SEP 11 - Learned Application MD5 Hash Reference Database
As an Authorized Symantec Consultant I've run into this a number of times where clients are looking to do some extensive application blocking but the only great way to perform this in SEP is via file fingerprinting (MD5 hash). In most cases this proves to be extremely difficult to port over from another product because, in the cases I've been involved in, the other product used other means to identify the products (as an example, internal program name). The MD5 hash is difficult to build from scratch since ever version of a product (exe) would generate a different fingerprint.
Knowing this a VERY useful tool would be a database that is globally available for Symantec customers to look up file fingerprints for executables. Maybe even a product enhancement to block based on application category (i.e. hacking software). A relatively simple tool to develop could prove to be invaluable to customers (especially large corporate customers looking to ensure their environments remain completely secure without having to use the learn application tool and have an insecure network while they identify all apps in their environment).
hope you could integrate a
hope you could integrate a list of MD5 hash for us to use in fingreprinting unwanted applications...
this must also be updated as per additional request has been made by the clients..
Nel Ramos
But the issues is that they
But the issues is that they should also update the list from time to time, coz the has value will change when a new version is released
Would you like to reply?
Login or Register to post your comment.