PDA

View Full Version : An integrity checker ?


IcePanther
August 9th, 2006, 06:40 AM
Hi,

As you can read in my signature, I use Nod32 as an antivirus, Outpost Pro as a firewall and SSM free edition as an HIPS.

I think I'm quite protected, since Firefox has NoScript! and CookieSafe. But, the only layer of protection I miss is an integrity checker.
Indeed SSM checks the MD5 hash of the authorized applications and asks if modified to create a new rule. BUT, it doesn't do the same for the modules loaded by an app (no control of what new/modified modules are loaded.) Outpost has this function : it controls what new/modified DLL's are loaded, but ONLY by programs that use the internet.

What I'm searching for is a program that can do the same function as the integrity control in Outpost, but with all applications. My questions would be :

It is useful to add this protection layer, given what I'm currently using ?
Does such a piece of software exist, and if so, does it have an impact on system resources usage ?Thank you for your answers,

Baldrick
August 9th, 2006, 05:31 PM
Hi there

You could check out Sentinel 2:

Advanced file integrity checker that integrates seamlessly with your anti-virus/trojan application(s).

Scan on Startup or use the Secure Shut Down feature to stop potential threats before they strike!

FREEWARE - NO SPYWARE - NO ADWARE

I use it regularly as an extra level and it works really well, but you need to run it as a seperate option which may not be what you are looking for. The only other thing is that I have not seen any reviews about it so I do not know how well it is rated by the security community. You can find out about it at/download it from the followng site:

http://www.runtimeware.com/sentinel.html

Enjoy;D

G1111
August 9th, 2006, 10:17 PM
Also see:

http://kareldjag.over-blog.com/article-1482539.html

IcePanther
August 10th, 2006, 01:20 PM
Thanks for the links Baldrick and G1111

Sentinel is not what I'm searching for, because it doesn't check for integrity on-access but only on-demand. What I'm after is a real time monitor. Some products reviewed in G1111 link seemed to have it, but in fact, it's only sheduled scans and so on, and/or the products are really expensive.

Plus, I don't want to scan my entire hard drive, only the DLL's loaded by an application at the time it loads them, like Outpost's module or KIS 6's application integrity control module.

Anyway, thanks for the info ^^