Introducing, The New Prevx Edge.

Discussion in 'Prevx Releases' started by trjam, Nov 13, 2008.

Thread Status:
Not open for further replies.
  1. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    yep, took it off for 3 days, mainly to try a new HIPS. Did not take me long to realize how much I missed it and how well it worked. I may never fully understand HIPS products, but I do understand Edge.;) :thumb:
     
  2. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Hello,
    Over the last few months we have made significant improvements to CSI but have not changed the shortcuts during an update because that tends to annoy users (restoring, changing possibly deleted shortcuts). You don't have to do anything with CSI (it automatically scans, etc.) but you can now do things with CSI if you want as we've added a number of new features.

    I've PM'd you a link to an update for Edge. If you could install this, I believe it will correct your problems. We will be releasing it as an update shortly.
     
  3. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    You hit the nail on the head :) That is precisely how it works - except we don't only watch samples when you are the first person to encounter a threat, we watch them and build information on the file across thousands of users as many threats appear differently to different users (different configurations, different IP addresses, etc.) and we do not use community voting at all like some of the other vendors do.

    Until a program is completely determined as "good", Edge monitors and learns about hundreds of unique program behaviors to attempt to build the clearest picture of a threat possible. If a file is really "borderline", it may be submitted into our server-side sandboxing system where we can tear it apart piece by piece. If it still can't be decided upon quickly, one of our researchers will get notified and will analyze it manually and write heuristic rules to teach the DB how to block similar threats in the future (however, in most cases, malware is blocked before it even needs to get through any of these processes).

    Threat identification is generally immediate, however, sometimes it may take a few minutes and during that time, Edge will continue to monitor and track what the program is doing, so, if it does turn out to be bad, Edge will be able to remove any malicious registry entries associated with the file and close down any other pieces of malware associated with it.

    Hope that helps! :)
     
  4. Saraceno

    Saraceno Registered Member

    Joined:
    Mar 24, 2008
    Posts:
    2,405
    Just an update, running extremely well alongside Avast!, sandboxie and Shadow Defender (on demand).

    The first few days or so, many applications were being 'analysed' for a few seconds before startup, but now it seems everything (all applications and web browsing) loads and responds as if the program wasn't even loaded in the first place.

    :)
     
  5. Hunter42

    Hunter42 Registered Member

    Joined:
    Nov 19, 2008
    Posts:
    7
    My two cents:

    Running KIS 2009, PrevX Edge and Malware Defender 1.2.1 (Overkill ?! :rolleyes: ).

    Works fine here...


    H
     
  6. n8chavez

    n8chavez Registered Member

    Joined:
    Jul 19, 2003
    Posts:
    3,355
    Location:
    Location Unknown

    Um, yeah. That's a bit much.
     
  7. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857

    Great thx, just an additional question (and I hope you say ney, otherwise Edge really has to much of an edge over the top of breed competition)

    Does Edge do registry key and file tracking (like ThreatFire) or does it also keep track of the changes (like Spyberus). In the last case a value change from say 10 to 20 could be revoked to 10 again.

    Nice to see that behavior blocking indeed is using virtualisatioin to gain time for analysis of patterns (as predicted :) )
     
  8. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I will have to say nay (for now) to this :) Our implementation is not quite this advanced.... yet.... but we are developing this extended system currently. The only reason why it is not completely in the current version is that it does require some additional overhead to store backup copies of every value, when most values that are changed will not turn out to be malicious, but, we are working on an optimal solution which will be pushed out to all clients as an update in a few weeks when it has been thoroughly tested and proven :)

    As well as this extended feature, we have a number of other exciting improvements, so, stay tuned :D Prevx is not sitting idle at all :D
     
  9. jlo

    jlo Registered Member

    Joined:
    Nov 29, 2004
    Posts:
    475
    Location:
    UK
    Hi,

    A couple of questions?

    1) If I run a exe file via Sandboxie, if it exhibits malware charactistics will EDGE flag it even though its been run within a sandbox?

    2) There is the option to manually detect a file that you know is malware and prevx does not detect. As soon as you do this PREVX recognises it as malware on your computer. If you double click on the detection you can then see the file on Prevx database and it generally gets listed as 'These files have yet to be determined.......'

    If another user clicks on the same exe file, will it get listed as malware on their Prevx Edge as well or will the file be allowed to run untill its determined as malware on the database (or of course if it trips you central heuristcs it will do this automatically)

    Sorry for the lenthy question!

    Best wishes

    Jlo
     
  10. mvdu

    mvdu Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    1,166
    Location:
    PA
    Does Prevx have regular signature updates like AVs? I'm using it right now as my AV.
     
  11. mvdu

    mvdu Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    1,166
    Location:
    PA
    Not too much for me, if it works. KIS won't install, though, if Prevx is already on the machine.
     
