home *** CD-ROM | disk | FTP | other *** search
- Section 1: SafeWord Virus-Safe Overview
-
- SAFEWORD VIRUS-SAFE CONSISTS OF:
-
- This SafeWord Virus-Safe User Guide,
-
- One or more files configured for use on one or more diskettes or
- disk drives formatted for compatibility with MS-DOS 3.0 and later.
- These files include:
-
- SWVSAFE.COM, the main program
-
- SWVEDIT.EXE, an editor to edit the checklist
-
- SWVINST.EXE, an automated installation utility
-
- SWVREMOV.BAT, an automated removal utility
-
- The only piece of software you actually need in order to get started is
- SWVSAFE.COM. This program will build its own checklist file (SWVCHECK.LST)
- and audit trail file (SWVAUDIT.TRL). You cannot edit the checklist file
- with a "normal" editor for security reasons. Nevertheless, in many cases,
- the checklist editor program (SWVEDIT.EXE) is not needed, because SafeWord
- Virus-Safe's main program (SWVSAFE.COM) learns your system as you use it,
- and builds an appropriate checklist file. You will only need the checklist
- editor if you decide you want to change or customize the checklist.
-
- The automated INSTALL and REMOVE utilities are simple files whose purpose is
- to copy the other files from the distribution diskette to your hard disk.
- Even without these automated utilities, installation and removal is easy and
- uses only straightforward MS-DOS. No copy protection or other such schemes
- are used, and a computer user who is familiar with MS-DOS need not use the
- automated installation and removal utilities.
-
-
-
- WHAT SAFEWORD VIRUS-SAFE DOES
-
- SafeWord Virus-Safe does only one thing, but that task is very important.
- When challenged to perform that task, SafeWord Virus-Safe is very, very
- reliable.
-
- What is that task?
-
- SafeWord Virus-Safe detects changes in files. When properly installed and
- used as described in this manual, SafeWord Virus-Safe will detect every
- change in protected files, even if the change is put into place by a clever,
- devious, technically competent attacker trying hard to evade detection.
-
-
- WHAT SAFEWORD VIRUS-SAFE DOESN'T DO
-
- Many companies are marketing anti-virus products that try to do too much.
- As a result, they annoy users with many false alarms. There is no reliable
- technology that can detect viruses before they contaminate your files, and
- products that attempt to do this are either extremely unreliable, or else
- they bombard their users with a seemingly unending stream of false alarms.
-
- SafeWord Virus-Safe makes no attempt to do any of the following:
-
- 1- Examine existing program internals to see if they contain logic that may
- be improper, unwise, vulgar, rude, illegal, or irresponsible.
-
- 2- Examine existing program internals to see if they contain exact copies of
- logic known to be contained in versions of viruses that are already well
- understood.
-
- 3- Determine whether any given program should be trusted when it attempts to
- write to special or reserved sections of disk.
-
- 4- Restrict the activities of users or programmers.
-
- Readers who are familiar with the intricacies of computer internals will
- recognize the folly in attempting to do too much, and will empathize with
- SafeWord Virus-Safe's refusal to attempt the above tasks. For those wishing
- further details, please refer to the Background Information contained in
- Section 2 of this User Guide.
-
-
-
- THE CHECKLIST FILE
-
- SafeWord Virus-Safe uses a checklist file to determine which files to check
- for changes, and when to check them. Any files may be designated to be
- checked, either when the PC is booted or, in the case of executable files,
- when they are executed. The checklist also determines how often and how
- thoroughly to check each of its files, to increase speed while maintaining
- the highest level of flexibility and security possible.
-
-
-
- System Requirements
-
- SafeWord Virus-Safe protects users of IBM PC, XT, AT, PS2, and compatible
- personal computers from the undesirable side effects of file contamination
- of the sort that results from viral infection, uncoordinated software
- upgrading, or malicious tampering. It requires an IBM PC, XT, AT, PS2, or
- fully compatible personal computer running MS-DOS 3.0 or later. While most
- users desiring this kind of protection have hard disk drives, none is
- required. And although most users can spare 19K of RAM to have SafeWord
- Virus-Safe continuously resident and examining every program all the time,
- it is not necessary to have any spare RAM dedicated to SafeWord Virus-Safe.
- The product can be installed in a way that makes periodic checks without
- residing in memory. It is also possible to use special memory management
- utilities, available from multiple sources at low cost, to temporarily
- remove SafeWord Virus-Safe from resident memory just long enough to run a
- single, very large application program.
-
-
-
-
- As an absolute minimum you need:
- 1- IBM-compatible computer, and
-
- 2- A compatible version of DOS (3.0 or greater).
-
-
-
-
- Most users will also have:
-
- 1- A hard disk drive, and
-
- 2- 19K of free RAM.
-
-
-
- In some cases, it is also desirable to use the following in conjunction with
- SafeWord Virus-Safe:
-
- 1- A vault or locking storage cabinet to store security-related diskettes
- where they cannot be contaminated even by insiders, and/or
-
- 2- Memory management utilities capable of temporarily removing memory-
- resident programs. (A common example: MARK.COM and RELEASE.EXE)
-
-
-
-
- Duties of your SafeWord Virus-Safe Supervisor
-
-
- SafeWord Virus-Safe is designed as a supervised product. Users can
- supervise themselves, or a separate person can be designated to supervise
- others. In either case, the supervisory role is small but powerful.
-
- The SafeWord Virus-Safe supervisor has two primary roles. He or she can:
-
- 1- Compose and distribute checklists, and
-
- 2- Install cryptographic keys to make protection of data and programs for
- one user different from another, so even if a sophisticated attack targets
- one specific user, it will be detected if and when the attack spreads to a
- different user.
-
- The standard SafeWord Virus-Safe distribution kit includes everything you
- need to perform the supervisory role as well as to use the product. If you
- obtained your copy as part of a corporate purchase, your organization should
- tell you who your supervisor is. That person can distribute a checklist to
- you, modify your checklist, and install your unique cryptographic keys. If
- you choose to act as your own supervisor, you can perform these functions
- for yourself.
-
-
-
-
-
-
- MODES OF INVOCATION
-
- SafeWord Virus-Safe can be invoked in either of two modes:
-
- 1- as a disk-resident program that checks all files in its checklist file
- each time it is invoked, or
-
- 2- as a memory-resident program, capable of checking programs before they
- are executed or each time the PC is booted, based on a flag set for each
- file in the checklist.
-
- The trade-offs of these modes are discussed in detail in Section 3.4 of this
- manual.
-
-