Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 10th, 2011, 08:44 AM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,091
Default Age/popularity heuristics

I was trying to trigger the age/pop heuristics by executing rare and newer software but I haven't been able to trigger a detection so far. Even with both age and popularity set to maximum it does not trigger on software that would normally have been triggered with Prevx 3 on lower settings. Is it fully working?

Also I did this to check if some improvements were already implemented which I suggested here and were confirmed for v4:
http://www.wilderssecurity.com/showthread.php?t=283838
Are they implemented in WSA?
  #2  
Old October 10th, 2011, 11:26 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is online now
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: Age/popularity heuristics

The Age/Popularity heuristics now take into account the behavior of a program. As we're just coming out of the beta, the Age/Popularity heuristics aren't fully enabled but once we establish a good baseline of users, we'll be turning them on.

In the meantime, you can set specific areas to block any non-whitelisted file or by raising the Advanced Heuristics which will show a "HIPS" warning like the one below:

Name:  image003.png
Views: 414
Size:  37.9 KB
  #3  
Old October 10th, 2011, 02:34 PM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,091
Default Re: Age/popularity heuristics

Thanks.

Quote:
Originally Posted by PrevxHelp
In the meantime, you can set specific areas to block any non-whitelisted file

How to do this? Are these the options in the Core system shield which are already enabled by default?(Except for HOSTS file modification.)
  #4  
Old October 10th, 2011, 07:06 PM
Romagnolo1973's Avatar
Romagnolo1973 Romagnolo1973 is offline
Frequent Poster
 
Join Date: Feb 2009
Location: Italy - Ravenna
Posts: 426
Default Re: Age/popularity heuristics

Quote:
Originally Posted by BoerenkoolMetWorst
Thanks.



How to do this? Are these the options in the Core system shield which are already enabled by default?(Except for HOSTS file modification.)
pc security - edit heuristic - set "warn when new programs execute taht are not trusted", in this case you bypass heuristics and are you that decide what allow or not
__________________
PrivateFirewall + Kaspersky AV + HitmanPro + Sumo Updater
Sorry For My Bad English I'm Italian
  #5  
Old October 10th, 2011, 07:52 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is online now
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: Age/popularity heuristics

Quote:
Originally Posted by Romagnolo1973
pc security - edit heuristic - set "warn when new programs execute taht are not trusted", in this case you bypass heuristics and are you that decide what allow or not

Exactly
  #6  
Old October 10th, 2011, 08:15 PM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,309
Default Re: Age/popularity heuristics

Quote:
Originally Posted by Romagnolo1973
pc security - edit heuristic
Just to clarify in case anyone is trying to find this - find it here: PC Security/Shields/Edit Heuristics.

Alternatively, click on Settings and go to Heuristics.
  #7  
Old October 11th, 2011, 02:03 PM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,091
Default Re: Age/popularity heuristics

Quote:
Originally Posted by Romagnolo1973
pc security - edit heuristic - set "warn when new programs execute taht are not trusted", in this case you bypass heuristics and are you that decide what allow or not
Yes, but that is about the execution of untrusted files(a nice feature btw), but I asked about blocking modifications done by untrusted files, like setting itself up to automatically start on boot like shown in Joe's screen.
  #8  
Old October 11th, 2011, 02:04 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is online now
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: Age/popularity heuristics

Quote:
Originally Posted by BoerenkoolMetWorst
Yes, but that is about the execution of untrusted files(a nice feature btw), but I asked about blocking modifications done by untrusted files, like setting itself up to automatically start on boot like shown in Joe's screen.

You can do that by raising the Advanced Heuristics one or two levels from the default Medium.
  #9  
Old October 11th, 2011, 02:09 PM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,091
Default Re: Age/popularity heuristics

Quote:
Originally Posted by PrevxHelp
You can do that by raising the Advanced Heuristics one or two levels from the default Medium.
Thanks
  #10  
Old December 16th, 2011, 07:04 AM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,091
Default Re: Age/popularity heuristics

Quote:
Originally Posted by PrevxHelp
As we're just coming out of the beta, the Age/Popularity heuristics aren't fully enabled but once we establish a good baseline of users, we'll be turning them on.
WSA has been released for a while now and a lot of old Webroot customers have been transfered, so are they completely enabled now?
  #11  
Old December 19th, 2011, 12:37 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is online now
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: Age/popularity heuristics

Quote:
Originally Posted by BoerenkoolMetWorst
WSA has been released for a while now and a lot of old Webroot customers have been transfered, so are they completely enabled now?

I believe they're still slightly different than the P3 age/popularity heuristics in how they work (as they're taking into account the behavior of files still) but we're currently working on tuning them fairly regularly to see how to best work within the configuration
  #12  
Old December 20th, 2011, 04:48 PM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,091
Default Re: Age/popularity heuristics

Ok, thanks.
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:31 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums