Behavior Blockers? Cloud?

Discussion in 'other anti-virus software' started by bellgamin, Jul 19, 2018.

  1. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Which of the *mainstream* antivirus apps include either a behavior blocker or a HIPS?

    Which of the *mainstream* antivirus apps scan primarily in the cloud &, therefore, put little or no signature files on user's computer?
     
  2. guest

    guest Guest

    99% of them, because they knew since ages that signature only is doomed to fail.
    BB: Emsisoft, bit defender, Avast, webroot, etc..
    HIPS: ESET, kaspersky, etc...

    it is faster to mention those who don't have any than those who have.

    Webroot, Panda cloud
     
  3. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,291
    Location:
    Pennsylvania.
    Comodo has a cloud AV with a sandbox.
     
  4. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Great topic. HIPS was "it" back on XP's run but 64bit rose up and they were done so AV's picked up that ball and ran with them.

    I was always partial to BB's too like CyberHawk turned ThreatFire as standalones and they did what was needed well enough IMO.

    But my answer to question number 2 from some experience, is Panda Cloud-(light as a feather), which for my more modern systems proved lightning quick and all that but as everyone knows, AV's rarely stayed on my systems no more longer than to test their ability/performance locally only.
     
  5. guest

    guest Guest

    Same here, there is only 2 AVs i care to eventually install on my systems; Webroot and Emsisoft. For the moment none of them are installed.
    i'm considering Cylance, but let see its resources impact... i don't need my next AV to be a "jack of all trade" with dozen fancy uber-feature because i use specialized softs that already lock my system more than enough; i may need a simple AV to backup my tools, no tons of features, with decent detection, very light, no local signature.
     
    Last edited by a moderator: Jul 19, 2018
  6. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    :thumb: They do that indeed. Some of the best minds have fashioned a few choice super-locktight security apps.

    Had a sneak-peek at full Panda Dome and actually have a valid license for it but only did that due to it's supposedly excellent firewall users were raving over when it came out. Realized soon after no matter how superior any AV is-plus it's features with HIPS/BB's, I already moved beyond any interest in any of them to add them to the current mix since WD is steprd up it's game.

    However with a choice it would be Russian roulette all over again. Panda would be the first choice (cloud)-very lightweight-minimum resource use, then the musical chairs would ensue the first time something poked through which is happened with every single AV I tried except recent WD.
     
    Last edited: Jul 20, 2018
  7. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    On my PC, Avast is as light as Panda and it's even lighter during boot time.
    It does download signatures, but the update process doesn't hog the system. It also has BB and cloud check.
    I chosed the MIN installation (file shield, behavior shield, web shield) to avoid the bloatware and I tuned it for better protection (hardened mode aggressive), lower resources impact and no ads.
    This is a nice guide for Avast https://malwaretips.com/threads/ava...-protection-and-efficiency.84620/#post-743926
     
  8. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Check out 2017's PCMag review of Webroot Secure Anywhere (WSA). Although I usually take PCMag's reviews with several grains of salt, their review of WSA was actually an educational write-up, instead of the usual laudatory *test results* of a potential advertiser's product.

    I actually learned several things about WSA (& about security in general) from that excellent article. A couple of the things I learned are: (a) WSA is very VERY much a cloud-based app, (b) WSA is lighter than helium as a result, & (c) WSA is a more-than-worthy succesor to my old favorite PREVX. Shazam!
     
  9. __Nikopol

    __Nikopol Registered Member

    Joined:
    Aug 13, 2008
    Posts:
    630
    Location:
    Germany
    Does Avira have BB? I'm not a hundred percent sure, but I'd say no.
     
  10. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,291
    Location:
    Pennsylvania.
  11. __Nikopol

    __Nikopol Registered Member

    Joined:
    Aug 13, 2008
    Posts:
    630
    Location:
    Germany
  12. m0unds

    m0unds Registered Member

    Joined:
    Nov 12, 2015
    Posts:
    219
    it has a local decision engine and cloud-based behavioral detection. easy to confirm by reading whitepapers and documentation about APC.
     
  13. guest

    guest Guest

    it is not a behavior blocker a la Emsisoft, just behavioral detection.
     
  14. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    8,251
    Location:
    The land of no identity :D
    Avira has a cloud based behavioural engine, not a traditional behaviour blocker. Their BB ProActiv is discontinued.
     
  15. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I think most of these AV's are using behavior blockers but they don't work in the same way. Most AV's use some form of behavioral detection pre execution, so before some app is allowed to run. When they can't decide whether it's malware they send it to the cloud.

    But you also have AV's that block suspicious behavior if some app is already running, Webroot does this via the Identity Shield feature. For example, you won't find this in an AV like Win Defender.

    https://community.webroot.com/t5/Tech-Talk/Identity-Shield-Deep-Dive/td-p/46422
     
  16. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
  17. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    On this regard, it is not what it appears to me.

    Many AV's will submit the suspicious process for scanning on their cloud servers. However, the process is not suspended awaiting a reply from the cloud as is done with WD's "block at first sight" and is allowed to execute. This is because the AV servers perform a detailed analysis which could take some time. If the process is deemed malicious, then a blacklist entry is created for it pending full sig. creation. As far as WD's high user interaction rates on AV lab tests, it is proof that a quick cloud scan really is not sufficient to determine most processes malicious activities with high confidence levels.

    Also this is the difference with the Next Gen solutions in that their AI engines are deployed locally and scan a process in more rapid fashion. However as shown on the AV lab tests, their detection rates are not any greater than conventional AV detection methods.
     
  18. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    @ itman -- okay, so do these AVs warn you with a pop-up saying something like: "Analysis of this Application may take some time. Recommend you do NOT install it until our analysis is complete." OR do they just leave you slowly twisting in the wind?
     
  19. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Good point, I also wondered about this, clearly "the cloud" isn't a silver bullet either. That's why post execution behavior blocking is still a must for me.

    I really don't have any idea, but I believe that Win Def claims it only takes seconds to get a result from the cloud. Webroot is also cloud based so is it really that quick?

    I'm not sure if they acquired this tech with Prevx, but it's fun to read these type of old articles.
     
  20. Muddy3

    Muddy3 Registered Member

    Joined:
    May 31, 2010
    Posts:
    415
    Location:
    Belgium
    Certainly did!*

    * @Triple Helix would be able to provide more details on this, but suffice it to say that those of us who came to Webroot SecureAnywhere from Prevx experienced a completely smooth continuum from Prevx 3.0 to first generation Webroot SecureAnywhere with basically exactly the same technology that we had come to know and love, but now at an even more sophisticated level. And though it has of course evolved further since then, it still remains fundamentally the same beast.
     
  21. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Agreed fully and the same developer designed WSA Joe Jaroch or PrevxHelp known on here: https://www.wilderssecurity.com/members/prevxhelp.87864/ ;)

    https://youtu.be/qy5o2wIwUDk
     
    Last edited: Jul 28, 2018
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.