View Full Version : About Behaviour Blockers :)
jmonge
November 5th, 2009, 04:24 PM
hi,i have DefenseWall which is a policy base sandbox and i am having a hard time finding a good security supplement for DW;) i tried other aproaches like antivirus which only hog down my system,try Hips but ;D too much pop ups,i like clasical hips for the reaon that they are very imformative:thumb: but i dont like the pop ups at all;D now i heard good things about behaviour blockers:)
will it be a good complament/supplement for DefenSeWall?thanks
IceCube1010
November 5th, 2009, 04:37 PM
Once they have it fully implemented, Avast 5 and DW will give you great protection. Avast 5 doesn't slow any of my PC's down. Extremely light on cpu and memory.
Ice
jmonge
November 5th, 2009, 04:43 PM
-{ Quote: "Once they have it fully implemented, Avast 5 and DW will give you great protection. Avast 5 doesn't slow any of my PC's down. Extremely light on cpu and memory.
Ice" }-cool:thumb: is it going to be free?and does it fully protects againts spywares?thanks
IceCube1010
November 5th, 2009, 04:49 PM
-{ Quote: "cool:thumb: is it going to be free?and does it fully protects againts spywares?thanks" }-
Yes, they have a freeware version which runs great. The paidware will include a firewall and spamware module. The updating of definitions is a bit different but you really don't need that stuff since you have DW. Avast 5 would be a good compliment.
Ice
Kees1958
November 5th, 2009, 04:49 PM
I am running Avast 5 beta with DWv3 beta, only in LUA under XP Pro
I only run the file and behavior blocker (the last is empty by the way until final release)
When you configure Avast file shield to check only at execution and write, it is fast, also has a nice feature to remember safe applications (not check them, both transient and persistent caching (enebaled by default).
See image of this post how effective the cache is http://www.wilderssecurity.com/showpost.php?p=1567752&postcount=211
The disk I/O of Avast is also remarkably low (often the slowest part in modern PC's now)
Regards Kees
jmonge
November 5th, 2009, 04:51 PM
-{ Quote: "I am running Avast 5 beta with DWv3 beta, only in LUA under XP Pro
I only run the file and behavior blocker (the last is empty by the way until final release)
When you configure Avast file shield to check only at execution and write, it is fast, also has a nice feature to remember safe applications (not check them, both transient and persistent caching (enebaled by default).
See image of this post how effective the cache is http://www.wilderssecurity.com/showpost.php?p=1567752&postcount=211
Regards Kees" }-that is the beta v5?
jmonge
November 5th, 2009, 04:51 PM
-{ Quote: "Yes, they have a freeware version which runs great. The paidware will include a firewall and spamware module. The updating of definitions is a bit different but you really don't need that stuff since you have DW. Avast 5 would be a good compliment.
Ice" }-
free;) like it
Kees1958
November 5th, 2009, 04:52 PM
-{ Quote: "that is the beta v5?" }-
Si monsieur Avast beta 5, c'est la meme que beta v5 ;D
jmonge
November 5th, 2009, 04:54 PM
-{ Quote: "Si monsieur Avast beta 5, c'est la meme que beta v5 ;D" }-
got it:thumb: cool;D
Creer
November 5th, 2009, 04:55 PM
-{ Quote: "(...)
now i heard good things about behaviour blockers:)
will it be a good complament/supplement for DefenSeWall?thanks" }-
Not really Jmonge, there is one simple reason why - BB mostly based-on blacklists like AV software you still need to download signatures from BB vendors... also BB are very susceptible on FP.
Ed_H
November 5th, 2009, 04:55 PM
I would offer 2 suggestions:
A2 Antimalware, which includes Mamutu behavior blocker will be free for 1 year on November 11. I have used this in the past and it gets along fine with DW. You can disable any of the protection features you don't want or need so it very flexible in that regard.
Online Armor free version works well with DW and once OA learns what is on your PC, which is a pretty quick process, you will rarely see a popup. I never see popups unless I am installing something new.
jmonge
November 5th, 2009, 04:57 PM
-{ Quote: "I would offer 2 suggestions:
A2 Antimalware, which includes Mamutu behavior blocker will be free for 1 year on November 11. I have used this in the past and it gets along fine with DW. You can disable any of the protection features you don't want or need so it very flexible in that regard.
Online Armor free version works well with DW and once OA learns what is on your PC, which is a pretty quick process, you will rarely see a popup. I never see popups unless I am installing something new." }-hey i forgot about this promotion for the 11 of november:thumb:
jmonge
November 5th, 2009, 04:59 PM
-{ Quote: "I would offer 2 suggestions:
A2 Antimalware, which includes Mamutu behavior blocker will be free for 1 year on November 11. I have used this in the past and it gets along fine with DW. You can disable any of the protection features you don't want or need so it very flexible in that regard.
Online Armor free version works well with DW and once OA learns what is on your PC, which is a pretty quick process, you will rarely see a popup. I never see popups unless I am installing something new." }-i have a free giveaway licence for Online armor;D
Kees1958
November 5th, 2009, 05:01 PM
Good old ThreatFire is a good pure Behavioral blocker.
Point is why waist CPU cycles on another security application when you have DWv3 on board.
Only reason I have is: to prevent forwarding e-mails with maleare and occasional fun stuff which is downloaded and which links are sent to friends.
So a behavioral blocker constantly monitors everything (like a HIPS). Mamutu uses surprisingly little CPU time and disk I/O. Threat Fire uses little disk I/O and a little more CPU time (although latest 4.6 is much improved, in the past Mamutu was a lot more CPU efficient than TF).
