Total Visitors

Saturday, April 17, 2010

Sandboxie : A new layer of Computer Security

The amount malware continued to grow at a record pace throughout 2009, primarily targeting naive computer users . On an average about 35,000 samples of malware are identified everyday the number itself is quite astonishing and it may not be possible that traditional Antivirus database would be able to detect the malware. This are termed as Zero-day threats it is very much difficult for AV to detect these Zero-day threats as their signatures are not updated to identify the malware. Malware has increased in an exponential manner, and the absolutely most persistent threat have been trojans, malicious software designed for stealing sensitive data, installing backdoors, deleting or encrypting files and downloading other malware from the internet. Hence the user's sensitive information is compromised.

Here comes the technology of sandboxing. Technically when you run a program it gets executed in real computer environment but when that same program is sandboxed it runs in an isolated environment and with some restricted privileges. It is similar to that you log on to your computer as Guest and not as admin or your username. Hence program running in isolated environment will be prevented from making changes that could be damaging to a system or which could simply be difficult to revert back.

Sandboxie
It is a freeware and the latest stable version can be downloaded from here.


The main idea behind this program is like it defines a space in your HD and executes the programs within that defined space only(preferably called as sandbox) which prevents them from making permanent changes to other programs and data in user's computer.


The red arrows indicate changes flowing from a running program into user's computer. The box labeled Hard disk (no sandbox) shows changes by a program running normally. The box labeled Hard disk (with sandbox) shows changes by a program running under Sandboxie.

The installer size is small(~1.44MB) the installation is quite easy





By default there will be a new shortcut on desktop named sandboxed web browser on double clicking it your default web browser(Mozilla or Internet Explorer) will be opened.

In order to run a program isolated right click on the program------>Run Sandboxed. When an application is run in sandbox it appears like this [#]Program Name[#]



+ points of sandboxie
  • Safe Web Browsing : Running web browsers in sandbox protects from any malicious changes as the program is in sandbox and hence all the software that is downloaded via this browser is trapped in sandbox.
  • Better Privacy : All the cookies, temporary data, browsing history are in sandbox and don't leak into Windows.
  • Safe Windows : Prevents windows getting corrupted by a certain program as that program is executed in an isolated environment.
  • Easy to use
  • FREE!!
I definitely suggest users to try this program it is easy to use and configure will also keep you protected it is very good when used in an offline computers where Antivirus signatures are not constantly updated. Sandbox is quite new technology but gaining good ground even some of the security vendors try to incorporate this technique so that even if traditional scanning misses some malware still the user is very much protected. For the average user, Sandboxie is preconfigured for optimal protection - no further configuration is needed. Users can access the internet check email and run programs from the start of this program. With the advanced options, it allows you to tweak Sandboxie as needed.

There is a paid version of sandboxie which unlocks all the limitations that are present in free version. In free mode, the program displays a pop-up prompt to register the program once 30 days have expired. In free mode, Sandboxie does not allow the Forced Programs and Forced Folders feature and does not allow for more than one sandbox to be run simultaneously.A lifetime registration for the current version and future versions is only €22 Euros (roughly $30) which is an extremely small price to pay for the security which Sandoxie provides.


To Visitors:
This is my first post in my blog so it might be possible that I may have not covered all the points regarding the topic I have started. I tried my best to make it easy to understand and be precise on the topic. Feel free to suggest any modifications that are required in the post.
Thank You for you time and have a nice day.......

-ISHAN

4 comments: