Future Changes to ESS

Discussion in 'ESET Smart Security' started by Blackspear, Jan 22, 2008.

  1. Najem1992

    Najem1992 Registered Member

    Joined:
    May 2, 2009
    Posts:
    53
    Location:
    In The Heart Of Eset
    hi
    these are the most important things that ESS v4 needs :
    1. Improving the firewall while maintaining good stability and performance

    2. adding HIPS technology ( they said they added it but actually they didn't )

    3- system protection ( not to be able modify any system components unless
    this feature is disable )

    4- for the support they should make an automated message so that the user would know that his message was recieved

    5- When firewall blocks an attack (such as a worm, DNS poisoing attack etc), I would like ESET to display a message and inform the user that an attack has been blocked.

    6- this one is very important I'd like to see an in-built sandbox on Eset like they have on Norman Virus Control to analyse newer malware and trace system activity. It would have to be a good one though. I've seen new malware that can detect a sandbox environment therefore not execute as it would on a live system.

    7- there must be an option related only with programs notifications and it should have two buttons Enable and Disable for all and each notification

    8-Change the events logging so that instead of just recording an entry that states "The program modules have been updated" it should actually state what module was updated, what the old version was and what the new version was (e.g. something like "The Firewall module has been updated from 1044 to 1045").

    9- there must be a removal tool for Ess to use it when reinstalling the program


    if they really make these things Ess will destroy any virus and will be the best in digital security world
    and thanks for your great efforts

    note : I took some ideas form people posting before me
     
    Last edited: May 6, 2009
  2. Najem1992

    Najem1992 Registered Member

    Joined:
    May 2, 2009
    Posts:
    53
    Location:
    In The Heart Of Eset
    hi again I remembered one more thing
    Eset doesn't support a lot of compression methods
    and that makes it week when scanning compressed files
    even though that when you extract them Eset will immediately
    scan them with real-time file system protection :D
     
  3. no_idea

    no_idea Registered Member

    Joined:
    Apr 1, 2009
    Posts:
    83
    I'd rather have excellent heuristics than potential incompatibilities and/or false positives by too frequent updates.
    As Marcos has pointed out elsewhere, quality assurance takes some time.
    So, even if other companies push out updates every 5 minutes, that doesn't mean, the updates cover the threats discovered 5 minutes ago!
    Competitors only stress their update frequency, not the time it took them to complete the full analysis-programming-packaging-qs-delivery cycle.

    full acq - I mean, what does an automated message like this cost?

    "Dear valued customer, thank you for contacting eset support. Your request has been issued ticket number 123456.
    Please understand that due to the large amount of messages received from our vast customer base we cannot personally respond to each and every message sent to us."

    At least we then would know our message has been received.

    oh! - Hopefully, eset doesn't listen to this!
    Imagine you are on an open wireless network directly connected to the Internet - with all the messages about blocked threats you wouldn't be able to get any real work done.
    At the very least, eset should make this kind of messages optional
     
  4. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Exactly. Just try enabling logging of blocked connections in the IDS setup and you'll probably see the firewall log growing in size quickly. If a balloons was displayed as well, you might easily end up with alerts being shown up even several hours or days after disabling firewall until there's no alert to display in the queue.
     
  5. Najem1992

    Najem1992 Registered Member

    Joined:
    May 2, 2009
    Posts:
    53
    Location:
    In The Heart Of Eset
    ok this point isn't necessary ...
    but what about other 8 pointes I mentioned
    they're so important :D
     
  6. Najem1992

    Najem1992 Registered Member

    Joined:
    May 2, 2009
    Posts:
    53
    Location:
    In The Heart Of Eset
    Eset firewall is very weak make it better !
    Eset doesn't clean archives he delete all archive
    but it should only delete infected files inside it and leave the rest
    like KASPERSKY !!!
     
