Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 30, 2009, 08:03:39 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
346333
Posts
38274
Topics
86910
Members
Latest Member:
truthteller
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
General Category
Which Product do you want Comodo to develop next?
HIPS with centralised monitoring
« previous
next »
Pages:
1
[
2
]
Author
Topic: HIPS with centralised monitoring (Read 6273 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8376
Re: HIPS with centralised monitoring
«
Reply #15 on:
August 04, 2006, 11:36:51 AM »
Quote from: falkor on August 04, 2006, 05:41:32 AM
Melih . You kill me with all this good stuff . My goodness . I think I might just pull up a cot and never leave this forum . Best forum I have seen .
Well its a fun forum, filled with lots of fun people who love helping and building to protect others!
It certainly is great fun for me ;-)
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
AJohn
Computer Security Testing Group
Comodo Loves me
Offline
Posts: 170
Re: HIPS with centralised monitoring
«
Reply #16 on:
August 10, 2006, 12:28:11 AM »
Quote from: falkor on August 04, 2006, 05:41:32 AM
Melih . You kill me with all this good stuff . My goodness . I think I might just pull up a cot and never leave this forum . Best forum I have seen .
Well said
This is what happens when honestly good-hearted people get power...
Logged
sr386
Newbie
Offline
Posts: 16
Re: HIPS with centralised monitoring
«
Reply #17 on:
August 25, 2006, 05:53:25 PM »
I tried the PREVX bought and paid for have about 8 months left
but I removed it as it slows things down to a CRAWL...
Just trying to copy a few animated GIFs to a CD would take
3 times as long as w/out PREVX...
It's a strange program to me anyway, although the concept seems to be good
I just wasn't happy w/the serious slow down it brought to my machine.
Stephen/SR386
Logged
SR386/Stephen
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 1096
Re: HIPS with centralised monitoring
«
Reply #18 on:
August 26, 2006, 01:35:57 AM »
Quote from: panic on May 09, 2006, 03:48:38 PM
G'day,
What about a HIPS style program, but beyond just monitoring system vectors?
I'm looking at another one of these types of programs at the moment called PREVX1 (
www.prevx1.com
). Very nicely done but very noticeable impact on system performance. One interesting thing they do is unknown or potentially dangerous objects are automatically reported back to a central database for investigation.
Once investigated they are either classified as safe or unsafe. These classifications are then distributed back to other users of PREVX1. Sort of distributed collation - centralised distribution. This would have an advantage in that every application each users ran would be reported, logged, investigated, classifed and reincorporated. Nice way of picking up zero day defects. Huge load initially but long term benefits, if only in timeliness.
Thinking further, if this method was adopted and the HIPS-style application reported back each object for classification, updating within each application would be unnecessary, as the HIPS could send objects and receive and install incremental updates for the firewall, anti virus and the anti spyware.
This method could be leveraged into the anti virus and the future anti spyware.
what do you think?
ewen :-)
I've been using this for some time,both Prevx1 and it's former incarnation Prevx Home.The reason they switched to the community database model was that Prevx Home suffered the same problem as many other HIPS products,pop up fatigue.Even the most security conscious user would tend to just click yes after the 15th warning message (or shut the thing down altogether).
I find there are very few warning messages now since they operate a large whitelist,plus any unknown files are verified with the central database and I have to say this works extremely well.I gather CAVS will operate on a similar principle,if so it'll be a very useful tool for the armoury.
Logged
Mr Bips
Newbie
Offline
Posts: 6
Re: HIPS with centralised monitoring
«
Reply #19 on:
August 26, 2006, 02:45:42 PM »
Hello all.
Odd this in so far as I've just registered to pose a Catch22 type situation that has arisen recently whilst trying out such a HIPS program. I started using Sandboxie a while back and was impressed with it (despite it being a little, well; 'clunky' in the interface department) but migrated to GreenBorder Pro recently to try it out. I have to say that of the HIPS style progs I've tried recently, not be confused with the whole Sandbox/Virtualisation type apps which one can use to run/monitor apps without messing with yer box, and which clearly don't really warrant consideration given the subject at hand, this is the best I've found.
Essentially what most people need, and I suppose to a lesser degree, want, is a protective bubble when running Internet Explorer with 'all the doors open' ie; ActiveX, JavaScript, etc. (for the kids or whatever) and also at a push Outlook/Express, so that if anything (inevitably) creeps in, the cnotrolled environment will prevent any contamination of your Windows system. Greenborder excells in this area but unfortunately is (now) Shareware.
