ProcessGuard Suggestions / Wish list

Discussion in 'ProcessGuard' started by Pilli, Mar 29, 2004.

Thread Status:
Not open for further replies.
  1. Devinco

    Devinco Registered Member

    Joined:
    Jul 2, 2004
    Posts:
    2,524
    Re: Process Guard Suggestions / Wish list

    I don't know if this has been requested before.
    A big list of the common processes that users are likely to come across.
    The list would be setup like Black Viper's list, except for Process Guard.
    It would show "safe" settings that would provide good protection with the least problems and "paranoid" settings for those willing to tweak a little to get more security.
    It would be really helpful for users less familiar with all the processes to be able to compare their protection list (and settings) against a "normal" baseline.
    This list doesn't have to be in PG at all, it could be here on the forum and continuously updated as new processes are added.
    It would be much faster than searching through every PG post.
    It could be in the help file as well, but on the forum the list would be much more dynamic.

    What do you think?
     
  2. Devinco

    Devinco Registered Member

    Joined:
    Jul 2, 2004
    Posts:
    2,524
    Re: Process Guard Suggestions / Wish list

    Based on this thread, a randomization of window placement that would thwart future trojanous attempts to use mouse cursor clicks in PG. By not having the same button location, it would be difficult for a malware to guess where the window button would be.
    I know it's far fetched that the trojan could even get that far, but DiamondCS doesn't allow keyboard access to PG for the same reason. Maybe some future exotic malware could directly manipulate the mouse cursor.

    Just a thought.
     
  3. Jason_DiamondCS

    Jason_DiamondCS Former DCS Moderator

    Joined:
    Nov 11, 2002
    Posts:
    1,046
    Location:
    Perth, Western Australia
    Re: Process Guard Suggestions / Wish list

    Well, the only area that can be mouse clicked by a trojan is the EXECUTION PROTECTION window that pops up when new programs run. So that means a trojan already needs to be running (and hence ALLOWED by you) and then simulate "clicking" on the "Allow" button to get other programs it wants to run. You can lock the ProcessGuard interface so none of your settings can be changed, so that is already safe.

    So if we assume you run and allow some malicious software that does target that specific aspect of ProcessGuard, your machine is still safe from those particular malicious processes since the main protection options cannot be changed. So they can't install hooks, can't install drivers, can't modify protected programs, can't terminate protected programs, etc. :)

    In the end it comes down to ease-of-use, do you want confirmations everytime you click the "Allow" button so that if you do run a trojan it can't click allow for you? I know I don't, and most other users probably agree with me. However the next build of ProcessGuard will probably allow you to set this up (havn't tested the new feature on this particular aspect yet but it should work).
     
  4. Chris12923

    Chris12923 Registered Member

    Joined:
    May 31, 2004
    Posts:
    1,097
    Re: Process Guard Suggestions / Wish list

    It might be nice to see when your in learning mode from the systray icon. it seems this might be dangerous if left unnoticed. Same with execution protection I guess. I know this would be on the user but as we all are human we all make mistakes.

    Thanks,

    Chris-
     
  5. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Re: Process Guard Suggestions / Wish list

    Chris, This has been discussed the DCS beta test forum. It has been suggested that when in learning mode the PG icon should be another colour.
    EG.Red enabled - Blue alerts - Crossed disabled and say Green for in learning mode.
    We will see what Jason comes up with :)

    Enjoy your weekend. Pilli
     
  6. Chris12923

    Chris12923 Registered Member

    Joined:
    May 31, 2004
    Posts:
    1,097
    Re: Process Guard Suggestions / Wish list

    Thanks Pilli seems you always come through for me :)

    Thanks,

    Chris
     
  7. rodsoto

    rodsoto Registered Member

    Joined:
    Mar 18, 2004
    Posts:
    77
    Location:
    Australia
    Re: Process Guard Suggestions / Wish list

    Hi all,

    Anyone noticed when a driver tries to install... or a program has been Blocked from running, or a program has been blocked from creating a hook, that the icon actually does change colour to blue, however sometimes this change isn't enough for you to notice so you can take swift action...

    I would like a feature like the XP hardware update, or XP automatic updates balloon that you get when something new happens. Here's an image for example. You should be able to select the features you want to be notified on.

    IE

    Service install
    Global Mouse Hook
    Keyboard Hook
    Blocked from starting

    [edit: Made a change to the image, looks a little more like this..]
     

    Attached Files:

    Last edited: Oct 9, 2004
  8. Inviernos

    Inviernos Registered Member

    Joined:
    Jun 6, 2004
    Posts:
    8
    Re: Process Guard Suggestions / Wish list

    Let's hear it for brightly colored display for items NOT allowed. Lou_Dinunzio you were correct, it was included in previous version. So, here's vote #3, at least. Please!

    Ricardo
     
  9. Jason_DiamondCS

    Jason_DiamondCS Former DCS Moderator

    Joined:
    Nov 11, 2002
    Posts:
    1,046
    Location:
    Perth, Western Australia
    Re: Process Guard Suggestions / Wish list

    No.. I think you mean more like this :- :)
     

    Attached Files:

  10. rodsoto

    rodsoto Registered Member

    Joined:
    Mar 18, 2004
    Posts:
    77
    Location:
    Australia
    Re: Process Guard Suggestions / Wish list

    Yes...exactly like that! Looks a lot nicer that way jason!
     