  7. ESS3

    ESS3 Registered Member

    Joined:
    Dec 11, 2007
    Posts:
    112
    add to ESET Smart Security
    SandBox, analysis file!!! :)
     
  8. ESS3

    ESS3 Registered Member

    Joined:
    Dec 11, 2007
    Posts:
    112
  9. ladhani

    ladhani Registered Member

    Joined:
    May 26, 2009
    Posts:
    5
    Hello,

    Since I upgraded to ESET Smart Security (ESS) version 4, we have the following issue:

    We are using in our company a number of browser applications for uploading (BIG) documents to our servers (Flash / PHP uploaders).

    Since we upgraded from version 3 to version 4, the upload progress bar in the browser application does not work correctly. It immediately shows 100% upload ready with an impossible high upload speed. And next nothing happens in the Browser application for a very long time. After some time, the browser application continues (upload ready).

    What ESET 4 seems to do, it directly catches the uploaded file, first storing it locally for scanning and than uploading it on the background to our servers.

    This is very disturbing for us as our employees think that the browser has frozen up as they see the upload progress bar directly at 100% and nothing seems to happen (for a long time).

    A crude solution for this issue is to completely disable HTTP - scanning (Advanced config -> Antivirus -> webaccess -> HTTP -> disable HTTP contol).

    As a result ALL HTTP scanning is disabled.

    Enabling HTTP scanning and adding our domain names to the list of domains not to be checked, DOES NOT solve the upload issue.


    ========================================================

    Here you can try / test this your self:

    http://www.tinywebgallery.com/en/tfu/web_demo2.php

    The upload size of this Flash uploader is limited to 300 KB but if you squeeze your netwerk speed, you will see that the progress bar does work correctly with HTTP-filter turned OFF and goes directly to 100% if you turn the filter on again.

    =========================================================




    So what we would like to see is:

    A - make a distinction between HTTP UPLOADING and DOWNLOADING in this setting.

    B - make it possible to define domains that are free from HTTP scanning for UPLOADS. So we could add our company domains to the ESS of our empoyees so they can upload the files to our servers using our webapplications. So NO underwater caching of upload files by ESS.

    This would really help our company, our employees and our system administrator to setup a better balance between using user friendly company web applications with upload fnctions - and - a good safe and secure use of ESS.
     
    Last edited: May 27, 2009
  10. JeroenKM

    JeroenKM Registered Member

    Joined:
    May 29, 2009
    Posts:
    1
    I like to see

    password protection for diffrent items (av, fw and spam)
    ra remember install password !
    ra remember package install (que) to client
    uninstall parameters for other vendor goal
    better support for lan and wan detection for updates
    having id's in tasks and profiles voor added deleting and renaming
    possibility for month scan by task
    offering discount program for home users (make eset bigger)
    component updating like patches (saw more users of this)

    I now use the products( av, ess and ra) for 2 weeks :) for 320 users (ex mcafee epo user)
     
  11. a3_alin

    a3_alin Registered Member

    Joined:
    Mar 5, 2009
    Posts:
    59
    Location:
    Romania
    you are right!!!
     
  12. ramremo

    ramremo Registered Member

    Joined:
    Aug 7, 2008
    Posts:
    6
    Last edited: Jun 19, 2009
  13. colin99

    colin99 Registered Member

    Joined:
    Apr 12, 2008
    Posts:
    2
    Location:
    Winnipeg, Canada
    I would strongly suggest that ESET get their firewall to pass Windows logo test (or logon test I can't remember). I tried to repair Windows XP a while ago and this error message kept comming up that eset firewall doesn't pass windows logo test, the messages kept comming up and I had to abort the repair and reinstall Windows XP after a format. Also this message pops up several times when I install eset smart security.

    Next, I've had a few rootkits install themselves on my system over the course of 6 months, looks like the same one each time. eset SS can't detect it and I get lots of pop ups from the firewall that svchost is trying to communicate with someone somewhere(I'm using interactive mode). It doesn't tell you the web sites or that anything odd is happening. If I start Webroot spysweeper with av and disable eset av, webroot gives me notifications (above the task bar) of all the websites(full name) that a program on my computer is trying to connect too. This is what tipped me off that I had malware. I ended up using unhackme to remove it, webroot av couldn't find it either. Eset needs to improve their rootkit detector.

