Looking for internet security software

For everything that's not in any way related to PureBasic. General chat etc...
Dare2
Moderator
Moderator
Posts: 3321
Joined: Sat Dec 27, 2003 3:55 am
Location: Great Southern Land

Looking for internet security software

Post by Dare2 »

Specifically I am looking for something that can:
  • Identify processes/threads that are going online.
    Quantify the data volume or bandwidth used by these processes.
    Identify which ports are being used.
    Identify the destination IP address.
    Log the above.
    Report daily (or on a scheduled basis).
(fairly important)

Anything else done is a bonus. Especially sending the electronic equivalent of WMD to selected intruder destinations. :evil:

Does anyone have any links, suggestions or recommendations?

Thanks.
@}--`--,-- A rose by any other name ..
GreenGiant
Enthusiast
Enthusiast
Posts: 252
Joined: Fri Feb 20, 2004 5:43 pm

Post by GreenGiant »

I'm using the free version of zone alarm, which I think does everything except the second one in your list. There is also a payed version which is probably a fair bit more sophisticated. http://www.zonelabs.com/

Edit: This pages shows the differences between the various products. http://www.zonelabs.com/store/content/c ... submit.y=7
Dare2
Moderator
Moderator
Posts: 3321
Joined: Sat Dec 27, 2003 3:55 am
Location: Great Southern Land

Post by Dare2 »

Hi GreenGiant,

Thanks for the link. I will try ZoneAlarm.

I currently use Tiny Personal Firewall which, to date, has done an excellent job.

I am looking for something additional that will passively monitor ports and do some or all of the following: Detect incoming and outgoing connections, identify files and folders and users involved, IP addresses involved, processes/threads involved. Log it. Any intrusion, and any legit, including "heartbeats" from ISP, etc.
@}--`--,-- A rose by any other name ..
GreenGiant
Enthusiast
Enthusiast
Posts: 252
Joined: Fri Feb 20, 2004 5:43 pm

Post by GreenGiant »

The log in zone alarm (can only speak for the free version) gives you the source and destination ip (inclucing port number) of an event, a rating of how serious it is, the protocol it was using (TCP etc), the program causing it if it was outgoing, the action zone alarm took (normally just says blocked) and the source and destination DNS (if it can get them). So not bad for a free program I think.
Fred
Administrator
Administrator
Posts: 18350
Joined: Fri May 17, 2002 4:39 pm
Location: France
Contact:

Post by Fred »

I would suggest Kerio Personnal Firewall which has a very good reputation.
thefool
Always Here
Always Here
Posts: 5875
Joined: Sat Aug 30, 2003 5:58 pm
Location: Denmark

Post by thefool »

I removed Zonealarm, because it want to have the control somewhere i did not want it to have. It blocked more than i would have it to.

so i switched to Kerio Personal Firewall, and i have used that for 3 months, without just a single problem.

so if i should list free firewalls, kerio would be as number 1 and zonealarm as number 2 8)
Codemonger
Enthusiast
Enthusiast
Posts: 384
Joined: Sat May 24, 2003 8:02 pm
Location: Canada
Contact:

Post by Codemonger »

I used to use Tiny Personal Firewall v2.0 It was the best firewall software for personal use because it was free ... anyway 6.0 is out now and I'm sure it has millions of extra features and it's tiny.

http://www.tinysoftware.com/home/tiny2?la=EN
<br>"I deliver Justice, not Mercy"

    - Codemonger, 2004 A.D.
Dare2
Moderator
Moderator
Posts: 3321
Joined: Sat Dec 27, 2003 3:55 am
Location: Great Southern Land

Post by Dare2 »

Hi Guys,

Thanks. I have added ZoneAlarm (so now Tiny and ZA both running) and have downloaded Kerio, will try it later. Tiny has been on my system for zonks, and logging, but misses something. ZA appears to be missing the same thing.

I am really looking for some good sniffers, tracker, intrusion logging, whatever the jargon is, software.

Things like NST and Snort and the gadgetry you get from places like insecure.org.

I want to track actual connections, files transferred, where they went, who (IP or user) put them there or downloaded them again, etc.

I do not want to stop this happening (which might alert some bods) until I have enough info to act on a number of fronts.

