home *** CD-ROM | disk | FTP | other *** search
- safeWord VIRUS-Safe Version 1.1
-
- Shareware release
-
- This file describes a software package, called "SafeWord VIRUS-Safe", which
- was developed by Enigma Logic Inc. of Concord, California. Our address is:
-
- Enigma Logic Inc.
- 2151 Salvio Street, #301
- Concord, California 94565
- USA
-
- You can reach us by telephone at (415) 827-5707
- You can reach us by teleFAX at (415) 827-2593
-
-
-
- This is NOT "Crippleware". We have licensed tens of thousands of copies of
- this same software to major banks, aerospace manufacturers, and sophisticated
- clients throughout industry and governments around the world. Nothing has
- been held back in this "shareware" release. Prior to this shareware release,
- the standard "list" price for this software in the USA was $125.00 per copy.
- Recently, interest in this product has exceeded our ability to deliver it
- through our commercial sales force, so we have decided to release it as
- shareware, for a lower price, to facilitate its rapid deployment into the
- marketplace.
-
- Please show us that we have done the right thing by making this quality,
- commercially-developed software available to you through shareware on the
- "honor" system. If you find this software useful, please register it with us
- promptly by sending us the registration fee as instructed in the "sign-on"
- window.
-
- Each time the software runs, the "sign-on" window is automatically displayed
- for 15 seconds. You can make it disappear immediately by pressing "ENTER".
- If you press "SPACE", while the window is displayed, then the 15-second
- timer is shut off and you can read the window at your leisure, terminating
- it with "ENTER".
-
- Organizations interested in purchasing multiple copies may feel free to
- contact us to discuss the possibility of purchasing a "site license".
- Organizations interested in bundling this software with other products or
- services, please contact us to discuss the possibility of purchasing an
- "OEM" license. Organizations interested in distributing this software
- either by conventional commercial means or as shareware, please write
- us on your letterhead and include a catalog of your other shareware
- offerings.
-
- Other than the rights specifically granted by written statements from Enigma
- Logic, all other rights are retained by Enigma Logic Inc., the copyright
- holder.
-
-
-
- WHAT THIS SOFTWARE DOES
-
- This software is for computers running the MS-DOS operating system. It helps
- users become aware of the "integrity" of their computing environments. This
- is done by periodically examining programs, data, and DOS modules to determine
- whether any of them have been changed without authorization.
-
- Unauthorized changes in programs, data, or DOS modules may indicate serious
- trouble, such as pollution by software viruses, tampering by malicious
- individuals, damage from "Trojan horse" programs, corruption due to hardware
- faults, improper installation or upgrading of software or hardware, or
- degradation by unsophisticated or irresponsible operating procedures.
-
- No matter the source of such unauthorized changes, it is important that users
- become AWARE that changes have occurred. Awareness of such changes permits
- quick and easy restoration of files back to their authorized condition by
- following normal "backup" and "restore" procedures.
-
- SafeWord VIRUS-Safe detects these changes by periodically calculating a
- "signature" of files and software modules. These signatures are then compared
- with corresponding prior signatures. If the signature has changed, the user
- is informed and asked if he or she knows of any good REASON why changes in the
- corresponding file(s) should be authorized. Comprehensive audit trails are
- maintained recording all available information relevant to the integrity of
- the protected computer system. Examination of these audit trails makes it
- very easy to learn about viral spreading,
-
-
-
- TWO DIFFERENT INSTALLATION MODES
-
- SafeWord VIRUS-Safe can be installed in either of 2 modes:
-
- 1- Invoked as a "device driver" through "CONFIG.SYS"
-
- or
-
- 2- Invoked as a ".COM" file, usually in conjunction with a batch file such as
- "AUTOEXEC.BAT".