  11. gkweb

    gkweb Expert Firewall Tester

    Joined:
    Aug 29, 2003
    Posts:
    1,932
    Location:
    FRANCE, Rouen (76)
    Re: Process Guard Suggestions / Wish list

    :eek:

    I want it !
     
  12. Chris12923

    Chris12923 Registered Member

    Joined:
    May 31, 2004
    Posts:
    1,097
    Re: Process Guard Suggestions / Wish list

    Be nice to see the permit once entries under security tab clear after a restart or have a manual clear button. I can't think of a reason these should not get cleared after a while just showing the programs that are allowed. Maybe I am missing something.

    Thanks,

    Chris
     
  13. rodsoto

    rodsoto Registered Member

    Joined:
    Mar 18, 2004
    Posts:
    77
    Location:
    Australia
    Re: Process Guard Suggestions / Wish list

    i was thinking something along those lines....but more on the lines of 'Remove permit once applications after XX days'.....and even the allow always 'Remove allow always applications after inactivity for XX days'
     
  14. Chris12923

    Chris12923 Registered Member

    Joined:
    May 31, 2004
    Posts:
    1,097
    Re: Process Guard Suggestions / Wish list

    Sounds good to me rodsoto. Anything to get rid of the permit once entries since they served their purpose they should be removed in my opinion.

    Thanks,

    Chris
     
  15. frogfoot

    frogfoot Registered Member

    Joined:
    Aug 8, 2004
    Posts:
    116
    Location:
    Yeovil UK
    Re: Process Guard Suggestions / Wish list

    I would like to see an option in the PG GUI to 'minimise PG to notification area of task bar when closed' rather than closing the GUI, I like to have PG GUI running all the time so I can see when something needs attention (icon flashes blue). This is the same sort of functionality you see in Outpost firewall, MSN messenger etc. An option to close the GUI would still remain in the notification area context menu.
    Thanks
    Tom
     
  16. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Re: Process Guard Suggestions / Wish list

    That wish has been granted and is in the latest private beta's, closing the PG gui using the X or the close menu item does indeed just close the GUI and minimises to the systray.

    Pilli :)
     
  17. frogfoot

    frogfoot Registered Member

    Joined:
    Aug 8, 2004
    Posts:
    116
    Location:
    Yeovil UK
    Re: Process Guard Suggestions / Wish list

    Thaks Pilli, thats good news
     
  18. frogfoot

    frogfoot Registered Member

    Joined:
    Aug 8, 2004
    Posts:
    116
    Location:
    Yeovil UK
    Re: Process Guard Suggestions / Wish list

    One more request while I am at it....
    Please Please Please put in an auto backup function for the PGHash/PGuard files, ie each time PG starts it could save a copy of these files automaticaly, keeping the last five or so. and a mechanism to select which one to load. I ask for this as I have just installed Outpost 2.5 on my machine (disabled protection first) and when I rebooted I got a blue screen. So I rebooted again and PG protection list was empty! That is such a PITA, but I suppose this is still Beta software :)
    Thanks
    Tom
     
  19. Devinco

    Devinco Registered Member

    Joined:
    Jul 2, 2004
    Posts:
    2,524
    Re: Process Guard Suggestions / Wish list

    Could you make it so that the system tray balloon pop ups would let me know on startup that Learning Mode is still on. I sometimes forget to turn it off.

    Thanks
     
  20. Paranoid2000

    Paranoid2000 Registered Member

    Joined:
    May 2, 2004
    Posts:
    2,839
    Location:
    North West, United Kingdom
    Re: Process Guard Suggestions / Wish list

    Speaking of colours, would it be possible to have a blue icon for normal use turning red when there are alerts to view? The current selection seems counter-intuitive.
     
  21. Devinco

    Devinco Registered Member

    Joined:
    Jul 2, 2004
    Posts:
    2,524
    Re: Process Guard Suggestions / Wish list

    Perhaps instead of (or in addition to) the learning mode balloon popup, when in learning mode, the system tray icon could be green.

    It's great that we are now talking about little tiny details instead of major problems isn't it?
     
  22. Paranoid2000

    Paranoid2000 Registered Member

    Joined:
    May 2, 2004
    Posts:
    2,839
    Location:
    North West, United Kingdom
    Re: Process Guard Suggestions / Wish list

    Shhh...we're just trying to lower DiamondCS' guard before ambushing them with some real corkers. :D
     
  23. Paranoid2000

    Paranoid2000 Registered Member

    Joined:
    May 2, 2004
    Posts:
    2,839
    Location:
    North West, United Kingdom
    Re: Process Guard Suggestions / Wish list

    Hmmm...just thought of one - if an executable is changed, conventional wisdom suggests running a scan on it. How about adding a scan option in PG's Execution Protection dialogue which would check the file using any installed AV/AT scanners? Scanner details would have to be entered separately but this could be a handy convenience feature for those running multiple on-demand scanners.
     
  24. Notok

    Notok Registered Member

    Joined:
    May 28, 2004
    Posts:
    2,969
    Location:
    Portland, OR (USA)
    Re: Process Guard Suggestions / Wish list

    I like that idea a lot.
     
  25. frogfoot

    frogfoot Registered Member

    Joined:
    Aug 8, 2004
    Posts:
    116
    Location:
    Yeovil UK
    Re: Process Guard Suggestions / Wish list

    Taking this one stage further you could optionaly automaticaly call TDS3/4 from PG when a new or changed executable is run (assuming it is installed) this would remove the need for execution protection, which checks every executable however many times it is run, which has a perfomance hit on my system.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.