Total Visitors

Saturday, April 17, 2010

Comodo Internet Security v4




Comodo released its security suite(Comodo internet security) their v4 a month before and is drastically improved from its predecessor v3. The v3 was said to produce too many false positives and also its HIPS functionality was also quite annoying. It irritated users with its endless pop-ups but that was past. Here is the new version of comodo they got rid of the useless HIPS no one ever wanted. And replaced it with a much better solution sandbox. And it is not others do it. They opted for a more unique approach which actually works for a change. The working is like if the application is trusted, it works in unrestricted mode. If the application is unknown, it automatically runs it in sandbox until tested to be safe. And sandbox is not a very slow emulated environment. Everything runs on host level with host performance. It's just that Comodo restricts certain stuff to the application run through sandbox.

I am currently trying comodo v4 it can be downloaded from here comodo gives hell of free products(You can browse their site and check) but as my discussions is of only CIS so i'll focus on CIS only. The installer size is about 60MB plus the additional download of signature updates after installation which is about 85MB. Yeah the signature size is quite large but the comodo team is working on it. Actually they already have compacted their virus databases i still remember when i installed v3 i downloaded more than 100MB of virus database updates. So only time will take to trim down the size of virus database without losing its detection ability.

When installation is started the user is prompted to install standalone Firewall or Antivirus or the entire suite. Comodo is one of the few suites that provide tons of features for free. By default all the features are installed viz..
  1. Antivirus : For detection of known as well as unknown malwares. Comodo's AV part is still new and needs some work on the detection part. It detects high percentage of false positives.
  2. Firewall : It is considered as one of the best FREE firewalls out there on net.
  3. Defense+ : The best part of comodo v3 included in v4 also but notable difference it that it included sandbox which is really good and doesn't have much of impact on system performance.
I tested 20 zero day threats against comodo and it was able to detect 14 (i.e. by the AV part) while the undetected were automatically placed in sandbox(Defense+ part) on execution so I can say that I had a clean system after testing comodo against these threats which is really a good sign as no AV can detect 100% so layered approach is preferred like even those 6 threats were undetected by comodo it made sure that those undetected were placed in sandbox while execution.

But the main demerit of comodo is still is high percentage of False +ves like it detected Malware Defender beta02 and 03 installer as Heur.Suspious.

Bottomline: Comodo offers a great free product which has all the necessary requirements to be one of the top competitors. I would advice it to give it a try you won't be disappointed with it.

2 comments:

  1. bad Av try norton instead it is much better than comodo!!!!!!

    ReplyDelete
  2. nice review!!!! i will try comodo

    ReplyDelete