Poll

Do you want automatic sandboxing (virtualization) to increase avast protection?

Yes. Make it available (on by default, i.e., for all users).
Yes. Make it available (off by default, i.e., for advanced users only).
No, I think the "default allow" policy (signatures, rules, etc.) is enough.
I don't understand the difference (please, post your doubts).
Other (please, post your opinion and why).

Author Topic: The future of avast protection  (Read 185798 times)

0 Members and 2 Guests are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: The future of avast protection
« Reply #240 on: October 15, 2010, 01:32:16 PM »
So, the idea of an automatic (on access) sandbox is not a Comodo-only suggestion?
Are you guys running Norman in virtual machines?
Is there an on demand scanner to test my computer and check the sandbox?
The best things in life are free.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: The future of avast protection
« Reply #241 on: October 15, 2010, 02:12:15 PM »
Quote
So, the idea of an automatic (on access) sandbox is not a Comodo-only suggestion?
Norman was first with sandbox, think it came around 1985

Omid is running it in VM see the signatur, i/we use it at work + one pc at home

Quote
Is there an on demand scanner to test my computer and check the sandbox?
Norman does not have online scanner, only the Sandbox where you can send samples
http://norman.com/security_center/security_tools/submit_file/
http://www.norman.com/security_center/security_tools/71562/71563/en

But there is the Norman Malware Cleaner http://norman.com/support/support_tools/58732/ 
or trails software http://norman.com/downloads/

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: The future of avast protection
« Reply #242 on: October 15, 2010, 02:35:32 PM »
Norman does not have online scanner, only the Sandbox where you can send samples
I see... It's not a batch submission process and you need to test sample by sample.
Is there any difference for virustotal? Code emulation only?
Comodo will do the same, i.e., upload the sample and test it virtualized/sandboxed, then return the answer to the user (15 minutes if it is a malware). It's a way to use the cloud and improve detection. Maybe avast could consider this.

What it's good its Normal zero-day protection then. Do you have further information about it?
The best things in life are free.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: The future of avast protection
« Reply #243 on: October 15, 2010, 03:35:12 PM »
Quote
What it's good its Normal zero-day protection then. Do you have further information about it?
in the middel of the road....

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: The future of avast protection
« Reply #244 on: October 15, 2010, 07:24:19 PM »
in the middel of the road....
??? What do you mean?
The best things in life are free.

Dch48

  • Guest
Re: The future of avast protection
« Reply #245 on: October 15, 2010, 08:21:18 PM »
Why does Norman always get such abysmal ratings from the testing organizations then?

GloobyGoob

  • Guest
Re: The future of avast protection
« Reply #246 on: October 15, 2010, 09:36:32 PM »
Why does Norman always get such abysmal ratings from the testing organizations then?

Because they test the antivirus, not the sandbox.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: The future of avast protection
« Reply #247 on: October 15, 2010, 09:47:11 PM »
Because they test the antivirus, not the sandbox.
Hmmm... So Normal model is the same of Comodo one? A poor antivirus with a good HIPS/Sandbox?
The best things in life are free.

Offline Omid Farhang

  • Frontend Developer
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1660
  • I wish I could write longer personal text!!
    • Homepage
Re: The future of avast protection
« Reply #248 on: October 15, 2010, 11:44:43 PM »
Because they test the antivirus, not the sandbox.
Hmmm... So Normal model is the same of Comodo one? A poor antivirus with a good HIPS/Sandbox?

I'm not an expert Norman user, but I doubt, because it has let many malware to run up to now, like a Zbot today...  ??? , so, is Zbot something which can bypass Norman Sanbox (after on-demand and online scan)? I don't know
Twitter: OmidFarhangEn - OS: Manjaro KDE

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: The future of avast protection
« Reply #249 on: October 15, 2010, 11:53:39 PM »
No AV vendor have found the holy grail to malware detection that will detect 100% ......and it will never happen, as this is an endless arms race

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: The future of avast protection
« Reply #250 on: October 16, 2010, 04:13:08 AM »
I'm not an expert Norman user, but I doubt, because it has let many malware to run up to now, like a Zbot today...  ??? , so, is Zbot something which can bypass Norman Sanbox (after on-demand and online scan)? I don't know
Worse? A poor antivirus and a poor HIPS? I can't believe it is a great technology to receive an award...
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: The future of avast protection
« Reply #251 on: October 16, 2010, 04:14:10 AM »
No AV vendor have found the holy grail to malware detection that will detect 100% ......and it will never happen, as this is an endless arms race
Well, the sandbox could be a way... I know, usability and user friendly could be a problem...
I'm just not convinced to drop arms down...
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: The future of avast protection
« Reply #252 on: October 16, 2010, 09:33:41 PM »
Does avast have signatures for all variants of Zeus? Really?
Trend Micro says it's not enough...

Quote
Trend’s experts, and all the other antivirus companies, have been working on a detection process.
Julius Dizon, research engineer at Trend Micro, concluded: “To properly guard against this threat, conventional antivirus is not sufficient. Both improved detection techniques and proactive blocking of the websites, working together, can protect users.”

What can we users expect of the protection for this dangerous trojan?
Only signatures?

http://www.itpro.co.uk/627748/son-of-zeus-can-sneak-past-antivirus-controls
The best things in life are free.

spg SCOTT

  • Guest
Re: The future of avast protection
« Reply #253 on: October 16, 2010, 09:52:33 PM »
Does avast have signatures for all variants of Zeus? Really?
...

Does anyone?

I think not...we will always be playing catch up...

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: The future of avast protection
« Reply #254 on: October 16, 2010, 10:08:14 PM »
Does anyone?
I think not...we will always be playing catch up...
Precisely. We need something more to protect us nowadays... We can't only rely on reactive policy of signatures (even they're generic ones).
The best things in life are free.