-
- The choice between these two different installation modes should be made by
- you according to the dependencies of your own system. You may already know of
- certain restrictions in the construction of your CONFIG.SYS file or your
- AUTOEXEC.BAT file which may impel you to choose one of these over the other
- for invocation of SafeWord VIRUS-Safe. If you know of no incompatibilities or
- dependencies which may impel you to choose one method over the other, then the
- choice is arbitrary. This choice is offered only for your convenience in
- avoiding conflicts with other products.
-
-
-
- TWO DIFFERENT OPERATIONAL MODES
-
- Operation is pretty much the same regardless of which of these two
- installation and invocation methods is used. In both cases, additional
- flexibility allows the operator to specify either of two distinct modes of
- operation. These two operational modes, (available from either of the 2
- invocation methods), are:
-
- 1- Memory-resident
-
- or
-
- 2- Non-memory-resident "batch" mode.
-
- Most users prefer the memory-resident mode. When operating memory-resident,
- SafeWord VIRUS-Safe is always present and can continuously intercept requests
- to execute programs, checking their integrity "on-the-fly". Because this mode
- is seamlessly integrated into DOS, it is nearly transparent to users and is
- thus very convenient and reassuring. The downside of this memory-resident
- mode is that approximately 19 kilobytes of RAM are tied up; it's as if DOS got
- 19K bytes bigger. Temporarily freeing up this extra 19 kilobytes in order to
- run a very large program is possible. However, it requires use of utility
- programs such as "MARK.COM" and "RELEASE.EXE" (both available through
- shareware channels) and is best left to computer-literate users.
-
- On the other hand, some users prefer the non-memory-resident "batch" mode.
- This mode doesn't tie up any of your precious RAM and eliminates any
- consideration of extra memory management utilities. The "batch" mode doesn't
- stay active all the time, so it is possible for a virus to enter your system
- and spread during work sessions between invocations of SafeWord VIRUS-Safe.
-
-
-
- TWO DIFFERENT STORAGE ENVIRONMENTS
-
- So far, we've discussed 2 different installation modes and 2 different
- operational modes, yielding 4 different functional combinations. That's not
- the end of the story. Any of these 4 different functional combinations may
- reside in either of 2 different storage environments as follows:
-
- 1- On your main hard disk system. In this case, SafeWord VIRUS-Safe is used
- frequently (maybe continuously) and it is in the best position to detect
- viruses early. However, it is also exposed to the possibility of a
- sophisticated virus that "targets" your specific environment. "Insider"
- attacks and "stealth" viruses may be able to compromise some of SafeWord
- VIRUS-Safe's integrity checking power in these cases.
-
- or
-
- 2- On a separate "boot" diskette. The intent of this case is to create a
- separate, "isolated" environment that is never exposed to the possibility of
- viral contamination, and which is used periodically to examine your main hard
- disk system and any of the defenses that reside in your working environment
- and that may have been attacked. This kind of "sterile" environment is
- created by making a boot diskette from a copy of MS-DOS that you trust.
- SafeWord VIRUS-Safe is then also installed on that diskette. Thenceforth,
- that diskette is referred to as the "SafeWord VIRUS-Safe Sterile Kernel" boot
- diskette, and it is never used for any purpose other than to bootstrap your
- computer and invoke SafeWord VIRUS-Safe. When not in use, this diskette
- should be physically locked up in a place where it cannot be accidentally
- inserted into a computer that may be virally contaminated. In this case, no
- virus can contaminate the boot diskette, and no viral contamination can avoid
- being detected by SafeWord VIRUS-Safe when operated according to the
- recommendations contained with the appropriate documentation.
-
-
-
- SUMMARY of DIFFERENT WAYS TO USE SAFEWORD VIRUS-Safe
-
- Taking into account all the modes discussed in the previous paragraphs, there
- are eight (8) different major variations on this theme. Most users choose
- some combination of 2 of the available 8 combinations and then disregard the
- rest. The most popular combinations are:
-
- 1- Resident on your main hard disk file system, install a version of SafeWord
- VIRUS-Safe in the memory-resident mode from CONFIG.SYS.
