McAfee® Host Intrusion Prevention 6.1 Product Guide

Application Blocking Policies

 

Overview

6

Application hooking

Block application hooking to prevent unknown applications from binding themselves to other programs. This type of hooking, which occurs at the kernel level of the API, is needed by some legitimate applications, but can also indicate an attack. For example, a malicious application might try to e-mail itself by hooking to the e-mail application. You can prevent these attacks by blocking application hooking or configure it so that only specific applications bind themselves to other programs. You can also enable automatic Adaptive mode or interactive Learn mode to handle unknown applications trying to hook other applications.

Preset Application Blocking policies

The Application Blocking feature contains two policy categories:

„Application Blocking Options: Turns application creation and hooking blocking on or off. Preset policies include Off (McAfee Default), On, Adaptive, Learn.

„Application Blocking Rules: Defines application blocking settings. The preset policy is the default (McAfee Default).

Quick access

The Application Blocking feature provides links (*) for quick access to monitor and manage Application Blocking Rules and Application Blocking Client Rules.

Figure 6-1 Application Blocking feature

*

95

Page 95
Image 95
McAfee 6.1 manual Application hooking, Preset Application Blocking policies