Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 23, 2013, 07:27:37 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663838
Posts
70590
Topics
145232
Members
Latest Member:
Golan
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
CFP will need new self defense protection modules
« previous
next »
Pages:
[
1
]
Author
Topic: CFP will need new self defense protection modules (Read 4377 times)
samtsam
Newbie
Offline
Posts: 20
CFP will need new self defense protection modules
«
on:
February 02, 2010, 03:36:00 PM »
Matousec has released new tests for proactive security challenge including autorun, file and registry tests. At this moment, CFP's D+ system will need introducing new features for protect its functionality.
«
Last Edit: February 02, 2010, 03:39:14 PM by samtsam
»
Logged
EricJH
Global Moderator
Comodo's Hero
Online
Posts: 16711
Re: CFP will need new self defense protection modules
«
Reply #1 on:
February 02, 2010, 04:52:31 PM »
You already know what is going to be tested? You know anything we don't know? I am listening......
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
soyabeaner
Guest
Re: CFP will need new self defense protection modules
«
Reply #2 on:
February 02, 2010, 05:54:36 PM »
He means this:
http://www.matousec.com/info/?news=134-Another_Proactive_Security_Challenge_milestone__ndash__it_now_contains_148_tests
I don't think there's a need to mention this, as I'm sure Comodo and other vendors (like in the past) are periodically contacted by Matousec about his updates well before he publishes his articles.
Although this does paint a clearer picture of his true intentions.
Quote from:
http://www.matousec.com/matousec/about-us.php
The main goal of
matousec.com
is
to improve security of end-users
with its own security related projects and research.
I think it's obvious that if that was the main goal, he wouldn't have waited until a few vendors have achieved a 100% perfect score on those leak-tests. If it really was about end-users, he should have continually researched and release new attack POC's. It's always business before justice
«
Last Edit: February 02, 2010, 06:11:35 PM by Soyabeaner | Mr. Bean
»
Logged
ailef
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 832
Re: CFP will need new self defense protection modules
«
Reply #3 on:
February 05, 2010, 09:55:04 PM »
the good new is the OS tested now : they'll use windows 7 64bit.
i looked at the comodo version tested, it was the 3.12 build 560.
i hope they're ready for some tests so we will see if the last comodo build fixed many problems or if the new tests will hurt our favorite FW. and what is cool is the use of win7 64bit, we will see how comodo works under 64bit system. is it able to run as fine as the 32bit version as it has to deal with the guardian kernel...
Logged
Windows 7 ultimate 64-bit SP1 - Comodo Firewall & Defense+ 5.10.228257.2253 - Antivirus ? It's unable to bring any serious protection so I gave up with AVs.
SiberLynx
Comodo's Hero
Offline
Posts: 2159
Re: CFP will need new self defense protection modules
«
Reply #4 on:
February 05, 2010, 10:27:18 PM »
Hi Guys,
All those tests regarding
the Firewall
whether it's 32bit or X64 with the Patch Guard present should be carried out
without any presence
of the Defense+
If you can show whether that specific point is a part of methodology - that would be helpful.
Sure, we are interested in "the last comodo" version being tested, but that has to be Firewall
only
. The same applies to any other Firewalls participating in any test
Testing any Firewall should not contain additional layer(s) of protection
The Defense+ conceptually does not belong to the Firewall
The Firewall has to be strong and not leaking irrespectively - no HIPS (and users' decisions) - that would be a subjective and correct testing
What do you think?
Cheers!
Logged
admin; XP Pro, SP3 (32bit); CIS 3.14.130099.587 (firewall only; Proactive with Defense+)- that is the only Comodo's thing I need; Emsisoft - Mamutu Behavioural Blocker or Full EAM
Win 7 x64: Comodo Firewall 3.14; Emsisoft Anti-Malware
ailef
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 832
Re: CFP will need new self defense protection modules
«
Reply #5 on:
February 05, 2010, 11:43:10 PM »
Defense+ is useless on win 64 ?
the guardian kernel is able to give the same level of protection as Defense+ can ?
the guardian kernel never informs me about what's happening on my win7 64, i cant create my own rules, it's like running totally blind in the street, i have no infos, it doesnt help to understand how the system works.
so finally, is Defense+ useless on win7 64 or not ?
Logged
Windows 7 ultimate 64-bit SP1 - Comodo Firewall & Defense+ 5.10.228257.2253 - Antivirus ? It's unable to bring any serious protection so I gave up with AVs.
SiberLynx
Comodo's Hero
Offline
Posts: 2159
Re: CFP will need new self defense protection modules
«
Reply #6 on:
February 05, 2010, 11:55:07 PM »
Quote from: ailef on February 05, 2010, 11:43:10 PM
Defense+ is useless on win 64 ?
the guardian kernel is able to give the same level of protection as Defense+ can ?
the guardian kernel never informs me about what's happening on my win7 64, i cant create my own rules, it's like running totally blind in the street, i have no infos, it doesnt help to understand how the system works.
so finally, is Defense+ useless on win7 64 or not ?
Hi ailef ,
I didn't get your message clear.
The Defense+ seems to be working the same way currently on win7 x64 as it is working on XP 3bit.
It is just more talkative regarding the service.exe and I encountered the loss of previously set policy for just a few Applications (say 7z) after few days of work but not much more.
I have to admit that I am not using win7 x64 constantly though, but when I was setting up stuff after installing Comodo Firewal & the Defense+ there - all necessary alerts were fired up for all Applications (sure there were pure Firewall Aalerts too)
So what do you mean by "the guardian kernel never informs me about what's happening"? and what is the connection with Defense+?
Cheers!
«
Last Edit: February 05, 2010, 11:58:24 PM by SiberLynx
»
Logged
admin; XP Pro, SP3 (32bit); CIS 3.14.130099.587 (firewall only; Proactive with Defense+)- that is the only Comodo's thing I need; Emsisoft - Mamutu Behavioural Blocker or Full EAM
Win 7 x64: Comodo Firewall 3.14; Emsisoft Anti-Malware
ailef
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 832
Re: CFP will need new self defense protection modules
«
Reply #7 on:
February 06, 2010, 12:57:13 AM »
probably i understood bad your message, i'm not native english.
about the guardian kernel and Defense+ on 64bit system, can the guardian kernel completely replace Defense+ and give the same level of protection ?
i mean that guardian kernel works the same as defense+ or not on 64bit ?
that's why i would like to know if Defense+ is usefull on 64bit or it's not necessary as the guardian kernel is able to protect the 64bit system like Defense+ does ?
what's your opinion about 64 bit systems, the guardian kernel can do the job of Defense+ ?
i maybe understood bad as i thought u were telling that there's no need for Defense+ in 64bit cause of the guardian kernel able to protect the system the same way as Defense+ ?
so i would like some clarifications on this point for 64bit OS, do we need defense+ or guardian kernel can protect the system without the need to use Defense+ ?
Logged
Windows 7 ultimate 64-bit SP1 - Comodo Firewall & Defense+ 5.10.228257.2253 - Antivirus ? It's unable to bring any serious protection so I gave up with AVs.
SiberLynx
Comodo's Hero
Offline
Posts: 2159
Re: CFP will need new self defense protection modules
«
Reply #8 on:
February 06, 2010, 02:02:07 AM »
Hi ailef
The language is not a problem. English is not my 1st language too. If people want they can understand each other.
==============
The
PatchGuard
or
Kernel Patch Protection (KPP)
has nothing to do with Defense+ or any HIPS / and other ways to monitor & secure the system.
This is the feature of x64 editions of Microsoft Windows that
prevents patching the kernel
.
Patching the kernel used by many security Software to prevent attacks.
At the same time malicious Software often is using the same method as well.
E.g: a dynamically generated hidden driver
mchinjDrv.sys
- Mad Code Hook Injection Driver - used by security and used by malware.
Basically in x86 (32bit) both “good & bad guys” were able to patch
openly and easily
Antiviruses; Anti-malware / Behavioral blockers are using kernel patching on 32 bit systems
As an example the SandBoxing in 32 bit is pretty much strong because of that.
On x64 MS is protecting the kernel patching and that technology by their PatchGuard
So neither “good” nor “bad guys” can do that.
Therefore creating security for x64 by any 3rd party vendors now is different and basically patching the kernel cannot be used by them
That is why, say the development of SandBoxie for x64 was initially dropped by the creator, but lately he just made a compromised variant and clearly stating that it is much vulnerable compare to “32bit brother”. By his estimation more than 10% (which is huge number ) of malware definitely cannot caught and the system cannot be protected by SandBoxing x64. There are other cases when the processed can escape and be invoked outside the sandbox
Interestingly enough when writing the malicious software you still can circumvent that protection by the PatchGuard but it makes it just much more difficult and the malware creators have to be quite proficient.
That is mainly about the PatchGuard in brief, but that has nothing to do with the idea of having security and its own features including Defense+ (HIPS) or others
Those just has to be implemented differently having in mind all implications, pluses and minuses of such system defense feature (or preventing measure) as MS PatchGuard.
My regards
«
Last Edit: February 06, 2010, 05:09:03 AM by SiberLynx
»
Logged
admin; XP Pro, SP3 (32bit); CIS 3.14.130099.587 (firewall only; Proactive with Defense+)- that is the only Comodo's thing I need; Emsisoft - Mamutu Behavioural Blocker or Full EAM
Win 7 x64: Comodo Firewall 3.14; Emsisoft Anti-Malware
ailef
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 832
Re: CFP will need new self defense protection modules
«
Reply #9 on:
February 06, 2010, 11:56:02 AM »
ok thanks, so the guardian kernel doesnt allow any modification of a microsoft file by any file that is not signed by microsoft too. so it keeps the system files safe.
but defense+ has others features than just only block any access to system files by patching them or add it some unknown dll, etc.
I understood first that guardian kernel would be able to replace Defense+ if it was good.
ok, so there's no prob on 64bit OS and Defense+, the tool is monitoring all we want it to, as guardian kernel is just the guardian of the system and block anything that tries to modify anything that is detected as a potential danger that would break the kernel security.
but Defense+ works as good on 32bit than 64 bit ? or does this guardian kernel have effects so Defense+ is a little less secure on 64bit ?
Logged
Windows 7 ultimate 64-bit SP1 - Comodo Firewall & Defense+ 5.10.228257.2253 - Antivirus ? It's unable to bring any serious protection so I gave up with AVs.
Tags:
on: February 02
2009
02:34:05 PM
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.054 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com