What is the best HIPS out there ?

Discussion in 'polls' started by IcePanther, Jun 9, 2006.

?

What is the best HIPS software ?

  1. Antihook

    1 vote(s)
    0.4%
  2. Ghost security suite

    31 vote(s)
    11.6%
  3. Online Armor

    60 vote(s)
    22.5%
  4. PrevX

    38 vote(s)
    14.2%
  5. Process Guard

    29 vote(s)
    10.9%
  6. System Safety Monitor

    54 vote(s)
    20.2%
  7. Other.... (please specify in your post)

    54 vote(s)
    20.2%
Thread Status:
Not open for further replies.
  1. screamer

    screamer Registered Member

    Joined:
    Apr 14, 2006
    Posts:
    922
    Location:
    Big Apple USA
    I've tried a few Hips:

    Prevx seems to slow down my machine
    OnlineArmor screwed w/ my start up list
    ProcessGuard doesn't play nicely w/ FD-ISR

    ProSecurity is very nice :)

    SSM gets my vote :thumb:

    I was in way over my head when I first installed it. After reading the forums and asking questions. I think I've got a handle on it now. I'm not claiming to be any kinda expert... After running it in "Learning Mode" taking it out of learning mode and answering a few popups. (reading the DETAILS in popups) If you feel compelled: configuring all the Parent / Child relationships...

    I feel I'm pretty well protected.

    ...screamer
     
    Last edited: Jul 5, 2006
  2. MikeNash

    MikeNash Security Expert

    Joined:
    Jun 9, 2005
    Posts:
    1,658
    Location:
    Sydney, Australia
    Hi Screamer - if OA caused you a problem, please drop me a PM.. happy to help you with it.


    Mike
     
  3. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    What problems did RegDefend cause with FD-ISR. I for sure don't see any issues at all.

    You might post questions about this in the leap frog forum.

    Pete
     
  4. screamer

    screamer Registered Member

    Joined:
    Apr 14, 2006
    Posts:
    922
    Location:
    Big Apple USA
    Pete, my mistake, it was process guard. I corrected it.

    ...screamer
     
  5. wilbertnl

    wilbertnl Registered Member

    Joined:
    Dec 29, 2004
    Posts:
    1,850
    Location:
    Tulsa, Oklahoma
    I vote for Cyberhawk (version 1.1.0.4), which is non-intrusive, has a decent foot print and I don't notice impact on performance.
     
  6. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    I have voted for SSM,..
    This I have done, not simply for its excellent protection, but also due to the fact I have found that the SSM team listen to its customers,.. they listen and impliment good ideas brought forward,.. and fix any bugs reported_ very quickly.
     
  7. sosaiso

    sosaiso Registered Member

    Joined:
    Nov 12, 2005
    Posts:
    601
    Online Armor with AV+ was amazing since the first stages of beta. Along with all the other features, it is amazing. And the support!

    Prevx1 comes closely behind it with lesser feature offerings.
     
  8. dylanfan

    dylanfan Registered Member

    Joined:
    Feb 10, 2006
    Posts:
    187
    SSM... Simply perfect.
     
  9. egghead

    egghead Registered Member

    Joined:
    Aug 27, 2005
    Posts:
    443
    Location:
    The Netherlands
    System Safety Monitor: :thumb: :thumb: :thumb:

    1.EVERY malware test I have thrown at it I've been able to block

    2.great support and committed company

    3. REAL ;) zero-second protection (does not work with a signature/data base)

    4.monitors all running processes and operating system activity in real time

    5. extremely fine-grained control over apps
     
  10. Ptah

    Ptah Registered Member

    Joined:
    Feb 25, 2006
    Posts:
    170
    Prevx1 here:thumb:
     
  11. rpsgc

    rpsgc Registered Member

    Joined:
    Dec 29, 2005
    Posts:
    312
    Location:
    Portugal
    Hi guys,

    Sorry for the off-topic but I have a question regarding HIPS... I'm currently using Winpatrol PLUS, which I don't know whether it qualifies as a HIPS or not. Do you think that's enough? Besides the standard protection of course (avast home, Kerio PF, Windows Defender)...

    Anyways I tried PrevX and although it seems pretty good it was really heavy on my system (PXAgent ~25MB, PXConsole ~6MB).

    Now I'm trying SSM. Should I set it to learning mode?
     
