Endpoint Protection

 View Only
  • 1.  browser intrusion prevention is malfunctioning

    Posted Dec 23, 2011 03:37 AM

    After enabling  "Prevent changes to system using Internet Explorer (IPS) [AC14] "  in applicaiton control.

    Gives me an error "browser intrusion prevention is  malfunctioning".

    I have refered to the below thread http://www.symantec.com/connect/forums/browser-intrusion-prevention-add-problem

    There are no GPO applied.

    IE is 8 and 9.



  • 2.  RE: browser intrusion prevention is malfunctioning

    Broadcom Employee
    Posted Dec 23, 2011 04:21 AM

    Is the pop up on all the machines  or are there machines with similar web browser version and everything's running fine?



  • 3.  RE: browser intrusion prevention is malfunctioning
    Best Answer

    Posted Dec 23, 2011 04:27 AM

     

    Expected behavior of Browser Intrusion Prevention

     

    http://www.symantec.com/business/support/index?page=content&id=TECH172174



  • 4.  RE: browser intrusion prevention is malfunctioning

    Posted Dec 23, 2011 04:30 AM

    Hello,

     

    I do not recieve a pop . I see it in the system logs that "browser intrusion prevention is malfunctioning ".

     

     



  • 5.  RE: browser intrusion prevention is malfunctioning

    Broadcom Employee
    Posted Dec 23, 2011 04:49 AM

    Is the log entry is seen in all the systems ?

    can you check running the support tool and see the errors ?



  • 6.  RE: browser intrusion prevention is malfunctioning

    Trusted Advisor
    Posted Dec 26, 2011 04:46 AM

    Hello,

    It is important to understand what is the RULE AC14: "Prevent changes to system using Internet Explorer (IPS) [AC14] "  in application control.

    AC14 Rule Set: Prevent changes to system using Internet Explorer (IPS)

    (Rule) > Internet Explorer Protection

    Note: applies to processes matching iexplore.exe and firefox.exe 

      • iexplore.exe
      • firefox.exe

    (Condititon) > AC14-1.1 Block writing to system folders

      • %windir%*\*
      • %programfiles%*\*
    • Excluded Files and folders
      • *\*softwaredistribution*
      • *\*softwaredistribution*\*\*
      • *\*windowsupdate*
      • *\*windowsupdate*\*\*
      • %windir%\profile*\*\*.


    (Condititon) > AC14-1.2 Allow IE to launch system process

      • %windir%*\*
      • %programfiles%*\*
    • Excluded Processes
      • *script*.exe
      • telnet.exe
      • mshta.exe
      • cmd.exe
      • ftp.exe
      • rundll32.exe
      • reg.exe
      • at.exe

     


    (Condititon) > AC14-1.3 Block IE from launching other processes
      • *

    (Condititon) > AC14-1.4 Allow IE to load system DLLs
      • %windir%*\*
      • %programfiles%*\*
    (Condititon) > AC14-1.5 Block IE from loading other DLLs
      • *

    • Prevent registration of new Browser Helper Objects (IPS) [AC16]

      Prevent registration of new Browser Helper Objects applies to processes matching *

    Reference: http://www.symantec.com/docs/TECH132307

    To resolve the issue, check this Thread: 

    https://www-secure.symantec.com/connect/forums/sep-hardening-policy-application-control-problems

     

    Hope that helps!!