Software Evaluation

BOA

My laptop was intruded by unknown users in a few occasions in the past few months, which alarmed me the vulnerability of my system. Hence I decided to install a personal firewall on my laptop to block intrusion. I first downloaded and installed the Norton Personal Firewall trial version, but the software crashed my system for unknown reason. It gave me a great deal of trouble to uninstall the software, so I decided to try some basic and free personal firewall first. What I found is Sygate Personal Firewall.

Sygate Installation

To install the Sygate personal firewall, simply download the executable from the Download.com site. Double-click the pspf.exe file from your personal computer; the InstallShield Wizard will prompt you through the installation process. The installation takes just a few seconds and one reboot, and the firewall is ready for use.

Once the firewall is installed, It prompts you each time you attempt to access an outside service using a port for the first time, as well as each time an outside service attempts to connect to a port for the first time. The message box allows you to block access to the service, allow access to the service, or allow access to the service using pre-defined rules.

Software Description:

SPF performs standard firewall tasks such as blocking unwanted connections to a computer and detecting possible attacks. There are three security levels in SPF, Normal, Block All and Allow All. The default security level is Normal, and you can customize protection according to your needs. Sygate detects and halts Trojan horses, authenticates my applications with checksums, and further authenticates each DLL so that hostile code can’t use a trusted application to executer an intrusion. As I mentioned earlier, Sygate prompts you each time you attempt to access an outside service, and you can choose to tell SPF to remeber your answer for future information. Except for asking permission for application access, the software mostly works on the background, and won't interrupt your work on computer. If you want to get the up-to-date network traffic status, you can open the main console by clicking the system tray icon. The design of the main console is pretty neat, and you can navigate to anywhere else within the firewall. Below is the screenshot for the main console.

main console

For firewall beginners, they may find the software is effective and pretty easy to manage. The regular version is free for personal use and $20 for business use. The Pro version is $40.

Effectiveness Evaluation:

I’m new to firewall, so I choose to evaluate SPF from the perspective of an inexperienced user who cares about computer security but has very limited knowledge about the technology.

Ease of Installation and Configuration: Sygate has autoconfigured with a blend of default security and minimal user intervention, which leaves most of the common legitimate programs free to work and saves users from lengthy configuration process. If you want to better control your network traffic, you can use the Advanced Rules feature to specify what kind of traffic you want to control. The Sygate firewall is easy to get up and running, and has a fair amount of flexibility for customization, which can meet needs for both new users and advanced users.

Clear Warnings:I think clear and easy to understand warnings are very important for users to understand what threats they are exposed to. Sygate has three different kinds of warning messages:
New Application Pop-up, which ask for your permission when an applicaiton is trying to access your network. An image of pop-up message is included below.

Changed Application Pop-up:If you recently upgrade an application, SPF will determine the legitimacy of an application by using checksum. The firewall will ask for your confirmation. Below is an sample image from the Sygate site.

System Tray Notification: When there's an attempted attack against your computer,the firewall will notify you about the attack. The image below is also a sample from the Sygate site.

Vulnerability Assessment:It is important to test your firewall to make sure you are protected from possible intruders. Sygate provides several online scan services that assess your system security. Sygate sstresses on its online services page that information collected on any scan is not used, stored and viewed by the company, which pretty much relieves my concern. I tried two scans from six. I first ran Quickscan which detect my computer's ports, protocols, services and possible trojans. I ran the test with and without the firewall, and the scan results showed my system was much better protected while the firewall is on. The additional information on the report is also helpful to alert you about the vulnerability of your system. The images below are part of scan results with firewall on and off.

(Scan with firewall)

(Scan without firewall)

I also ran Stealthscan which uses various stealthing techniques to penetrate firewalls. My test showed ideal "Blocked" status for each port, which means the firewall stealthed for hid all ports. The image of scan result is included below.

Recommendations:

I would recommend the Sygate Personal Firewall free version to firewall beginners who are looking for a simple but effective product. SPF begins working without additional configuration after installation; pop-up warnings are easy to understand; and it effectively blocks inappropriate connection behavior, protecting PCs from hackers and other rouge elements. Its online help file and online scan services are also pretty handy for users to customize the firewall and assess their system security

References:
Sygate Technologies
Sygate Personal Firewall 5.0Download
SPF 5.0 Online help file

Go back to INLS187 Assignments Page