Ответ: Статьи, обзоры, новости, ...
CORE FORCE
CORE FORCE is the first community oriented security solution for personal computers. CORE
FORCE is free and can be installed in computers using Windows 2000 or Windows XP, and
provides a framework than combines a host-based Intrusion Prevention System (H-IPS) with a
powerful personal firewall. This security framework is leveraged by a community of security ex-
perts that share their security configurations for a growing list of programs. These security profiles
can be downloaded by any user of CORE FORCE from the community website and they're also
completely open so that they can be peer-reviewed to minimize security hazards. The community
approach to endpoint security also allows end-users who are no security experts to work in a secure
environment.
COREFORCEcanbeusedto:
• Protectyourcomputerfrom compromisebyworms,virusandemail-bornemalware
• Prevent you computer from being used as a staging point to amplify attacks and compromise
others
• Prevent exploitation of known bugs in the operating system and applications running on your
computer
• Prevent exploitation of unknown bugs (0-day) in the operating system and applications running
onyourcomputer.
• Detect and prevent execution of adware, spyware, trojan horses and other malware on you com-
puter
The product provides inbound and outbound stateful packet filtering for TCP/IP protocols, granular
file system and registry access control and programs' integrity validation. These capabilities can be
configured and enforced system-wide or on a per-application basis for specific programs such as
emailreaders,webbrowsers,mediaplayers,messagingsoftware,etc.
CORE FORCE Architecture
CORE FORCE is implemented by security modules that provide different aspects of the security
framework. These modules are implemented as system drivers that work in kernel mode to provide
the highest level of protection to protected resources. A centralized administrative console allows
users to configure all permissions for the computer and to interact with CORE FORCE Community
todownloadsecurityprofilesandupdates,andsharethemtootheruserstoo.
Firewall
The firewall component of CORE FORCE is a Windows port of OpenBSD's PF, the open source,
mature, server-level firewall (PF: The OpenBSD Packet Filter [
You must be registered for see links
.
ThePFfunctionalityhasbeentrimmedandtailoredtomakeitsuitablefordesktopsystems.
CORE FORCE support inbound and outbound stateful filtering with advanced settings such as TCP
flags and ICMP type/code flags. It works on a per application basis, loading and unloading rules dy-
namically at application runtime and it can be configured to require runtime user confirmation on
certain connections. It is implemented at kernel level as an intermediate driver that mediates com-
munications between the network card drivers and the operating system's TCP/IP protocol stack,
makingitverydifficulttobypass.
Filesystem and Registry
The file system and registry access control component of CORE FORCE is implemented as a file
systemfilterthatmediatescommunicationbetweentheoperatingsystemandfile-systemsdrivers.
The component runs at kernel level and captures file system and registry access operations per-
formed by the rest of the operating system (user-level applications, services and kernel subsystems)
and enforces permissions for create, read, write, execute, delete and list operations. Due to its loca-
tion inside the operating system, it can traps calls to any filesystem, and even calls made by other
kernel components. The filesystem permissions can be specified using wildcards and specifying
whetherasubfolderinheritstheconfigurationfromitsparent.
(вобщем бесплатный фаерфол для windows на основе pf из openbsd )
You must be registered for see links
You must be registered for see links
You must be registered for see links