Regards
jmonge
November 5th, 2009, 05:07 PM
-{ Quote: "Good old ThreatFire is a good pure Behavioral blocker.
Point is why waist CPU cycles on another security application when you have DWv3 on board.
Only reason I have is: to prevent forwarding e-mails with maleare and occasional fun stuff which is downloaded and which links are sent to friends.
So a behavioral blocker constantly monitors everything (like a HIPS). Mamutu uses surprisingly little CPU time and disk I/O. Threat Fire uses little disk I/O and a little more CPU time (although latest 4.6 is much improved, in the past Mamutu was a lot more CPU efficient than TF).
Regards" }-i know but to add alitle extra blanket to protect againts the flue is a warm good feeling;D
Creer
November 5th, 2009, 05:14 PM
-{ Quote: "i know but to add alitle extra blanket to protect againts the flue is a warm good feeling;D" }-
Yeah but don't forget that it can be placebo :D
jmonge
November 5th, 2009, 05:16 PM
-{ Quote: "Yeah but don't forget that it can be placebo :D" }-i know:)
by the way this DW FireWall is very cool.i tested and it is very good;)
jmonge
November 5th, 2009, 05:18 PM
ok fellows DW is a policy base sandbox,do you thing that by adding a behaviour blocker will add extra-peace of mind?
Hugger
November 5th, 2009, 05:18 PM
I guess part of the answer depends on what OS you're using.
I've use the combination of DW and Prevx with no slowdown at all.
Enjoy.
Hugger
jmonge
November 5th, 2009, 05:20 PM
-{ Quote: "I guess part of the answer depends on what OS you're using.
I've use the combination of DW and Prevx with no slowdown at all.
Enjoy.
Hugger" }-i have DefenSeWall and MalWareBytes but i am thinking of adding a behaviour blocker,but if i dont need it i will not use it;D please advise
Hugger
November 5th, 2009, 05:28 PM
-{ Quote: "i have DefenSeWall and MalWareBytes but i am thinking of adding a behaviour blocker,but if i dont need it i will not use it;D please advise" }-
I'm not as knowledgeable as the rest of you but as far as I know I haven't had anything get past my signature.
Other than DW and Prevx, everything else is on demand.
You could also throw Hitman Pro in there for an occasional scan for for &^%^$ and giggles.
Hugger
jmonge
November 5th, 2009, 05:37 PM
Hugger i know that DefenseWall is hard to be bypassed but i still have some space for another security application ;D i was thinking of a behabiour blocker but not sure if i really need it,i tried couple of hips but the only disadvantage of too many pop up alerts;D
Hugger
November 5th, 2009, 05:47 PM
You need to go with what will give you peace of mind. Anything else and you will continue down the well traveled road to insanity brought on by security anxiety.
Good luck.
Hugger
jmonge
November 5th, 2009, 05:55 PM
-{ Quote: "You need to go with what will give you peace of mind. Anything else and you will continue down the well traveled road to insanity brought on by security anxiety.
Good luck.
Hugger" }-DefenseWall gives peace of mind;) ;D
jmonge
November 6th, 2009, 03:48 PM
ok i tried ThreatFire and my system was slowed down,so it was not a good experience then disable malwarebytes for a while and it was ok:) then i remember i have a Online armor premium licence some where and decided to try it and it when very smooth:thumb: will i benefits from a pure hips rather than having a behaviour blocker?thanks any advises
jmonge
November 6th, 2009, 03:49 PM
online armor looks faster now:thumb:
Kees1958
November 7th, 2009, 06:06 AM
Jmonge,
When you want to have a second security feature, try SURUN (your on XP right?). This will give you an UAC like prompt when something tries to install.
You will DWv3 beta as HIPS/FW for untrusted aps and untrusted/downloaded/emailed documents: in short highest alert level without the pop-ups guarding your threat gates
Surun when something tries to install, system wide
regards Kees
jmonge
November 7th, 2009, 10:12 AM
-{ Quote: "Jmonge,
When you want to have a second security feature, try SURUN (your on XP right?). This will give you an UAC like prompt when something tries to install.
You will DWv3 beta as HIPS/FW for untrusted aps and untrusted/downloaded/emailed documents: in short highest alert level without the pop-ups guarding your threat gates
Surun when something tries to install, system wide
regards Kees" }-thanks kees:thumb: do you have the link to take a look?and it this surun same as pgs?
Kees1958
November 8th, 2009, 04:23 AM
No PGS is somewhere between SRP and Applocker when looking at its options
Surun is an UAC type of application (like Vista UAC plus Norton UAC tool).
Thanks to Mrkvonic SEE http://www.dedoimedo.com/computers/surun.html
jmonge
November 8th, 2009, 10:07 AM
-{ Quote: "No PGS is somewhere between SRP and Applocker when looking at its options
Surun is an UAC type of application (like Vista UAC plus Norton UAC tool).
Thanks to Mrkvonic SEE http://www.dedoimedo.com/computers/surun.html" }-ah i see,thanks
Triple Helix
November 9th, 2009, 11:30 PM
Prevx 3.0 in free mode!
TH
clocks
November 10th, 2009, 08:18 AM
-{ Quote: "Prevx 3.0 in free mode!
TH" }-
Problem is in free mode it doesn't block anything, just alerts you if you get infected.
Triple Helix
November 10th, 2009, 03:32 PM
-{ Quote: "Problem is in free mode it doesn't block anything, just alerts you if you get infected." }-
Well then a least you know there are infected files on-board and in that case if you want to purchase Prevx!
TH
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums