Does sandbox security really protect your desktop?

Tests question vendor claims of meaningfully improved security, though not everyone agrees

Another Grimes gripe concerned the reset button. Sandbox browsers have a reset button that the user can push if he suspects that the browser has been compromised. The button resets the browser to a clean state, often to a snapshot of the virtual browser before the Web session started. Of course, if the virtual browser is infected with something that can get to the operating system, the reset button option may be too late to protect you.

These reset buttons don't actually fully reset the browser; they leave some user settings alone, such as bookmark lists, between sessions. But ForceField's reset button kept resetting Grimes' home page. That's an annoyance compared to GreenBorder, which didn't actually reset its browser, so malware remained even after he triggered the reset button, Grimes recalls. "E-mail worms would start spamming other people on your network until you reset it -- and a reset wouldn't even get rid of it all."

Check Point fires back: a flawed test?

Check Point has been trying to replicate Grimes' ForceField test (and results) without success. "We're just not sure how the product was actually tested," says Jordy Berson, product manager of ZoneAlarm ForceField. "There are cases with ForceField where a threat is stopped -- it never hits the computer but is captured in the virtualized layer -- and it may appear to the tester that it's actually been successful."

Moreover, the sandbox browser was never meant to run on a system without patches, firewalls, or anti-virus software. ForceField simply adds another layer of protection and has never claimed to be full-proof, contends Berson. Indeed, Grimes' test didn't show whether or not ForceField could improve security of a fully patched system.

Sky King, product leader at ForceField, admits that the underlying virtual red-green computing model requires trade-offs. "We are virtualizing the core browser, but there are some exceptions you have to make for usability," he says. Users will want to download Web browser plug-ins like Beatnik, QuickTime, RealPlayer and Shockwave, as well as cookies and other software files, that need to tap into the computer's file system to be used regularly.

Here's how the trade-off works: ForceField's decision engine looks at every downloading file to determine whether the user solicited it. If the engine decides that the user solicited the file, it will likely allow the file to pass through the virtualization layer. "But if something comes down from the browser that the user has not solicited, then it goes straight to virtualization to die," Berson says.

For user-solicited files, ForceField offers some protection. When a user clicks a link to download a file, ForceField analyzes the file and runs it against a database of millions of good and bad applications. "If we detect it to be a known bad application, we'll warn the user to prevent it from crossing the virtualization layer," King says.

Grimes agrees that ForceField provides good value in these cases. "In my test, I found that a fully patched system prevented all attacks but didn't alert you about the attacks," he says. "[Sandbox browsers] at least alert you a lot of the time, just not perfectly."

Join the Good Gear Guide newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Tom Kaneshige

InfoWorld
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?