Sophos

Online support

Product maintenance

Contact support

Support services

Sophos Anti-Virus for Windows 2000+: Host Intrusion Prevention System (HIPS)

Host Intrusion Prevention System (HIPS) is a security technology that protects computers from unidentified viruses and suspicious behavior. It is used in Sophos Anti-Virus for Windows 2000+.

The following types of behavior are monitored.

Runtime behavior analysis

Sophos Anti-Virus analyzes behavior of the programs running on the system. The runtime behavior analysis includes:

Suspicious file detection

Sophos Anti-Virus can scan for suspicious files, that is, files that contain certain characteristics that are common to malware but not sufficient for the files to be identified as a new piece of malware. For example, a file containing dynamic decompression code commonly used by malware can be regarded as suspicious.

Using HIPS with Sophos Anti-Virus

When Sophos Anti-Virus is first installed, it detects suspicious behavior and sends alerts to Enterprise Console. However, it does not block any of the programs detected.

See Sophos Anti-Virus for Windows 2000+: managing the detection of suspicious files and behavior for details on managing your installation.

What to do

Sophos recommends that you introduce blocking of suspicious behavior as follows:

This approach avoids blocking programs that your users may need.

If you need more information or guidance, then please contact technical support.