The reason I registered was because I then figures I'd try out GesWall as I wished to try and stick with the 'good stuff' ie; free if I could find something that would do the same thing. This performs the same task as GreenBorder Pro, but also provides 'templates' for all manner of additional applications such as P2P, Messenger apps, etc. etc. to also be protected in this fashion.
The issue I've noticed with using this particular app, which wasn't apparent when using GreenBorder Pro, was that upon every subsequent reboot/connect to the t'interweb, Comodo's App Protection would signify that IE had changed and asked me whether I wished to allow it, this I attribute to GesWall somehow affecting IE whilst it runs from within its environment.
Anyone know on this note whether there is any resolution for this short of disabling the Application Behaviour settings within Comodo, as it has for now forced me to migrate (once more) to running CyberHawk as an alternative as I'm not prepared to lower my defences from within Comodo in this respect.
Ta.
Logged
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 1096
Re: HIPS with centralised monitoring
«
Reply #20 on:
September 07, 2006, 09:14:32 AM »
Quote from: Melih on August 02, 2006, 12:54:47 PM
Thanks for the suggestion Falkor.
I have some interesting ideas that will help us have the biggest safelist in the world ;-) I just gave the go ahead to recruit another 25 people to our safelisting dept :-)
I think the idea we have will help us build the most comprehensive safelist in the world!
give me a month or two.. you will see what i mean and why Comodo can do it while others can't.
don't want to give too much away to our competitors at this stage. I want our competitors to "follow" our leadership after we launched the products not before ;-)
Melih
An approach you may consider taking is one similar to that used by Dynamic Security Agent.It uses behavioural monitoring based on normal resource usage of applications which are averaged over the learning period.It then looks for unusual deviations from the norm,unusually high cpu usage etc.
Logged
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 1096
Re: HIPS with centralised monitoring
«
Reply #21 on:
September 07, 2006, 09:16:52 AM »
I should explain,I'm meaning that in conjunction with the whitelist of approved applications.
Logged
solo
Comodo Loves me
Offline
Posts: 153
Re: HIPS with centralised monitoring
«
Reply #22 on:
September 29, 2006, 01:27:24 PM »
HIPS programs aren't simply for computer geeks! I am proof.
I don't know a lot about computers. Because I don't, I try to put the best security software on my computer and get good, sound advice from people that know more than me.
And let me tell you, HIPS doesn't have to be HARD. I am presently using a program called On-line Armor (by Tall Emu). This program is SO easy to use. It doesn't alert me with a ton of pop ups. It just does it's job quietly in the background.
On-line Armor is an ideal HIPS program in my opinion, designed for the computer novice like me im mind. If Comodo were to develop a HIPS program, I hope they would follow the same philosophy that Tall Emu did.
By the way, I mentioend that I try to use "best in class" products. Right now I use:
NOD32
On-line Armor
Comodo Firewall
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 7694
... and I say to myself, "What a wonderful world"
Re: HIPS with centralised monitoring
«
Reply #23 on:
September 30, 2006, 03:23:10 AM »
Quote from: Mr Bips on August 26, 2006, 02:45:42 PM
The issue I've noticed with using this particular app, which wasn't apparent when using GreenBorder Pro, was that upon every subsequent reboot/connect to the t'interweb, Comodo's App Protection would signify that IE had changed and asked me whether I wished to allow it, this I attribute to GesWall somehow affecting IE whilst it runs from within its environment.
Hey Mr. Bips,
This is EXACTLY why CPF is alerting you.
When an executable is run within a sandbox environment, its internal signature appears differently to the fireall. CPF is one of the few firewalls that is smart enough to spot that something has changed in an executable that you had previously OK'd.
As a consequence, it prompts you to alert you to the fact that IE has changed in some way. You'll find that any app you configure to run inside a sandbox-type environment will result in alerts from the smarter firewalls.
Hope this helps,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 1096
Re: HIPS with centralised monitoring
«
Reply #24 on:
October 04, 2006, 03:59:23 PM »
Quote from: panic on September 30, 2006, 03:23:10 AM
Hey Mr. Bips,
This is EXACTLY why CPF is alerting you.
When an executable is run within a sandbox environment, its internal signature appears differently to the fireall. CPF is one of the few firewalls that is smart enough to spot that something has changed in an executable that you had previously OK'd.
As a consequence, it prompts you to alert you to the fact that IE has changed in some way. You'll find that any app you configure to run inside a sandbox-type environment will result in alerts from the smarter firewalls.
Hope this helps,
Ewen :-)
You gotta just love how smart CPF is! (R)
Logged
Tags:
Pages:
1
[
2
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in -0 seconds with 17 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com