home *** CD-ROM | disk | FTP | other *** search
- Norton Internet Security 2001 4.0
- Norton Personal Firewall 2001 4.0
- Technical Notes - August 25, 2001
-
- Copyright 1999, 2000, 2001 Symantec Corporation
- All rights reserved
-
- This document contains technical information about
- some features of Norton Internet Security and
- Norton Personal Firewall. Note that the release
- notes may refer to features that are not in the
- product you have installed, as it covers three
- products with different features.
-
-
- Cookie Blocking
- ~~~~~~~~~~~~~~~
- NIS and NPF 4.0 block cookies from being created
- on your computer by the browser's routine
- operation, but doesn't block special cookies from
- being created via script or activex/Java. The
- cookie blocking feature blocks all outbound
- cookies to provide full protection, but you may
- occasionally see some cookies appear in your
- cookie folder because of this.
-
- Earlier versions of NIS only blocked the outbound
- cookies.
-
-
- Content Filtering
- ~~~~~~~~~~~~~~~~~
- New to version 4.0 is the move of http filtering
- from the device drivers to a service named
- SymProxySvc. This has resulted in fewer device
- drivers being loaded and a common architecture for
- both web content filtering and email virus scanning.
-
- This service is utilized as a transparent proxy
- through which http, MSN Messenger, and AOL Instant
- Messenger traffic is redirected. When this occurs,
- you will see connections from your web browser and
- other applications to localhost, which are those
- applications communicating with the proxy.
-
- A second proxy, NAVAPW32.EXE, is used for filtering
- POP3 and SMTP traffic to mail servers to scan them
- for viruses.
-
-
- Application Scan
- ~~~~~~~~~~~~~~~~
- During an application scan, you may receive an Internet
- Access Control alert stating ALESCAN.EXE is attempting
- to communicate to the internet. This access may be
- DNS lookups, or an http communication (usually to
- crl.microsoft.com).
-
- This communication is needed for the verification of
- the digital certificates of applications being scanned,
- and checks for certificates which may have been revoked.
-
-
- Automatic Internet Access Control
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- Norton Internet Security and Norton Personal Firewall
- have a feature called Automatic Internet Access Control,
- that can automatically create firewall rules for
- recognized applications without requiring user
- intervention. When rules are created in this manner, a
- notice will appear in the log and the Alert Tracker will
- show a notification that this occured.
-
- This feature is turned on by default after installing.
- To turn it off, go to the Personal Firewall / Internet
- Access Control panel, select the configure button, and
- choose the "Enable Automatic Internet Access Control"
- line. With this feature off, you will get alerts for
- all applications which have not been previously
- configured.
-
- Not all applications are eligible for the Automatic
- Internet Access Control. For an application to be
- subject to automatic rule creation, it must pass a
- virus/trojan scan (if Norton AntiVirus is present on the
- system), and it must match a digital fingerprint of the
- application as profiled by Symantec. The digital
- fingerprint uses an SHA-1 algorithm and is extremely
- difficult to fake, virtually guaranteeing that only
- applications which have been analysed by Symantec will
- have rules automatically created.