Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 17th, 2012, 05:05 PM
Gullible Jones
 
Posts: n/a
Default Apply HIPS restrictions to children of a restricted process?

Asking because of some odd behavior I've seen with Outpost FW...

What HIPS software is known to apply restrictions specified for a program to processes spawned by that program?

Furthermore, what HIPS software is known not to apply such restrictions to child processes?
  #2  
Old August 17th, 2012, 05:20 PM
LoneWolf's Avatar
LoneWolf LoneWolf is online now
Massive Poster
 
Join Date: Jan 2006
Posts: 3,130
Default Re: Apply HIPS restrictions to children of a restricted process?

Is this what you mean?
Screenshot of Malware Defender alert..............
Name:  2012-08-17_171453.png
Views: 202
Size:  20.0 KB

Or here............

Name:  2.png
Views: 198
Size:  46.3 KB
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness

Last edited by LoneWolf : August 17th, 2012 at 05:27 PM.
  #3  
Old August 17th, 2012, 05:58 PM
Gullible Jones
 
Posts: n/a
Default Re: Apply HIPS restrictions to children of a restricted process?

Nope... I mean silently applying the same set of restrictions to child processes, unless another set of restrictions is specified and the child application is specifically disallowed from inheriting restrictions. Something like this:

- A, B, C, and D are applications.
- A has a ruleset that denies sound card access. B has no rules. C has rules denying keyboard access, plus whatever is denied by the parent process's rules; D has rules that deny keyboard access but supersede the parent process's rules.

So:

- If A launches B, B inherits A's rules.
A+NoSound -> B+NoSound

- If A launches C, C inherits A's rules and has its own applied.
A+NoSound -> C+NoSound+NoKeyboard

- If A launches D, A's rules are not inherited, and only D's are applied.
A+NoSound -> D+NoKeyboard

Umm, I hope this makes sense?
  #4  
Old August 27th, 2012, 02:42 PM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Apply HIPS restrictions to children of a restricted process?

Most classical HIPS having a rule set on program level (Malware Defender, Comodo) apply the default rule when the launched program does not have his own rule, Most policy based HIPS apply the same restrictions to programs launched by a guarded program (DefenseWall, GeSWall), when this program is not in exclusion list.

Basic difference is that a clasical HIPS provides system wide protection while it guards all threat vectors and a policy based HIPS guards named threatgates programs (keeps them in a sandbox or policy container) while protecting against all threat vectors (including process creation and spawning other programs).

Last edited by Kees1958 : August 27th, 2012 at 03:37 PM.
  #5  
Old August 27th, 2012, 06:26 PM
itman itman is offline
Frequent Poster
 
Join Date: Jun 2010
Posts: 569
Default Re: Apply HIPS restrictions to children of a restricted process?

PrivateFirewall HIPS has this capabilty. You can get pretty granular with access permissions with it.
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:05 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums