09-24-2008 02:08 PM
Can someone (finally) explain what this is/does, and if NIS2009 has it. I've read that most new suites have it, but sometimes it is off by default. What's the status with HIPS and NIS2009? There seems to be a lot of talk about it, but I must have missed all the explanatory posts.
Thanks.
Solved! Go to Solution.
09-24-2008
02:45 PM
- last edited on
09-24-2008
03:57 PM
by
Tony_Weiss
Hi Deuceswild,
I work on the team that builds the Behavioral Detection engines and HIPS is a big part of that.
Simply put, HIPS (Host-based Intrusion Prevention System) engines monitor all applications running on the machine for suspicious behaviors. Some examples of suspicious behaviors are "Writing to the run key", "Registering a BHO",
"Modifying the etc/hosts files" etc. Most HIPS products will simply popup an alert telling the user that "application XYZ is writing to the RUN key. Allow or Block ?" The user then makes a decision and as you can imagine, more users aren't in a position to make this decision correctly.
NIS2009 has a smart HIPS technology where it will look at all the behaviors of the applications and run certain heuristics on the application to determine if its a good application or a malicious application. If found to be malicious, it will automatically remove the application from the machine without prompting the user with these difficult-to-answer questions. This technology is called SONAR.
SONAR is ON by default in both NIS and NAV 2009 on XP 32-bit and Vista 32-bit. If you have Vista 64-bit, please see this post from Dave Cole for more information:
http://community.norton.com/norton/board/message?b
Hope this helps.
Shane.
09-24-2008 02:55 PM
Shane,
That was nicely worded, informative and easy to understand.
Thanks!
Norton 360 • Norton Internet Security • Norton Zone | XP SP3 • Windows 7 Professional SP1 x64
• PLEASE, BACKUP or EXPORT your Identity Safe Data on a regular basis •
09-24-2008 06:22 PM
I agree. Didn't really expect that much- but I do appreciate the explanation in everyday words. I would give it more kudos if I could. I think he just sold a copy of NIS2009.
Thank you very much Shane.
09-24-2008 06:34 PM
I love NIS but it fails alot of HIPS tests. I was running Threatfire along side NIS and now I pass the tests but since have uninstalled Threatfire. Here are 2 tests. HIPS is where NIS needs to improve on.
http://zeroday-software.110mb.com/
http://www.syssafety.com/leaktests.html
09-24-2008 07:32 PM
09-25-2008 09:07 PM
I just added Mamutu along side NIS 2009 and its a good match. Mamutu is alot better then Threatfire.
http://www.emsisoft.com/en/software/mamutu/
09-26-2008 11:01 AM
09-26-2008 11:28 AM
I would highly suggest NIS 2009. I believe it to be the most comprehensive security suite on the market and I do not use any companion products with it.
I have used Norton Products for many years and have never been infected.
And, if you ever have any questions, you will always get good support here on the very active Norton Community Forums.
Who else can offer all of that?
Norton 360 • Norton Internet Security • Norton Zone | XP SP3 • Windows 7 Professional SP1 x64
• PLEASE, BACKUP or EXPORT your Identity Safe Data on a regular basis •
09-26-2008 11:34 AM
Phil_D wrote:I would highly suggest NIS 2009. I believe it to be the most comprehensive security suite on the market and I do not use any companion products with it.
I have used Norton Products for many years and have never been infected.
And, if you ever have any questions, you will always get good support here on the very active Norton Community Forums.
Who else can offer all of that?
Yeah; N.I.S. 2009 is a great Product; it is one of the best - if not the best because it has added features as well as lots of V.D.s Updates so you are always going to be Secure - Anti-Virus Product out there. I have to say, that I do not like one particulat feature in it which is Background Tasks as there should be more Options in the Settings section. But yeah, it is a great Product and I would not go with any other one. Another advantage is how light it is on the system.
