New Update Download Sentinel improved functionality new versions

@LinuxFan58
Maybe i am silly:oops:, but with this 2.0.1 version i've always the alert after downloading the file (no the purpose of DS), so the downloaded file is already on my desktop before being checked, and no go back option!!!!.
Forget my ignorance if am mistaken.
 
@Sampei.Nihira

When you encounter unexpected results, please share the links and explain what you expected and why.

Import and export is on the listm but let us first try to get the core functionality right. It is a fine balence between FP's and FN's

This isn't unexpected, they behave differently from DS 1.6.;)
Anyway, that was just a suggestion on my part.
It’s not my intention to change the extension’s operating procedures as established by the developer.(y)

You’ve probably also noticed that it’s not possible to post links to malware-containing content because they’re removed by the moderators.

And I don’t want to notify you about them via PM because such links are often short-lived, and also because I’m currently busy containing,as an outside player,potential threats related to tourism but especially to increased migration flows.

Best regards.;)
 
  • Like
Reactions: LinuxFan58
@LinuxFan58
Maybe i am silly:oops:, but with this 2.0.1 version i've always the alert after downloading the file (no the purpose of DS), so the downloaded file is already on my desktop before being checked, and no go back option!!!!.
Forget my ignorance if am mistaken.
Yes it is post download, because that is the only way I can surpress warnings for clean VT results. Also very small downloads arrive on disk before VT results are returning.
 
@Shadowra thanks to @Sampei.Nihira I added a new heuristic (post download) in version 2.2

Also Trident offered some integration, but he is busy on a contract at the moment (we are investigating whether it is possible to use his advanced malware testing environment when Virus Total does not know the download. Off course this has all kinds of hurdles (ranging from server costs to seamless user handover)

1784218946050.png


Thanks Sampei-san (y)(y)(y)
 
I could have done this yesterday, but I waited until today to run this download test using Download Sentinel 2.4.0:

0.png

False Positive Reduction = Medium

1.png

False Positive Reduction = Low

2.png

It would probably be best to set the default value to “Low.”
When will version 2.4.0 be available on CWS?

P.S.

Could it be that the download of each file is taking too long?:unsure:
 
  • Like
Reactions: piquiteco
@LinuxFan58

I'm just curious,does DS also protect the installation of extensions from CWS?:unsure:
No Chrome Webstore is on the whitelist. I could add an option to disable internal whitelist, since it now only has a the webstores of Google, Apple and M$ now. Or remove whitelist completely.


About the download taking long, there is 2 or 3 second wait for the VT-results to return.

Default level set to medium for default, because average users won´t be downloading from URL Hause like you do :-) For your use case, low is indeed the better option (that is why you can adjust it).

I have no idea why it is taking so long. Last time it took so long people had reported it as suspicious and some one suggested it infringed copy rights. May be my dear second best forum friends (Statler and Waldorf, who left the forum) are getting their revenge :)
 
Last edited:
@LinuxFan58

I don't think, as you wrote elsewhere, that a review is necessary to speed up the release of a new version of the extensions.
APIVoid Browser Protection doesn't have any reviews, yet the extension is up to date as of today.

It's certainly something different.;)
 
won´t be touching them until they are published. On teh other hand the thursday before I went to BosPop (3 day pop-funk-rock festival) I posted them for publishing and saterday evening theyr were pubished. I asked Chat and Cloaud and Gemini, but they tell me backlog of three days to two weeks is normal for non established developers (amateur like me). Patience is a virtue. :)

1784554211816.png
 
Yes ! 2.4 aviable in store
1784632447370.png


What is new

1. Improved heuristics (thanks to @Sampei.Nihira )
2. Shortened build-in whitelist to only webstores (also thanks to Sampei-San)
3. When download URL is unknown it offers to check download at Hybrid-Analysis.com (Crowdstrike + MetaDefender)
a) Ignore email entry (works without it)
b) choose quick scan (Crowdstrike + MetaDefender)
c) upload file

@Shadowra next time when you test URL protection (although this is only download warning when a possible harmful file is downloaded = post download warning), maybe you could include download sentinel. The testing by MT-members improved heuristics a lot, so I am very interested in false negatives and false positives.
 
Last edited:
It's interesting to note how DS 2.4.0 evaluates its own ZIP file downloaded from GitHub
False Positive Reduction = Medium


1.png


but it seems the same to me at Low.
@LinuxFan58 I think this warrants your attention.;):)
 
There are some “important” domains that can spread malware, where Google Safe Browsing and protective DNS seem to have little to no effect.
This is the case with the domain below:

0.png

With this link, even a configured DownloadRestrictions policy proves ineffective at blocking it, at least at this point in time.

Osprey blocks the URL, as you can see in the image below, solely thanks to the Urlhaus PP:

2.png

But in this case, the "Online Malicious URL Blocklist" also steps in to provide protection.;)(y)
Almost certainly with more reliable performance in non-MV3 ad blockers.

How does DownloadSentinel behave?

Whether False Positive Reduction is set to Low or Medium, this is the warning displayed to the user:

1.png

;)
 
Yes ! 2.4 aviable in store
View attachment 298949

What is new

1. Improved heuristics (thanks to @Sampei.Nihira )
2. Shortened build-in whitelist to only webstores (also thanks to Sampei-San)
3. When download URL is unknown it offers to check download at Hybrid-Analysis.com (Crowdstrike + MetaDefender)
a) Ignore email entry (works without it)
b) choose quick scan (Crowdstrike + MetaDefender)
c) upload file

@Shadowra next time when you test URL protection (although this is only download warning when a possible harmful file is downloaded = post download warning), maybe you could include download sentinel. The testing by MT-members improved heuristics a lot, so I am very interested in false negatives and false positives.

Based on the report I sent you in a PM, I'll be making a video about Sentinel next week! ;)
 
Whether False Positive Reduction is set to Low or Medium, this is the warning displayed to the user:
False Positive Reduction is for VT-results not for heuristics. The heuristics are factual observations and each suspicious signal is translated to a negative score (e.g. changing file type between On-download and Write to disk is more suspicious than downloading something from github raw or google cloud, Sketchy URL weighs more than a longer domain name this.is,an-example,com, etcetera) When there is an heuristics observation only, the strict calculation is applied, when VT info is available the loose calculation). That is why it classifies its own download from Githun as inclonclusive (mixed signals) and rates it as probably suspicious, to stimulate the user to run a check at Hybrid Analysis. Because the program is not yet trying to install or execute, the effects of a False Positives are zero (only some user time and energy). That is why Download Sentinel applies a ¨better be safe than sorry" approach (in regard to heuristics with no VT-info).