-
- and
-
- 2- Configure a sterile kernel diskette to bootstrap your PC and then
- periodically (once a month or so) run SafeWord VIRUS-Safe in non-memory-
- resident "batch" mode. Never use this diskette in any other way. Never use
- this diskette on any other computer, and never insert it into a computer that
- may have been exposed to viruses while it is operating. Always re-boot or
- switch off the computer, then bootstrap from this diskette and run SafeWord
- VIRUS-Safe to examine the critical programs and defense mechanisms on your
- main hard disk file system.
-
- By setting up your SafeWord VIRUS-Safe defenses to operate in BOTH of these
- modes, you will be able to assure "overlapping" defenses that are virtually
- impenetrable.
-
-
-
- THE FILES CONSTITUTING SafeWord VIRUS-Safe
-
- A complete distribution package contains the following files:
-
- 1- README.ASC (This file)
-
- 2- MANUAL1.ASC The cover sheet for the user manual (FLAT ASCII TEXT)
-
- 3- MANUAL2.ASC The preliminary pages of the user manual
-
- 4- MANUAL3.ASC Chapter 1 of the user manual
-
- 5- MANUAL4.ASC Chapter 2 of the user manual
-
- 6- MANUAL5.ASC Chapter 3 of the user manual
-
- 7- MANUAL6.ASC Chapter 4 of the user manual
-
- 8- MANUAL7.asc Chapter 5 of the user manual
-
- 9- UPDATES.ASC A list of new features in this release
-
- 10- SWVINST.EXE Automated installation utility
-
- 11- SWVREMOV.BAT Automated removal utility
-
- 12- SWVSAFE.COM The main program that detects integrity violations.
- invoked through autoexec.bat, or config.sys,
- at your discretion via command line, or from
- a convenient batch file.
-
- 13- SWVEDIT.EXE A highly specialized editor program for editing
- "checklists" containing integrity-checking rules.
- You probably won't use this very much.
-
- 14- PRINTALL.BAT Very simple utility to print an unformatted
- copy of documentation
-
- 15- F_FEED Tiny file used during the PRINTALL.BAT process
-
- 16- ORDER.ASC An order form to make it even easier to register SafeWord
- VIRUS-Safe. You may register by forwarding
- payment to Enigma Logic as instructed in the
- Sign-On Screen, with or without this form.
-
-
-
- A Directory Listing of the distribution kit should look like this under MS-
- DOS:
-
-
- Volume in drive x has no label
- Directory of x:\
-
- F_FEED 2 11-21-90 3:14p
- MANUAL1 ASC 187 11-21-90 3:14p
- MANUAL2 ASC 5253 11-21-90 3:14p
- MANUAL3 ASC 7120 11-21-90 3:14p
- MANUAL4 ASC 12626 11-21-90 3:14p
- MANUAL5 ASC 35555 11-21-90 3:14p
- MANUAL6 ASC 7072 11-21-90 3:14p
- MANUAL7 ASC 4222 11-26-90 4:45p
- ORDER ASC 2450 11-26-90 4:03p
- PRINTALL BAT 360 11-21-90 3:14p
- README ASC 17551 11-27-90 10:18a
- SWVEDIT EXE 32343 11-26-90 5:20p
- SWVINST EXE 19274 11-26-90 6:20p
- SWVREMOV BAT 3394 11-21-90 3:14p
- SWVSAFE COM 30372 11-26-90 5:19p
- UPDATES ASC 15371 11-21-90 3:14p
- 17 File(s) xxxxxx bytes free
-
- In addition, certain other files will be created when the software runs.
- These contain checklist and audit trail information. Periodic examination of
- "SWVAUDIT.TRL" will prove very interesting, especially if you suspect a
- virus has been spreading throughout your file system. It records before-and-
- after file sizes and non-forgeable file signatures that will prove of great
- value in chasing down viral attacks.
