CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Process termination

 
Post new topic   Reply to topic       All -> FavForums -> Prevx [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
WhirledTurn

Trooper
Trooper


Joined: May 24, 2007
Posts: 27


PostPosted: Thu Jun 14, 2007 10:49 pm    Post subject: Process termination
Reply with quote

Does Prevx2 feature process termination protection?

I note from reading a HIPS Comparison here on CC ( http://wiki.castlecops.com/HIPS/IDP_programs/services ) that Prevx1 did not.

Thank you.

Back to top
View users profile Send private message
WhirledTurn

Trooper
Trooper


Joined: May 24, 2007
Posts: 27


PostPosted: Fri Jun 15, 2007 9:50 pm    Post subject:
Reply with quote

My question really is twofold.

Does Prevx2 protect not only itself, but other processes from termination?

I read that OA has this capability, and I'd like to find a program that will protect others as well as itself.

Any Prevx2 users know?

Back to top
View users profile Send private message
ghiser1

Prevx Host
Premium Member

Joined: Jan 07, 2005
Posts: 315
Location: UK
Premium

PostPosted: Fri Jun 15, 2007 10:35 pm    Post subject:
Reply with quote

It has the potential to, with respect to its protection framework, but we haven't yet released the security setting to do it - but it is an area I'm actively progressing. Initially, it would be for expert mode only.

The setting is there today but its in report-only mode.

Darren

Back to top
View users profile Send private message
WhirledTurn

Trooper
Trooper


Joined: May 24, 2007
Posts: 27


PostPosted: Sat Jun 16, 2007 6:32 pm    Post subject:
Reply with quote

So at this time Prevx2 can be turned off in Task Manager?
And Prevx2 does not protect other processes from termination?
Just trying to make sure I understand.

Back to top
View users profile Send private message
ghiser1

Prevx Host
Premium Member

Joined: Jan 07, 2005
Posts: 315
Location: UK
Premium

PostPosted: Sun Jun 17, 2007 10:55 am    Post subject:
Reply with quote

WhirledTurn wrote:
So at this time Prevx2 can be turned off in Task Manager?

No, it protects itself from termination.
WhirledTurn wrote:

And Prevx2 does not protect other processes from termination?

Correct, it does not prevent the termination, but it does take note of it and report the behaviour to the Prevx Community Watch Controller. If the process doing the termination is seen terminating certain types of applications, like AV products, but not normal programs - that is its not a generic process termination tool, but a targeted attack against AV products - it is likely that it will be determined as Bad by the community watch controller.

Once this happens, attempts to run that process on any other system that has Prevx 2.0 installed will cause that execution attempt to be blocked.

So, in terms of traditional HIPS functionality, it doesn't prevent the termination of non-Prevx processes. However, it terms of CIPS (Community Intrusion Prevention System) functionality, it prevents the termination of non-Prevx processes by preventing the process that would terminate them from running in the first place.

This is the reason why we call Prevx a CIPS product not a HIPS product. Yes, in expert-mode its a partial HIPS, but its not designed as a true HIPS products. Sometimes, it is benificial to the community to allow certain behaviours to proceed on a few systems in order to determine whether they are truly malicious; to protect the community as a whole.

It's critical to realize that you cannot provide Information Security without Security Information! Intelligence is key in any battle and in the battle against malware it is critical. Unfortunately, this means that the needs of the many (the Prevx community) outway the needs of the one (an individual agent) and in all battles sacrifices have to be made.

Of course, in the Prevx case, that sacrificed agent will be corrected and cleaned as soon as the the malicious program is determined as Bad, so its only a temporary sacrifice.

Compare this to traditional AV, where all users are sacrificed until a signature can be developed and distributed to them - and this can sometimes take weeks.

Hope that helps put things into perspective for you.

Regards,

Darren



Last edited by ghiser1 on Sun Jun 17, 2007 7:25 pm, edited 1 time in total
Back to top
View users profile Send private message
WhirledTurn

Trooper
Trooper


Joined: May 24, 2007
Posts: 27


PostPosted: Sun Jun 17, 2007 2:33 pm    Post subject:
Reply with quote

ghiser1 wrote:
Hope that helps put things into perspective for you.

Very enlightening. Thank you for the detailed explanation.

Back to top
View users profile Send private message
ErikAlbert
Warnings : 3

Captain
Captain


Joined: Jan 20, 2005
Posts: 424


PostPosted: Tue Jun 26, 2007 1:40 pm    Post subject:
Reply with quote

Interesting i admit i have not being watching Prevx2 as much, due to various reasons.

I will update the table for Prevx2 soon.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Prevx All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer