, Lol Smiley

But do your clients want to hear that Roll Eyes

Greetz, Red.

Sometimes, when a system is truly hosed..noone can guarantee that they can clean all there is in that PC, cos they don't know all the malware, as noone knows 100% of the malware out there. So sometimes the best thing is to re-format. Painful as it maybe, but we care about security and if a bitter pill is what we have to take, then we have advise accordingly. False sense of security will never help anyone.

Melih
Logged

jeremysbost
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 218



WWW
« Reply #11 on: October 07, 2008, 07:44:38 PM »

Sometimes, when a system is truly hosed..noone can guarantee that they can clean all there is in that PC, cos they don't know all the malware, as noone knows 100% of the malware out there. So sometimes the best thing is to re-format. Painful as it maybe, but we care about security and if a bitter pill is what we have to take, then we have advise accordingly. False sense of security will never help anyone.

Melih

And besides cleaning your computer, reformatting lets you start fresh, without the software you don't need.

But what if you got a virus that acts like Diskshield, and when you reboot after a reformat it is all back again?  Huh
Logged

Jeremy Bost
Programing Beginner

Vista Home Premium; Dell Inspiron 1525; Dual-Core, 2GB Ram; 160 Hard Drive.

If you want to talk to me, use Windows Live/MSN messenger.
3xist
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2707



« Reply #12 on: October 07, 2008, 07:46:10 PM »

[quote author=jeremysbost link=topic=22635.msg204316#msg204316 date=1223426678
But what if you got a virus that acts like Diskshield, and when you reboot after a reformat it is all back again?  Huh
[/quote]

That would be some powerful malware/virus code right there!!  Shocked

Josh
Logged

Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.111 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com