SB: mal-warning

Ideas for enhancements to the software
Post Reply
TiAMAT

SB: mal-warning

Post by TiAMAT » Fri Jan 02, 2009 2:19 am

Hi ppl,
I know the purpose of the Software, but I still would like seeing a warning when something wrong is going on.
I'm not talking 'bout built-in AV or HiPS, but simply a warning about something wrong done explicitly and intentionally.
Maybe as a plug-in would do?
Regards,

dynarx
Posts: 174
Joined: Mon Apr 02, 2007 9:31 pm
Location: New South Wales, Australia

Post by dynarx » Fri Jan 02, 2009 7:08 am

Define 'wrong'. Not easy? There's your problem!

How can software give a warning when it doesn't analyse or discriminate, it simply protects?

You would be well advised to use other malware detection software in conjunction with SB if you want analysis.

Cheers,
D

RE>

Post by RE> » Fri Jan 02, 2009 9:56 am

It's no problem and quite simple:
- anything that can compromise the overall system performance is a bad thing (BIOS/video/ROM flashing);
- anything that does something user doesn't expect it to (system drivers re-configuration, autoloading, replacing vital data and accessing protected storage etc)

I also think it could be handy to warn a user that the program he runs is not so simple. Probably some rating-system would also be nice.
Antiviruses? In this very case they just cause problems and merely halt threads/processes.
___________________________________
It's not so trivial but if (when?) Tzuk implements it then most users will feel more informed and secured IMHO.

MitchE323
Posts: 2268
Joined: Thu Nov 02, 2006 9:32 am

Post by MitchE323 » Fri Jan 02, 2009 10:29 am

So ..... a logging method on steroids? Why don't you just open the Resource Access Monitor as you begin and surf till your hearts content? :D

tzuk
Sandboxie Founder
Sandboxie Founder
Posts: 16076
Joined: Tue Jun 22, 2004 12:57 pm

Post by tzuk » Fri Jan 02, 2009 11:16 am

if (when?) Tzuk implements it then most users will feel more informed and secured IMHO.
I disagree. It is somewhere between very hard and not possible to correctly identify 'bad actions' by software. Which is why most HIPS software throw so many warnings -- they just can't tell if the action comes from well-meaning software or from malicious software.

So if you like these kind of notifcations, there are many HIPS software that can serve that purpose, but this concept has no place in Sandboxie.
tzuk

NINOR

Post by NINOR » Sat Jan 03, 2009 1:12 am

I think tzuk is right that it would be not so easy.
Though it can check its container for suspicious activity and so on but atm it needs 'smart' supervising from the one who knows. And if he knows he needs no warning, right?
I also see the point from TIAMAT - a little pre/caution can help user to be more careful with the software.
So, just stay sensible ;)
Cheers.

Buster
Posts: 2576
Joined: Mon Aug 06, 2007 2:38 pm
Contact:

Re: SB: mal-warning

Post by Buster » Sat Jan 03, 2009 3:23 am

TiAMAT wrote:Hi ppl,
I know the purpose of the Software, but I still would like seeing a warning when something wrong is going on.
I'm not talking 'bout built-in AV or HiPS, but simply a warning about something wrong done explicitly and intentionally.
Maybe as a plug-in would do?
Regards,
Malwares usually writes to registry and drop files in Windows folder, exactly the same as any other legit software, therefore the concept of "wrong done explictly and intentionally" is too vague.

You may try Eset´s SysInspector. Maybe it´s what you are looking for.

http://www.eset.com/download/sysinspector.php

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest