This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

New applications added to Application Control policy in the 4.48 data release

Hi,

For those interested I'm planning each month to post a list of new applications which can be detected using the Application Control policy within SEC. This month has been a particularly prolific one for SophosLabs as we've added detection for 42 new applications. Most of these identities have been created following requests made by customers via the form accessible within the security analysis pages: http://www.sophos.com/security/analyses/controlled-applications/

More detail on each application can be found on the relevant analysis page.

Best regards,

John Stringer (Product Manager)

Application name            Category

Google Chrome Frame         Browser plug-in

Yoono                       Browser plug-in

Adobe Reader 5              Document viewer

Adobe Reader 6              Document viewer

FastStone MaxView           Document viewer

AxCrypt                     Encryption tool

Graboid video client        File sharing

Windows FTP                 FTP Client

Yetisports                  Game

PopCap Games                Game

Deer Hunter                 Game

Halo Zero                   Game

GemTree Desktop Games       Game

AChat                       Instant messenger client

Pwytter                     Instant messenger client

Visual IRC Client           Instant messenger client

Quitter                     Instant messenger client

MXit                        Instant messenger client

CompanionLink               Mobile Synchronization

MobileMe Control Panel      Mobile Synchronization

SugarSync Manager           Mobile Synchronization

Zune                        Mobile Synchronization

Google Calendar Sync        Email client (moving to Mobile Synchronization)

PPStream                    Media player

MediaMonkey                 Media player

KM Player                   Media player

Mozy                        Online storage

CDBurnerXP                  Optical burning tool

PacketiX                    Proxy / VPN tool

Fastviewer                  Remote management tool

EMCO remote desktop         Remote management tool

OmniQuad Instant            Remote management tool

Remote Control          

Elcomsoft Distributed       Security / system tool
Password Recovery Tool

Metasploit                  Security / system tool

XAMPP                       Security / system tool

Winpcap                     Security / system tool

Conduit Toolbars            Toolbar

LinkedIn Outlook Toolbar    Toolbar

ASuite                      USB Program launcher

CodySafe                    USB Program launcher

RocketDock                  USB Program launcher

ZoIPer                      Voice-over IP (VoIP)

:233


This thread was automatically locked due to age.
Parents
  • Hi Ash,

    The applications will appear within Enterprise Console when the latest endpoint release has been completed:

    1) SAV 7.6.14 was released at the end of November

    2) SAV 9.0.2 is scheduled for release next week

    The issue you describe with applications getting blocked that aren't in the list should now be resolved. The Labs have guidelines which mean that new application control  identities should only be released as part of a monthly data update. Of course the Labs can still update existing identities in between releases.

    You should be able to block "All added by Sophos in the future" again and obviously this is a good way to keep on top of regularly updated categories like IM and file sharing.

    Best regards,

    John

    :244
Reply
  • Hi Ash,

    The applications will appear within Enterprise Console when the latest endpoint release has been completed:

    1) SAV 7.6.14 was released at the end of November

    2) SAV 9.0.2 is scheduled for release next week

    The issue you describe with applications getting blocked that aren't in the list should now be resolved. The Labs have guidelines which mean that new application control  identities should only be released as part of a monthly data update. Of course the Labs can still update existing identities in between releases.

    You should be able to block "All added by Sophos in the future" again and obviously this is a good way to keep on top of regularly updated categories like IM and file sharing.

    Best regards,

    John

    :244
Children
No Data