Author Topic: The BEHAVIOR shield  (Read 4005 times)

0 Members and 1 Guest are viewing this topic.

Offline WildWestGuy

  • Jr. Member
  • **
  • Posts: 95
The BEHAVIOR shield
« on: May 02, 2010, 03:25:33 PM »
When will AVAST Behavior Shield Improve??? My SETUP is: Comodo Firewall Free V4.0 with Sandbox and Defense+ and ofc. Avast 5 free(This is my free protection that is REALLY REALLY powerful. So, I have watched many reviews with AVAST IS 5, Pro and free, and they let some stuff through but the Behavior Shirld didnt pop-up. When will you make it powerful? Thanks. :-)
Every man has a right to change, a chance at forgiveness.



Windows 7 x64bit - 8Gb Ram - AVAST! INTERNET SECURITY - IMMUNET PROTECT CLOUD FREE - Wired Connection 800 kb/s

Offline logos

  • Avast Überevangelist
  • Serious Graphoman
  • *****
  • Posts: 9441
Re: The BEHAVIOR shield
« Reply #1 on: May 02, 2010, 03:43:30 PM »
When will AVAST Behavior Shield Improve??? My SETUP is: Comodo Firewall Free V4.0 with Sandbox and Defense+ and ofc. Avast 5 free(This is my free protection that is REALLY REALLY powerful. So, I have watched many reviews with AVAST IS 5, Pro and free, and they let some stuff through but the Behavior Shirld didnt pop-up. When will you make it powerful? Thanks. :-)

1 what stuff was let through?
2 what is the behavior shield?
3 what do you expect it to be?
w7 - ais7

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 85967
  • No support PMs thanks
Re: The BEHAVIOR shield
« Reply #2 on: May 02, 2010, 03:44:48 PM »
The problem is one of interpretation as you believe all behaviour shields,etc. work in the same way.

- avast! Behaviour Shield, general information from an interview Softpedia - Vlk
Quote
Vlk: The Behavior Shield that we shipped in version 5.0 is a new component that is going to be further developed moving forward. For example, in version 5.1, we will be adding more sensors that will allow for even finer-grain filtering.

For now, the Behavior Shield is focused on exploits coming via typical mechanisms (browser, PDF reader, and flash vulnerabilities, for example). It also closely monitors all kernel-mode code (drivers) loaded into the operating system, and is able to detect zero-day rootkits.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 21.9.2494 (build 21.9.6698.703) UI 1.0.672/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bri

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 684
  • U.S.A
Re: The BEHAVIOR shield
« Reply #3 on: May 02, 2010, 06:56:00 PM »
its sounds like and seems to me that the behaior shield is there to pickup exploits and zero day stuff that the avast sigs dont catch,therefore in my opinion the behavoir shield is very weak or in my opinion it doesnt work.needs a ton more work and seems like thats what there doing.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 85967
  • No support PMs thanks
Re: The BEHAVIOR shield
« Reply #4 on: May 02, 2010, 07:21:32 PM »
Well if you check the quote it is more specific than all zero-day stuff, but zero-day rootkits.

The fact is that it doesn't currently fall into what people interpretation/expectation of a behaviour shield to be.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 21.9.2494 (build 21.9.6698.703) UI 1.0.672/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40610
  • Dragons by Sasha
    • Malware fixes
Re: The BEHAVIOR shield
« Reply #5 on: May 02, 2010, 07:36:35 PM »
Mayhap you will not see anything until something tries to penetrate your system

Offline bri

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 684
  • U.S.A
Re: The BEHAVIOR shield
« Reply #6 on: May 02, 2010, 07:44:24 PM »
davidr when i said zero day stuff i meant all malware so rootkits too.all im saying is ive been infected already and not a peep from the behaior shield not one single alert,so therefore to me it doesnt work.at the moment not a biggie for me i use ais sanbox.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 85967
  • No support PMs thanks
Re: The BEHAVIOR shield
« Reply #7 on: May 02, 2010, 08:12:48 PM »
I know what your saying but the problem is behaviour and heuristics are somewhat loose terms. Given Vlk's quote he defines a) what is does now and b) what they are working on. Given that we can't say that it doesn't work as it is limited in what it is doing in 5.0.

Hopefully some additional sensors for the behaviour shield in 5.1 will go some way towards that.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 21.9.2494 (build 21.9.6698.703) UI 1.0.672/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bri

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 684
  • U.S.A
Re: The BEHAVIOR shield
« Reply #8 on: May 02, 2010, 08:55:57 PM »

very well put
i agree,hopefully it will get better and better

I know what your saying but the problem is behaviour and heuristics are somewhat loose terms. Given Vlk's quote he defines a) what is does now and b) what they are working on. Given that we can't say that it doesn't work as it is limited in what it is doing in 5.0.

Hopefully some additional sensors for the behaviour shield in 5.1 will go some way towards that.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67247
Re: The BEHAVIOR shield
« Reply #9 on: May 02, 2010, 10:49:40 PM »
The best things in life are free.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 72963
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: The BEHAVIOR shield
« Reply #10 on: May 02, 2010, 10:53:25 PM »
When will AVAST Behavior Shield Improve???

It starts right now... ;)
asyn

Hi *,
we'll soon be releasing a new build of avast 5 Free/Pro/IS. As usual, we're making the build available for public testing before it's officially released (so far the version number is 5.0.533).

What's new
Most notable improvements include:
•   Improvements in the Behavior Shield (realtime antirootkit part)
Win 8.1 [x64] - Avast PremSec 21.11.6787.IBC [UI.683] - EEK - Firefox ESR 91.4 [NS/uBO/PB] - TB 91.4
Avast-Tools: Secure Browser 96.0 - Cleanup 21.4 - SecureLine 5.14 - Driver Updater 21.4 - CCleaner 5.87
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0