  12. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    (Lengthy questions are always preferred :) My responses tend to be just as lengthy so I deserve some retaliation!! :D)

    1) We haven't tried running malware from within a sandbox and seeing what Edge can see but I'd imagine that if the sandbox was working properly, Edge would not be able to see the behavior as the sandbox would isolate it from reaching the system at all. I also don't know how the internals of Sandboxie work

    2) Our Community approach does not take the opinions of the users in the community, rather, it looks at the behavior of programs on the computers in the community. Therefore, even if 5,000 users mark a file as 'Good' in Edge, it will not automatically mark it as good in the database. This prevents Mr. Malware Author from getting a bunch of computers together and fooling us into thinking it is good.

    The same goes in the opposite direction - if 5,000 people mark a file as bad, it will not be automatically changed to bad (as there is the possibility that Mr. Malware Author just wants to discredit us by marking good files as bad).

    In both cases, samples with overridden determinations, either good or bad, are sent into manual analysis or deeper automated server-side analysis, so, there will be some delay from when you override to when we actually change the global determination.

    However, if you do have overrides on malware to block them, feel free to let any of the Prevx people here know and we can mark them as bad immediately. Going through the overrides every day does take time and logic to reason through and sort out the incorrect user overrides, so, it would be faster if you send the samples in question through to us directly (we will provide you with email addresses, etc. and we are in the process of developing a sample submission system to help out in automated analysis of manual overrides).

    I hope my verbosity make you dismiss the message! :D Let me know if you have any further questions!
     
  13. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    KIS appears to check for the registry key HKEY_LOCAL_MACHINE\Software\PCSI, which is our main registry key (just has a couple values in it).

    If you want to get Edge/CSI to work alongside KIS, you will want to first uninstall our products, make sure that the key is removed completely, and then install KIS and after that install Edge/CSI on top.

    This has worked for users that have come into our inbox with the question, but if not, please let us know and we'll try and find another workaround :)
     
  14. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We have extremely regular signature updates, but they are nothing like normal AVs. We add literally thousands of new samples every hour to our definitions and heuristics, but everything takes place on the Community-side, so, you never need to download updates - the clients just check against the newest definitions on the server.
     
  15. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    well, i must say.

    I do love the new version, like a kid with a new toy. :rolleyes:

    so, have i mis-read something, or are more security-features for the EDGE product on its way via updates?
     
  16. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    From my experiences using Edge and Sandboxie together, Edge will see and block malware if it starts to run in the sandbox. Pretty much the same as using an AV together with Sandboxie. Programs outside the sandbox can look in but programs in the sandbox can't look out.
     
  17. jlo

    jlo Registered Member

    Joined:
    Nov 29, 2004
    Posts:
    475
    Location:
    UK
    Thank you for the excellent answers.

    Best wishes

    Jlo
     
  18. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    I agree with you CSJ, Edge has permanently taken the place of an AV on my computer.
     
  19. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Oh yes :D While they won't be released for a few weeks, we have a number of security-related features that will be incrementally added into Edge, coming down to clients via automatic updates.

    (Note: We do have an update scheduled for later today in Edge as well which fixes a lot of the compatibility issues with other AVs)
     
  20. jlo

    jlo Registered Member

    Joined:
    Nov 29, 2004
    Posts:
    475
    Location:
    UK
    Brilliant. thats just what I wanted to know.

    Jlo
     
  21. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Good to know! Thanks for the clarification :)
     
  22. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    No problem!!! :)
     
  23. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    cool, cant wait.

    so, what kind of things? (in a few weeks)

    will they help detection, removal or what? :)


    ---

    also, i do wonder how EDGE would perform in one of the tests compared to the traditional antivirus solutions do you not think it should be included? :)
     
  24. mvdu

    mvdu Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    1,166
    Location:
    PA
    I'm trying KIS 2009 and Prevx together now. No major problems yet, but after Prevx finished scanning and went to real time, KIS popped up with a "Trojan.Generic" alert that I think might have been related to Prevx, since the only option was to allow. Maybe this can be checked out. Thanks for all your help!
     
  25. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We have a number of new behavior modeling algorithms baking in the oven as well as removal improvements and a whole mess of other things :D

    I think comparing Edge against traditional antivirus products is a bit unfair for both ends. Firstly, standard AVs detect a great deal of things that Edge won't, for example, old DOS viruses from 20 years ago and corrupt virus samples that have remnants of old, inactive infections in them.

    On the other hand, Edge detects a great deal of things normal AVs don't detect, in the time that it takes them to release an update.

    If you look at it graphically, normal AVs have to cover all old samples, even ones that can't affect users, up until new samples. However, based on the conceptual problems in definition updates, it isn't possible to have extremely fast detection of new threats.

    However, if you look at Edge, which covers malware that actually affects users today rather than users of 20 years ago, all the way up to malware that will be affecting users next week, you see that there is some overlap but not a whole lot.

    With how fast infections are mutating, testing antivirus products is becoming increasingly difficult and time consuming. Rather than being able to just right click on a folder and select 'Scan', testers now have to take into account whether the file is detected in realtime, while loading, on demand, in memory, if under a rootkit, coming via an exploit, etc. etc.

    Honestly, in today's threat landscape, I would not want to be a tester :D

    To make a long story short (too late), Edge and conventional AVs shouldn't really be tested side by side as they both have very different intentions. I hope that helps, sorry for the essay! :D
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.