D
Deleted member 178
Thread author
AppGuard Technology is client security software that blocks malware attacks, preventing harm when end
users:
• Browse Hacked/Malicious Websites
• Open Malicious Email Attachments
• Insert Infected USB Drives
• Open Tainted Documents (pdf, xls, doc, etc.)
• Played Spiked Multimedia Files (jpg, avi, wmv, etc.)
• Run UnPatched Software
AppGuard Technology employs a different approach from that of legacy defenses, which rely on signatures to identify incoming malware. In principle, this signaturebased approach does not trust the practically infinite variety of files and communications of a computer. AppGuard Technology, on the other hand, does not trust the applications that process these files and communications. It blocks write operations by these applications to system and application resources as wells as prevents unknown applications from launching from user-space or USB drives. Further, AppGuard Technology differs from other technologies that counter zero-day malware attacks, which rely on heuristics, protocol filtering, and extensive rule-sets. Instead, users merely need to identify any applications by name that are not already guarded by default. Careful attention has been devoted to striking a balance between usability and security
http://ww1.prweb.com/prfiles/2010/05/11/1052624/AppGuardTechWhitePaper.pdf
old documentation but still valid
note this about HIPS:
To spare end-users, HIPS administrators must devote considerable effort to fine-tune the HIPS to these application idiosyncrasies and tune-out the mountains of false positives generated. With every application update and patch, however, administrators must re-tune.
HIPS vendors try to simplify this by providing default settings for the operating system and some of the applications typically found. However, HIPS products are considerably less effective with default settings than with finely tuned settings by a professional.
The HIPS concept failed because of a fundamental lack of prioritization and upfront focus on usability.