Thanks for any other links, ideas, etc.
@}--`--,-- A rose by any other name ..
thefool
Always Here
Always Here
Posts: 5875
Joined: Sat Aug 30, 2003 5:58 pm
Location: Denmark

Post by thefool »

you run 2 firewalls at same time? Well i can only strongly say that is for no need. I belive the help file of the firewalls says the same.
Dare2
Moderator
Moderator
Posts: 3321
Joined: Sat Dec 27, 2003 3:55 am
Location: Great Southern Land

Post by Dare2 »

Hi thefool,

How you going? :)

Two firewalls? Yes - just temporarily (less than 24 hours). It has been interesting to see which reports what. :)

So far both are doing the same job, although ZoneAlarm (pro/commercial) sure calls home a lot, going online to talk to base even though I requested not. :) (Tiny's logs tell me this). ZoneAlarm logs Tiny Personal Firewall as setting up as a server on bootup. Thereafter it does not try to go online. Good little fellow. :)

ZoneAlarm does a heap of stuff Tiny doesn't (or doesn't report), some of it pretty unexpected for a firewall.

I will run Kerio in conjunction with one of them later.

When I've settled on one, I'll stick with it. For the last few years I've run Tiny.

PS: Right now I want to get something beyond a firewall. Problem is I don't know what the correct terminology is for what I'm looking for. I know what I want. I don't know how to describe it to search engines and other people.
@}--`--,-- A rose by any other name ..
Moonshine
Enthusiast
Enthusiast
Posts: 263
Joined: Tue May 25, 2004 12:13 am
Location: UK

Post by Moonshine »

Im running a hardware firewall on a wireless router and the standard WinXP firewall (SP1). Since March Ive had maybe 4 viruses MAX and about the same amount of spyware - also running AVG Antivirus 6 Free edition.
Mark my words, when you least expect it, your uppance will come...
Sparkie
PureBatMan Forever
PureBatMan Forever
Posts: 2307
Joined: Tue Feb 10, 2004 3:07 am
Location: Ohio, USA

Post by Sparkie »

I haven't tried it out yet, but I stumbled accross this little gem called Ethereal. Maybe it has some features you're looking for.
What goes around comes around.

PB 5.21 LTS (x86) - Windows 8.1
Dare2
Moderator
Moderator
Posts: 3321
Joined: Sat Dec 27, 2003 3:55 am
Location: Great Southern Land

Post by Dare2 »

Hi Sparkie,

That looks good. I'll try it. Thanks! :)
@}--`--,-- A rose by any other name ..
thefool
Always Here
Always Here
Posts: 5875
Joined: Sat Aug 30, 2003 5:58 pm
Location: Denmark

Post by thefool »

@dare2: im fine, thanks :D

well for a product that lists programs that uses the net, kerio also does that.
It shows how much of the connection it uses, too.
User avatar
blueznl
PureBasic Expert
PureBasic Expert
Posts: 6172
Joined: Sat May 17, 2003 11:31 am
Contact:

Post by blueznl »

i'm a registered user of both (kerio and zonealarm pro :-)) so here are the verdicts...

zonealarm is easier to use (for beginners), free version is good enough for most applications, it is slightly less stable but (here it comes) severely sucks when using LARGE numbers of ports / HUGE amounts of traffic (think anything p2p, after a few days you have to reboot the machine if, for example, you're running something like emule 24/7)

i found it easier to get zonealarm to work with games, and managing security levels is a bit easier as well

kerio may be a little less friendly (imho ymmv etc.) but it works fine as a gateway firewall, and doesn't give any troubles with p2p stuff

kerio did f* up with the last update though, classifying all windows (os, filesharing, etc.) traffic as 'medium severity intursions' means the latest version is pretty much useless for anyone running a homenetwork, must be a bug (i hope) and i expect them to fix it soon... duh

another thing i didn't like about kerio is the way they handle vpn's... on the dutch kpn adsl network ppoe is used by default, declaring all that traffic as 'secure' if you use the default ruleset (this does not apply to those not using ppoe / pptp)

both packages are supposed to support ics stuff only in their pro versions, well, this is and is not true, it just depends on what you're doing... i got both of them working in their free versions on an ics machine

if you're using something like nat32plus, you can use the standard versions, as they don't check traffic 'going through', remember these are 'personal' firewalls, and do little to protect machines behind the gateway

just need a simple client firewall? go for zonealarm... need it for a small homenetwork on the gateway machine? go for kerio (perhaps registered)

you can always mix and match :-)
( PB6.00 LTS Win11 x64 Asrock AB350 Pro4 Ryzen 5 3600 32GB GTX1060 6GB - upgrade incoming...)
( The path to enlightenment and the PureBasic Survival Guide right here... )
Post Reply