    Shaun
     
  14. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    Add HIPS
    Add a behavior blocker
    Make the signatures databases much bigger.
    This will truly make it the best in my oppinion
     
  15. MasterTB

    MasterTB Registered Member

    Joined:
    Jun 19, 2007
    Posts:
    547
    Location:
    Paran?, Argentina

    I quote you entire message because the same thing is happening in the Opera Community with the new flash uploader, you put some files in the queue and then you hit upload, after that you see 100% for the first file and the browser freezes... depending on how many files and how big they are after a few minutes you see download complete or the browser crashes because it does not register activity directly.
    This is baaad behavior from Eset, specially when I don't have active mode enabled for my browser.. Hence, the antivirus should check the files on disc and let the browser do it's business alone.
     
  16. OLDXTECH

    OLDXTECH Registered Member

    Joined:
    Aug 7, 2007
    Posts:
    30
    Location:
    Exact center of California
    PROVIDE A "RESUME" FEATURE [ LIKE MICROSOFT! ] FOR FILE DOWNLOADING THAT HAS BEEN STOPPED AND RESET BY A DISCONNECTED DIALUP LINK.

    I have just spent over 10 hours trying to download all the files after "upgrading" from 3.0.650 to 3.0.684 with my 40kps dialup connection, which is the only service I can get here in the boondocks. On the 6th try, over the weekend with lower traffic to the servers in "Lower Slobervia", I finally got them done. If there is ANY clitch in the link, the files fail and start all over again from the beginning! Microsoft solved this ages ago - time for ESET to do the same.
     
  17. simexi

    simexi Registered Member

    Joined:
    Apr 2, 2009
    Posts:
    22
    Is there feature that check rules and file paths ? I mean if you delete / uninstall some program, so no point to keep those rules.

    Just tested something and the rule was still there even file didnt exist. Or is there some delay for cleaning?
     
  18. grib78

    grib78 Registered Member

    Joined:
    Jul 6, 2009
    Posts:
    7
    Yes, same problem of upload to dropbox or mobileme (see my thread)
     
  19. Atomas31

    Atomas31 Registered Member

    Joined:
    Sep 7, 2004
    Posts:
    923
    Location:
    Montreal, Quebec
    - An anti-phising protection that could be integrated into browser (IE, Firefox, etc.)
    - Improve detection and removal of virus, malware, spyware, adware, keyloggers, root-kits, etc...
    - HIPS
    - Cookie blocker
    - An easy way to report false positive or real threats and an email like what you received it and/or that you have corrected the situation.
    - improve the firewall wich seems the weakest part of the suite
     
  20. ESS_Lover

    ESS_Lover Registered Member

    Joined:
    Aug 4, 2009
    Posts:
    29

    That's awesome !! :eek:
    I hope ESET will do these things !
     
  21. plx

    plx Registered Member

    Joined:
    Aug 8, 2009
    Posts:
    9
    add a "global" cleaning level control to change all the cleaning levels simultaneously
     
  22. The PIT

    The PIT Registered Member

    Joined:
    Sep 4, 2008
    Posts:
    185
    Enable Jumbo Frame support so ic an use my Gigabit lan the way it should be used.
     
  23. TsunamiZ

    TsunamiZ Registered Member

    Joined:
    May 24, 2008
    Posts:
    12
  24. rony474

    rony474 Registered Member

    Joined:
    Mar 5, 2009
    Posts:
    24
    i would like to have ,

    1. sandbox
    2. hips

    :)
     
  25. Subgud

    Subgud Registered Member

    Joined:
    Nov 6, 2008
    Posts:
    151
    Location:
    Norway
    I would like a sanbox as many others here. But it should be userfriendly. Not to draw parallels to kasperksy 2010, but theire sanbox is a but hard to figure out when it comes to downloading files.When running IE or FF in sandbox, if you download a file it is hard to find it when the download finish.

    If ESS should have a sandbox I whish it would run web browsers and email clients in sandbox bye default. And it should be possible to download files and save them wherever you want. Just like you do when you are using your browser without a sandbox. :)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.