Author Topic: Autosandbox request to developers  (Read 3406 times)

0 Members and 1 Guest are viewing this topic.

Tgell

  • Guest
Autosandbox request to developers
« on: February 27, 2012, 05:38:34 PM »
I really like the autosandbox feature in avast! 6 but after reading the problems with portable apps and other files like explorer.exe being sandboxed with no input from the user, I will not be installing version 7 until it at least has an ask function.  Why was ask removed? Please reinstate it or is it impossible because of the new code? If a person removes autosandbox from avast 7, how much does this affect detection of malware?

Thank you.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Autosandbox request to developers
« Reply #1 on: February 27, 2012, 05:41:55 PM »
I will not be installing version 7 until it at least has an ask function.

It has that, I'm using it. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline BTIsaac

  • Full Member
  • ***
  • Posts: 100
Re: Autosandbox request to developers
« Reply #2 on: February 27, 2012, 06:21:09 PM »
Or you could, you know, install version 7 and disable autosandbox.

FlyingRobot

  • Guest
Re: Autosandbox request to developers
« Reply #3 on: February 27, 2012, 08:34:50 PM »
Perhaps the OP saw the messages about the ask feature going to be removed in future builds?  Such as: http://forum.avast.com/index.php?topic=93866.msg747953#msg747953 ?

buffy_92

  • Guest
Re: Autosandbox request to developers
« Reply #4 on: February 27, 2012, 09:54:03 PM »
i have the same problem:(
« Last Edit: February 27, 2012, 10:12:30 PM by buffy_92 »

Tgell

  • Guest
Re: Autosandbox request to developers
« Reply #5 on: February 27, 2012, 11:37:09 PM »
Perhaps the OP saw the messages about the ask feature going to be removed in future builds?  Such as: http://forum.avast.com/index.php?topic=93866.msg747953#msg747953 ?

Yes, that is what I am worried about, ask going away. I guess I will have to disable autosandbox. Wish they would keep ask.

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Autosandbox request to developers
« Reply #6 on: February 27, 2012, 11:53:36 PM »
Let me explain in a bit more detail what we're trying to do here.

First, a little bit of background information. We introduced the Autosandbox feature in v6 as a way to cope with suspicious programs. Traditionally, AV software had to make binary decisions: either call a file clean (and then let it run on users' machines) or call it infected (and deal with it, i.e. typically quarantine/delete the file). The autosandbox gave us the possibility to let the file run, but without risking that it would do any harm to the system. Therefore, it was a handy tool for our analysts who could relax the heuristic rules without risking too many "hard" false positives.

Now, in v7 (partly in this initial v7 build, and partly in the upcoming builds), we'd like to change this little bit in the following sense:

Instead of "automatically running apps inside the sandbox", we'd like to use the sandboxing subsystem to act more like an extension of the scanner. That is, when the engine isn't sure about a file, it would do the following:
1. Go ahead and run the app in the sandbox (with that "avast is analyzing a suspicious files" dialog; btw this dialog will be augmented with some additional information about the actual reason of why the file looks suspicious)
2. Let it run for a while - but not too long. Typically, kill it after 10-15 seconds (unless it dies on itself before that). While the app is running, collect all the details about what it's doing
3. After that, analyze the logs collected in step 2, and
   a. If it's found malicious, present the user with the usual options like Move to Chest, Delete etc.
   b. If the file isn't found malicious, present the user with options like "Continue launching the program", "Keep this program in the sandbox", "Cancel launching the program".
Also, in this step, give the user actually a way to VIEW the log so that power users can draw their own conclusions.

In my opinion, this is clear step forward and is really user friendly (much more than the v6 implementation). We may also leave the old v6-style mode there, but once the new system works as expected, I don't see any reason why anyone would actually want to switch to it.


I hope this helps.

Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Autosandbox request to developers
« Reply #7 on: February 28, 2012, 12:05:00 AM »
Seems good, a good balance for common and advanced users and a way to decide.
The best things in life are free.

Tgell

  • Guest
Re: Autosandbox request to developers
« Reply #8 on: February 28, 2012, 12:07:28 AM »
Thank you for the clarification Vlk.

Offline Charyb-0

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2508
Re: Autosandbox request to developers
« Reply #9 on: February 28, 2012, 12:24:49 AM »
With Filerep, AutoSandbox, streaming updates, regular def. updates, and WebShield, it sounds tough to penetrate. Once it is fine tuned, I hope to never hear of another person, using avast, with a rogue antivirus install on their computer. Not to mention many all of the other nasties.

The more detailed the sandbox warning and log the better.

FlyingRobot

  • Guest
Re: Autosandbox request to developers
« Reply #10 on: February 28, 2012, 12:59:11 AM »
What are the risks of allowing the (upcoming) autosandbox... what can it break?  I rarely get the ask, and right now I can only remember seeing it in response to manually launching a downloaded standalone program.  I suspect there are no risks there, so that is actually the only type of scenario where I allow the autosandbox.  However, if I were asked about some component of a sophisticated already installed or installing program, I would disallow the autosandboxing in order to minimize the chances that it would hose the application, install, or system (I'm generally more worried about that than malware).  This is why ask appeals to me, although I'm clearly not knowledgeable enough to know how to apply it in the best way.

If the new autosandbox will continue to be a component that can be enabled or disabled, how does one make that decision?