From CastleCops:
System Safety Monitor
From CastleCopsWiki
Jump to: navigation, search
Product: System Safety Monitor
Company: System Safety Company
Website:
http://syssafety.com/
Support forum:
http://syssafety.com/forum/
First released: 2002 (private project), 2006 (commercial product)
Feature list: Main features include execution control (including parent-child), process modification and termination control, service/driver installation control, registry control. Full Feature list compared to other products
Various reviews and tests:
http://kareldjag.over-blog.com/8-categorie-69553.html ,Nicm's test against selected "unhookers" malware
Contents [hide]
1 Quick review
2 Strengths
3 Weaknesses
4 Comments on the free version
4.1 Conclusion
[edit] Quick review
SSM began as a private project in 2002.[1] and was one of the first behavior blockers available to home users along side ProcessGuard but because it was a personal freeware project it was pretty unstable most of the time. In April 2005, It was sold to a group of professionals who started Syssafety company.[2] who went commercial and they released the first 2.0 beta series in September 2005. In June 2006, they split the series into 2 lines.First there was A freeware version 2.0 that has all of the features of the original 1.9 series plus some improvements . There was also a 2.1 commercial version that has some improvements over the freeware version, particularly an improved registry control (hooking as opposed to polling) , low level keylogging control and better Process Termination. The new 2.1 version also dropped support of Windows 98 and Windows ME .
[edit] Strengths
SSM provides a wide and deep coverage of various behaviors and system states on your computer. Besides the standard feature sets of HIPS, it also offers Children-parent control (good for handling leak tests), monitoring of load Dll libraries , Blocking low level disk accesses (protecting your system from trojans that try to destroy your hard disk) as well as choice of using SHA512 as alternative hashing algorithm's instead of the traditional and older MD5 used by most security software.
SSM also warns you when a program tries to shutdown the system. It not only protects the registry but also offers some file and directory coverage, in particular of ini files, Startup folder and Layered service providers.
The low level keylogging control in SSM is also pretty powerful covering even unusual methods like getKeyState or AsyncKeyState used by some keyloggers like Martin's Undetectable Keylogger.
SSM also has customizable logging options, various options on system startups (whether to block process creation only or block everything when loading up etc). There is also an option to ignore the file hash check for processes that are rapidly changing.
SSM also updates very frequently, often several times a month.
[edit] Weaknesses
SSM greatest strength is also its greatest weakness. As you can see above, SSM covers a wide range of behaviors and states far more so than say ProcessGuard. This gives a degree of control that is unmatched by almost all products out there.
Unfortunately all this control comes at a price, the user has to know what to do with it! With every new feature added, the number of queries and prompts that the user has to answer increases and the number of prompts that SSM generates is corresponding larger than most HIPS. Most of them are generated as a result of features like DLL monitoring, parent-child execution control (you don't just give full permission to run firefox.exe but only for specific cases e.g run firefox.exe only if it is started by explorer.exe).
While SSM has surpassed ProcessGuard in terms of features and coverage of extra system points, it doesn't do anymore to help users handle all this extra complexity any better than ProcessGuard. It covers the standard learning mode just like the later and that's it. For sure, a constantly list of updated whitelists would be helpful to reduce popups.
The interface of SSM is also somewhat cluttered and difficult to handle (particularly the registry tab is confusing), but this no doubt due to the fact that it is bursting with options.
SSM is also somewhat less stable than other HIPS and often conflicts with other security programs due to the wide coverage and depth of its intergration with the system, but problems are often quickly fixed.
Also despite the fact that SSM has a lot more features than ProcessGuard (which we take as the gold standard), it is still a classical HIPS product as such it does not offer file/directory restrictions , nor virtualization/rollback options of Sandboxes.
[edit] Comments on the free version
The free version of SSM is one of the more capable free HIPS out there. It is essentially, the last full version of SSM that still works for Windows 98 (The pro version drops Win 98 support). As one of the few HIPS that supports Windows 98, it is highly recommended for users that are on that operating system.
The pro version provides further advanaced features including full blown termination protection (the free version technically doesn't have any, though it can intercept some termination attempts on a per process basis), configurable registry protection (free version has fixed list in modules), choice of SHAA256 check sum, LSP monitoring, various advanced anti-keylogger and anti-rootkit techniques , protection against low level disk access, command-line parameters support for applications , basic network control, rule plus a lot of other refinements.
Regardless the free version is still very capable and fully featured comparable to the full versions of many HIPS.
[edit] Conclusion
SSM is a great option if you are an experienced user looking for the ultimate in control and you aren't borthered by constant queries and prompts.
However, if you are a new user looking for simplicity, SSM is probably too complicated.