顯示包含「沙盤」標籤的文章。顯示所有文章
顯示包含「沙盤」標籤的文章。顯示所有文章

2011年2月21日星期一

Avast 6.0 beta 試用

Avast 6.0 已推出第二版 beta,修正了第一版大部份的臭蟲,便下載來試試。

Avast 6.0 免費版也加入不少新功能或強化了原有功能,官方公佈如下︰
- AutoSandbox – suspicious programs will be optionally run sandboxed
- avast! WebRep – browser plugin for website reputation rating
- Script Shield now even in the Free AV
- Site Blocking now even in the Free AV
- Restore factory settings command (Settings -> Troubleshooting)
- Automatic actions in the boot-time scan
- New compression method in the installer makes the setup packages about 20% smaller.
- Script Shield now functional even with IE8/IE9 Protected Mode
- Sidebar gadget
- Improved stability/compatibility of the Behavior Shield
- Improvements in the avast! sandbox

注意安裝 6.0 前要先移除原有 5.x 版,安裝時已提供繁中選項,安裝後也如前版要程式註冊。

新版介面並沒有大改變

免費版加入了原付費版有的腳本防護功能


其他防護下可以找到 6.0 的新功能-全自動沙盒、網頁信譽評價及站台封鎖

全自動沙盒
網頁信譽評價
部台封鎖

新的全自動沙盒會將可疑的應用程式開啟時自動移到沙盒內執行﹐不過預設會有警告示窗彈出,詢問用戶是否確定程式在沙盒內執行,若是用戶已知的安全程式,可以選擇不在沙盒內執行。
沙盒警告示窗

用戶可以在警告示窗勾選記住程式的沙盒設定,也可以在沙盒的設定視窗加入排除檔案。

自動沙盒只提供簡單的設定

網頁信譽評價會在瀏覽器的工具列上加入小圖示顯示正在瀏覽的網頁是否安全,按一下小圖會彈出評價視窗讓用戶反影對網頁評價,可以看到這部份還未中文化。

網頁信譽評價視窗


新版也提供桌面小工具,不過用處不大,功能似乎跟原有小圖示重疊。

桌面小工具
試用感想
1. Avast 6.0 維持原有佔用資源少及不大影响電腦效能的好處
2. 免費版可享原有收費版的功能,防護有所加強
3. 個人一直以 Comodo 防火牆配合 Avast 使用,Avast 新版的沙盒及加強了的行為防護跟 Comodo 的功能有所重疊,試用時 Avast 沙盒內的程式可用性似乎比 Comodo 沙盒差,Avast 沙盒中的 Q-Dir 就不能抄擋案,Avast 的白明單似乎也比 Comodo 的少,所以之前試用行為防護時有些不必要的彈窗,所以個人選擇不安裝 Avast 的行為防護,不過也可能是本人常的程式比較配合 Comodo,用戶可以自行試試那一個程式的沙盒及行為防護會較合用
4. 試用了一天,beta 版暫時沒有特別問題

官方論壇介紹

免費版下載連結
http://files.avast.com/files/beta/6.0.986/setup_av_free.exe

2010年9月15日星期三

Comodo Internet Security 2011 (ver. 5) 正式推出

有以下新工能及改善

1. 防火牆加入雲測毒 (就算不安娤防毒模組也會檢測要執行的程式)
2. 加入行分析防護
3. 自動檢測不明程式,若在雲白名單(cloud white-listing)會自動把檔案加入本地白名單
4. Game Mode
5. 改善沙盤的兼容性
6. 加強除清毒功能

繁體中文化檔案

官網介紹

What's New In COMODO Internet Security 2011?

THANKS! COMODO would like to thank the beta testers whose feedback made this release possible!

NEW! Extended spyware scanner and improved malware cleaning
NEW! Cloud Based Antivirus Scanning
NEW! Cloud Based Behavior Analysis
NEW! Cloud Based Application White-listing
NEW! Game Mode
IMPROVED! Application Control
IMPROVED! Default Deny re-engineered to improve application compatibility
IMPROVED! Application user interface

Cloud Based Infrastructure:

2011 family of products(Yes COMODO Firewall too!) are now armed with cloud based file rating technologies. The cloud computation, enabled by default, is used for a variety of purposes.(Do not be surprized if COMODO Firewall gives you a malware alert!!!).

With cloud computation;

Cloud based Whitelisting: Safe files and trusted vendors are now easily identified. The concept of “Trusted Publisher” is now cloud based.

Cloud based Anti virus: Malicious files are detected even if the users do not have an up-to-date antivirus product or an antivirus product at all.

Cloud Based Behaviour Analysis: Zero-day malware can be detected INSTANTLY by COMODO’s cloud based behavior analysis system CIMA(Comodo Instant Malware analysis).

Extended Spyware Scanning

COMODO’s vision and focus has been about “keeping a clean computer clean” from early days. Now that We have achieved that COMODO is focusing on “cleaning an already infected computer”. This is why we extended the spyware scanning in COMODO Internet Security 2011 and COMODO Antivirus 2011 and now include a new spyware scanner which is capable of scanning the windows registry and computer disks for the signs of malware infection.

This new scanner is implemented to improve the detection and successful cleaning rate of already infected systems.

Game Mode

2011 family of products are now gamer friendly security applications. When they are put into the game mode, the operations that can interfere with users’ gaming experience such as alerts or resource intensive virus database updates, scheduled scans are suppressed.

Stronger and Smarter Application Control

2011 family of products have a highly smart application control mechanism which extends the functionality of the previous versions.

The new application control provides the users the ability to lockdown their computers such that only the known good applications can be executed.

The new sandbox introduces a new default application isolation level, partially limited, which improves the compatibility with many windows products.

Nowadays, a lot of malware come in other forms than standalone executables. For example, some come in the form of visual basic scripts while some come in the form of java binaries. When they come in such forms, they are executed by “interpreter” applications such as wscript.exe or java.exe etc.

2011 family of products can identify such applications heuristically and detect the real file behind the requests of “interpreters”.

2010年8月1日星期日

Comodo Internet Security 5 beta 推出

Comodo 推出 CIS 5(或稱 CIS 2011)測試版,試用了一下,介面作出了較大改變,但主要操作方法沒有太大改變,舊用戶應該不難適應。

似乎內建白名單也加大了,一些以前認不出的程式現在也能自動識別,使用上更方便。


下載網頁
COMODO Internet Security 5.0.156985.1061 BETA Released

已經有人開始制作繁體中文語系檔案

官網介紹
NEW! Application Whitelisting
CIS 5.x fills the missing links that its predecessors had in this area by providing a usable application white list control.

NEW! Spyware Scanner and improved malware cleaning
CIS 5.x again fulfills the missing features of its predecessors by providing a new spyware scanner which is capable of scanning the windows registry and file system.

Note: We will be releasing the signatures for spyware scanning during the course of BETA testing. So you might not immeidately see this in action. i.e. next monday

NEW! Cloud Based Antivirus Scanning
CIS 5.x has integrated the cloud based computation everywhere. From on-demand scanning to process execution control, it checks if the file is known in the cloud.

NEW! Cloud Based Behavior Analysis
Instant malware analysis has been introduced to CIS 5.x making detection of unknown malware possible! Any unknown file that is sandboxed and NOT observed by COMODO before is submitted to CAMAS and results are sent to the PC in 15 minutes after the upload process is done.

NEW! Game Mode
Now CIS has a game mode. Just before you start to play a game, you can switch to game mode and all the alerts will be suppressed. Virus database updates or schedules scans will also be postponed.

IMPROVED! Default Deny re-engineered to improve application compatibility
Unlike CIS 4.x, CIS 5.x, by default, automatically runs every unknown executable as "Partially Limited", which is a new level introduced with CIS 5.x.

IMPROVED! A New User Interface!
You will be seeing a lot of suprises with the new user interface. It is friendlier, easier and prettier.

2010年4月19日星期一

沙盤防護軟件 Sandboxie 及 GeSWall

除了防火牆、防毒、HIPS等軟件,還有「沙盤」類軟件可以防止病毒程式危害電腦。「沙盤」類軟件的基本原理是在你的電腦上再建立一個相對獨立的虛擬環境,在虛擬環境內運行的程式並不會影响原電腦上的文件,它們的原理跟 Virtual PC 有點相似,可以說是類 Virtual PC 的方案但又未有像 Virtual PC 般差不多完全給隔離出 host 電腦的環境,因此它們使用上比較方便,如在接收郵件,上網等都可以像一般使用時打開應用程式便可。

最出名的「沙盤」軟件可以說是 Sandboxie ,若只是要應用在上網,安裝後便可以經 Sandboxie 打開你用開的瀏覽器,就算瀏覽一些有害網站,它只會影响到瀏覽器所在的虛擬環境,當關閉瀏覽器及 Sandboxie,所有虛擬環境中的改變不會保留,因此那些有害網站便不會入侵及損害到原電腦。

在沙盤中開啟的 Firefox

一般來說沙盤內程式建立或修改過的檔案會存在沙盤中


試用沙盤來上網,開 Outlook 接收郵件,軟件的基本工能沒有大影响,接收的郵件也可以保留,下載的檔案也可以從沙盤裡儲存保留到硬碟。初用時設定不全善時,在瀏覽器修改的個人化設定並不能保存下來,簡單如書籤改名也不可以,所以個人覺得用沙盤來執行可疑或要上網的應用程式還好,作為其他日常應用就比較煩。

基於以上原因,有應用程式如 GeSWall 可設定半虛擬的環境,受監控的程式只可以修改及使用認可的資源如程式本身的設定檔或要應用到的檔案,沒有預先認可的只可以如沙盤環境中作暫時的改變,因此「理論上」,它可以避免使用沙盤的麻煩同時有沙盤保護的效果,個人都有試用 GeSWall,它沒有影响到防毒軟件的運作,瀏覽器的個人化設定也能保存下來,但它的設定也比較煩,GeSWall 免費版只預設一般瀏覽器的設定,其它如電郵軟件的設定要自已加上,試了許多時間也不能好好的使 Outlook 正常運作,所以最後只用它來監控瀏覽器。

GeSWall 監控 Firefox


沙盤官方網站
http://www.sandboxie.com/

GeSWall 官方網站
http://www.gentlesecurity.com/