Welcome, Guest. Please login or register.
November 19, 2008, 06:00:41 AM

Login with username, password and session length

212407 Posts
24553 Topics
57741 Members

Latest Member: Citywolf100

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  General Category
| |-+  Which Product do you want Comodo to develop next?
| | |-+  A behav blocker like ThreatFire
« previous next »
Pages: [1] Go Down Print
Author Topic: A behav blocker like ThreatFire  (Read 1029 times)
aigle
Comodo's Hero
*****
Offline Offline

Posts: 344



« on: August 18, 2008, 05:30:46 PM »

It can be made a stand alone software or somehow integrated in CFP. There are only two standalone behav blockers so far as I Know:

ThreatFire
Promary Response SAfe Connect( Norton Antibot)

Such type of behav blocker will be great for people who don,t want to use a classical HIPS like DfencePlus.

Thanks
Logged
Rhaegar
Comodo Member
**
Offline Offline

Posts: 46


« Reply #1 on: August 18, 2008, 09:49:47 PM »

     I think this is a great idea!  Something with the power of D+ but with the ease of use of ThreatFire!


Rhaegar
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2773


Why not ? The choice is yours !


« Reply #2 on: August 19, 2008, 03:39:59 AM »

Errr... just for info... Defense+ is such thing....

But to the more comprehensive part, we have suggested some redisignes here http://forums.comodo.com/feedbackcommentsannouncementsnews/redesign_of_cfp_alerts-t21345.0.html I sujest you take a look at it ...

Xan
Logged

OK, we'll see each other outside  Angry. But err... different countries ?

 Vista Ultimate 64bit SP1  l  Comodo Internet Security  l  Comodo BoClean
Rhaegar
Comodo Member
**
Offline Offline

Posts: 46


« Reply #3 on: August 20, 2008, 10:15:23 AM »

Xan,

     Yes, I am aware that D+ is a HIPS but its more on the classic model (or at least that how others see it).  Threatfire is also a HIPS, and I don't really know how D+ differs from Threatfire under the hood, but I do know that they behave differently.  On the surface, it seems that D+ is more talkative and dependent on user interaction while Threatfire minimizes it and SEEMS more intelligent.  In my opinion, both tools are very useful and powerful although it seems easier to use Threatfire. 

     Don't get me wrong, I like D+ the way it is right now, it IS powerful, but it is also dependent on user input.  What I'm saying is it would be nice if Comodo also had another option to D+ that is more user friendly than the way D+ is now.  Like another mode for D+ that kinda emulates what Threatfire does.  Well, just a thought.  Anyway, I'll be checking the thread you pointed out.  Thanks!

Rhaegar
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2773


Why not ? The choice is yours !


« Reply #4 on: August 20, 2008, 01:46:03 PM »

Comodo is going through many enhancements to get as less pop-ups possible. I think you must have noticed the difference between the first V3 beta and now...
As everyday many files are send to Comodo, the whitelist database keeps growing and growing, also there adding even more 'smarties' to get less pop-ups. I'm sure that within a year Comodo will be the greatest and most quite...

Well see how it develops, only time can tell, but I have great fate in Comodo Developers, as you can see the enhancements and development they made  Cheesy

Xan
Logged

OK, we'll see each other outside  Angry. But err... different countries ?

 Vista Ultimate 64bit SP1  l  Comodo Internet Security  l  Comodo BoClean
3xist
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3348



« Reply #5 on: August 22, 2008, 12:56:53 AM »

Xan,

     Yes, I am aware that D+ is a HIPS but its more on the classic model (or at least that how others see it).  Threatfire is also a HIPS, and I don't really know how D+ differs from Threatfire under the hood, but I do know that they behave differently.  On the surface, it seems that D+ is more talkative and dependent on user interaction while Threatfire minimizes it and SEEMS more intelligent.  In my opinion, both tools are very useful and powerful although it seems easier to use Threatfire. 

     Don't get me wrong, I like D+ the way it is right now, it IS powerful, but it is also dependent on user input.  What I'm saying is it would be nice if Comodo also had another option to D+ that is more user friendly than the way D+ is now.  Like another mode for D+ that kinda emulates what Threatfire does.  Well, just a thought.  Anyway, I'll be checking the thread you pointed out.  Thanks!

Rhaegar

Hi Rhaegar,

First of all, Defense+ is NOT "Classic" HIPS.

Hi,

Renaming and replacing a file:
Default policy allows such operations. SFI automatically protects explorer.exe in this case. Well, policies are the part of CFP intelligence ofcourse. However one of the points here is, we are able to create and distribute such default policies with CFP because CFP can live with such a default policy.
Can other classical hips solutions make sure that explorer.exe can not be used by other applications to bypass the policy?
For example, do they provide means to protect COM interfaces that could be used to manipulate explorer.exe?
Do they provide means to protect knowndlls both in MEMORY and on DISK, to prevent injection into explorer.exe?  I can list a couple of more threats.

Believe me when I say, developing a classical HIPS, is one of the easiest tasks. An above-average developer can develop a simple classical HIPS in 2 weeks. Surf the internet and you will even find open source versions.

If you look at CFP, even its heuristics can catch 60-70% of unknown viruses BEFORE you execute them. It is not a 2 week classical hips. So when we say something in public, we dont just say it. We mean it. We genuinely try to protect the users. Not trying to sell them our software by marketing stuff...

Also in 2-3 months, we will introduce some new technologies into our Defense+ and make it Defense++++. I think comparing with the others will then be quite irrelevant.

Egemen

That was from the lead developer. After COMODO Internet Security (CIS) is launched, the other technologies that will be put into CFP 3 will be Threatcast & Sandbox, Where Threatcast gives advice based on users responses to alerts, and Sandbox where files get passed through the sandbox producing ZERO alerts, etc. So it will be the most powerful, yet quietest, "HIPS" if you like on the market!

Off course other technologies is to come, and the infrastructure to build such unique technology is in progress!

Wait and see... Smiley

Josh
Logged

Comodo Moderator: Maintains order at the forum and makes sure the policy is followed.
My System Details: Windows XP 32bit SP3, CIS 3.5.
Specialty: Malware Removal & Remote Helper.
Rhaegar
Comodo Member
**
Offline Offline

Posts: 46


« Reply #6 on: August 23, 2008, 08:10:29 PM »

     Good to know!  As always, I eagerly await what COMODO has up it's sleeve for us.

Rhaegar
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2773


Why not ? The choice is yours !


« Reply #7 on: August 24, 2008, 03:40:00 AM »

Just an update that Melih posted elsewere

Quote
I like this vote as it educates people to the new concept of how current AVs work and the 21st alternative to this 20th century technology!

This thread is not about use this and not the other one but a way of educating imo and a good one to get the grey cells thinking about our security.

You know what I think... your name is not in the list, you are not coming in!!! And yes, we will make this more user friendly so that users' simply install and forget (and let this app which has whitelisting as its first line of defense) this app. I will predict that we will have this app in 2009! 

Melih
Source


Xan
Logged

OK, we'll see each other outside  Angry. But err... different countries ?

 Vista Ultimate 64bit SP1  l  Comodo Internet Security  l  Comodo BoClean
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.163 seconds with 18 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com