-
-
-
- Printing the Documentation
-
- For your convenience, the documentation is stored as "flat ASCII" text files
- that you can easily manipulate with your favorite word processor to help you
- during your evaluation period. The batch file "PRINTALL.BAT" will print all
- of the documentation files in the appropriate sequence, in a very simple
- format on your locally attached printer. Registered users automatically
- receive a professionally typeset manual.
-
-
-
- INSTALLING SafeWord VIRUS-Safe
-
- If you've read this far, you are probably wondering how complicated it is
- going to be to install this software. With eight main combinations of running
- mode options, you might worry that installation could be very complicated.
-
- Well.... the MANUAL is very complicated. We felt we had to cover all the
- options in the manual. As a result, the manual is going to be a bit hard to
- swallow. Sorry about that... With literally tens of thousands of users
- sending us suggestions and informing us of various quirks in the machines out
- there in the cold cruel world, we've added options on top of options on top of
- options that will allow you to configure around just about any conceivable
- kind of incompatibility. That makes for a manual that is bewildering and
- overwhelming. We recommend that you read it right now anyway....
-
- You didn't read it, did you? Nobody else does either. The good news is
- that even if you disregard our best advice about reading the manual, you are
- very likely to have a good experience on your first attempt to install this
- software if you just run the automated installation utility ("SWVINST.COM")
- and carefully read the menu screens and act on the options that are
- presented one at a time. Look particularly at the prompts at the bottom of
- each installation screen window. These prompts indicate the responses you
- can make at any time. Most users find this installation process straight-
- forward. The automated installation makes pretty good assumptions about the
- options you'll want to try first. You shouldn't just dive in without
- reading the manual first, but since everybody else does, we assume you will
- too. Since most people make a success out of this exercise, we assume you
- will too. If you really want to know what the automated installation
- procedure is going to do to your computer (you must be concerned about
- integrity or you wouldn't be reading this...) you can read all about it in
- the manual. There is even a subsection on performing the entire
- installation by hand, for those of you intrepid souls that want to assert
- total control of the situation.
-
- Once you are comfortable with the way the software operates, you'll want to
- consider at least a few of the special options that can "tune" performance to
- your desires. Most of these are "command-line" options that you can add to
- the line invoking SWVSAFE.COM from your CONFIG.SYS or AUTOEXEC.BAT file.
- Experiment til you find the set of options you like best.
-
-
-
- Removal
-
- Removing SafeWord VIRUS-Safe is straightforward. The files constituting the
- product are marked "READ-ONLY" to prevent accidental deletion. Use any
- available tools to remove the READ-ONLY restriction, then simply delete the
- files and restore your CONFIG.SYS or AUTOEXEC.BAT as they were prior to
- installation. If you used the automated installation utility, backup copies
- of these files are automatically saved in your root directory.
-
- We have provided a batch file called "SWVREMOV.BAT" to automate this removal
- process. You may want to examine it because it illustrates one way of easily
- removing SafeWord VIRUS-Safe.
-
-
- Conclusion
-
- We sincerely hope you like SafeWord VIRUS-Safe. It won't be obvious from
- superficial examination, but sophisticated users will want to know that we
- have fully implemented all the recommendations of the American National
- Standards Institute's (ANSI) standard X9.9, and the International Standards
- Organization's standards ISO 8731-1 and ISO 8731-2 for calculation of
- cryptographically based, non-forgeable signatures based on "message
- authentication codes". What this means to the casual user is that the file
- signatures used to detect tampering are very sophisticated, and take full
- advantage of the same technology that ensures the integrity of the electronic
- funds transfer system forming the backbone of modern banking and commerce. If
- anybody figures out how to "forge" one of these signatures, he or she can do
- more than fool SafeWord VIRUS-Safe; he or she may be able to tap into billions
- of dollars worth of electronic wire transfers. Fortunately, there is no
- credible record of any such system ever being compromised. If you operate
- your copy of SafeWord VIRUS-Safe according to the recommendations in the
- accompanying documentation, your computer will operate in an environment of
- that same rigid integrity. Also: please register your copy with us and
- support our ShareWare distribution system! Thank You.
-