- Nokia's new N97 vs. the iPhone
- 10 Microsoft research projects
- Hard to get justice in MySpace case
- Smartphone smackdown: Storm vs. iPhone
- Apple removes antivirus support page
|
|||||||
A new category of antimalware tools has emerged, neither gateway tool nor desktop cleaner. This approach manipulates executable file permissions to actively allow, deny or limit the running of any computer program.
Instead of trying to recognize malware, this approach uses whitelists, blacklists and policies to set Windows permissions for executables, even if logged in as an administrator. SecureWave's Sanctuary, Green Border Technologies' GreenBorder Pro, Savant Protection and Winternals Software's Protection Manager are some products in this category.
For example, Protection Manager (starts at $25 per managed computer) uses Windows privilege levels to deny the running of an unknown application, run a known application with reduced privileges, or allow an application full access to files/directories, including operating system directories. Letting a program run at a lower privilege level denies the program access to Windows system directories and files, for example.
Doing this lets you allow Microsoft Word to have free access to all directories except system directories. Beyond whitelists, Protection Manager works "on demand" to let users dynamically adjust an application's privileges, or (if desired) stop an application.
When a user unwittingly clicks on a Web page link that downloads malware on a machine protected by the software, Protection Manager intercepts the launch of the malware and prevents it from running. Protection Manager features can be managed from a central location, and it integrates with Active Directory to let administrators easily protect whole groups of users in one fell swoop.
Microsoft was so impressed with Protection Manager that it bought the Winternals Software company.
< Previous: Zero-latency approach gives FaceTime edge | Next: Still no 'malware' definition >
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment