Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

SEP 11 - Learned Application MD5 Hash Reference Database

Updated: 19 Jun 2009 | 2 comments
Blenky's picture
9 Agree
0 Disagree
+9 9 Votes
Login to vote
Status: Reviewed

As an Authorized Symantec Consultant I've run into this a number of times where clients are looking to do some extensive application blocking but the only great way to perform this in SEP is via file fingerprinting (MD5 hash).   In most cases this proves to be extremely difficult to port over from another product because, in the cases I've been involved in, the other product used other means to identify the products (as an example, internal program name).  The MD5 hash is difficult to build from scratch since ever version of a product (exe) would generate a different fingerprint.  

Knowing this a VERY useful tool would be a database that is globally available for Symantec customers to look up file fingerprints for executables.  Maybe even a product enhancement to block based on application category (i.e. hacking software).  A relatively simple tool to develop could prove to be invaluable to customers (especially large corporate customers looking to ensure their environments remain completely secure without having to use the learn application tool and have an insecure network while they identify all apps in their environment).

Comments

Nel Ramos's picture
18
Jun
2009
0 Votes 0
Login to vote

hope you could integrate a

hope you could integrate a list of MD5 hash for us to use in fingreprinting unwanted applications...
this must also be updated as per additional request has been made by the clients..

Nel Ramos

Acretian's picture
22
Oct
2009
0 Votes 0
Login to vote

But the issues is that they

But the issues is that they should also update the list from time to time, coz the has value will change when a new version is released