  12. WSFuser

    WSFuser Registered Member

    Joined:
    Oct 7, 2004
    Posts:
    10,639
    i personaly do consider winpatrol an HIPS but to each their own.

    as for learning mode, its up to you. some people dont like it and prefer to validate each app themselves. i havent tried SSM but id use learning mode as i dont like having lots of alerts.

    as for the poll, i already voted for online armor but i have just recently switched to prevx. its memory usage is heavy but its being worked on, and its quite powerful and thorough on its policies. plus running in ABC mode, i havent seen any alert yet except for two small notifications when it is authenticating a program or scanning it.
     
  13. dylanfan

    dylanfan Registered Member

    Joined:
    Feb 10, 2006
    Posts:
    187
    Hi
    The way I use SSM is this:

    After installing SSM on a clean system I trust (for instance, a newly installed and patched OS), I set SSM in learning mode ("connect the user interface" - SSM icon is green in the systray), and I open every app I currently use in turn, one after another.

    Each time, of course, SSM would intercept it and ask me what I wanna do with it. Since they're all apps I just decided to open myself, I answer "allow to run each time" for those.

    Once this is done, I right-click on SSM and "disconnect the user interface" (SSM icon is grey in the systray), which means that now, SSM won't ask me anymore when a new app will try and start: it will then simply block it. Only the apps I previously launched and instructed SSM to allow will be able to run in this new "disconnected-user" mode I just set.

    It stays that way from then on. In the options of SSM, I check the option "start automatically at OS startup" and uncheck "connect user interface automatically". I also instruct SSM to monitor apps, processes, services, regkeys and so on, also by right-clicking in the systray.

    That's it. Your system is now bulletproof against any leaktest or whatever bad app which would even try and install on your system.

    This way, you don't have to always play questions and answers with SSM: it now knows what to do and what not to allow (which is anything it doesn't know or trust already).

    Try it: it succeeds against any leaktest or whatever I ever throw at it. That's not a surprise once you set SSM up the proper way.

    Cheers
     
    Last edited: Jul 8, 2006
  14. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Hi, I think learning mode is must with SSM otherwise u will waste ur time with pop ups.
    Put it in learning mode and do watever u are doing normally every day. When u think it is over then go to normal mode.
    About WinPatrol, if u use windows defender then I think it covers a lot of things covered by WinPatrol( new start up enteries, new services etc). I will personally remoeve it if I am using Ws Defender.
     
  15. rpsgc

    rpsgc Registered Member

    Joined:
    Dec 29, 2005
    Posts:
    312
    Location:
    Portugal
    Thanks for the help guys! :)
     
  16. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    I like to do like this but I want to ask, this way is it not going to cause any trouble with auto- updates of windows and Av etc? I put it in learning mode for many days but still it pops up some times( after AV and probably after windows auto-updates).
     
  17. dah145

    dah145 Registered Member

    Joined:
    Jul 3, 2006
    Posts:
    262
    Location:
    n/a
    Also what of the HIPS is the less resource consuming? o_O (but still a good one?)
     
  18. WSFuser

    WSFuser Registered Member

    Joined:
    Oct 7, 2004
    Posts:
    10,639
    of teh various HIPS ive tried, ProcessGuard is the lightest. Its no slouch either, it can block drivers, hooks, process modification/termination, etc...
     
  19. dah145

    dah145 Registered Member

    Joined:
    Jul 3, 2006
    Posts:
    262
    Location:
    n/a
    Thanks and
    How is SSM in resources usage?
     
  20. MGhell

    MGhell Registered Member

    Joined:
    Jul 9, 2006
    Posts:
    34
    SSM is quite light on resources, it uses about 8MB on my system (XP PRO SP2).

    Max
     
  21. dah145

    dah145 Registered Member

    Joined:
    Jul 3, 2006
    Posts:
    262
    Location:
    n/a
    Thanks, I will try SSM. :cool:
     
  22. squibbon

    squibbon Guest

    Online Armor - without a doubt.
     
  23. Heco

    Heco Registered Member

    Joined:
    Mar 8, 2003
    Posts:
    264
    Location:
    Provence, France
    +1:)
    Cheers,
    Hervé
     
  24. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ dylanfan

    I use SSM in the same way, however I´ve noticed that if I choose to use the "block everything paranoid mode" setting, some browsers will not work correctly. So that´s why I´ve installed Neoava Guard as a backup HIPS because SSM will not block everything when in "block process creation" mode.
     
    Last edited: Jul 11, 2006
  25. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    DefenseWall deserved a place in this poll :(
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.