|
Concerning to Kaspersky Internet Security 7.0 (all builds)
Protection of confidential data (Privacy Control) is a module of Kaspersky Internet Security 7.0 which protects from unauthorized access and confidential data transfer: such as e-mail addresses, credit numbers, etc.
This module controls the following attempts to access confidential data:
- Attempt to send confidential data via WebBrowser
- Attempt to access personal data and passwords
Attempt to send confidential data
In order to transfer the data this way a malicious code embeds itself into the browser’s process which is usually added to all lists of trusted applications. Next this malicious code creates a hidden copy of the process, for example, iexplore.exe and uses a new process as a transport to transfer any data from your computer by http-protocol. Transferred confidential data are extracted from the corresponding file and encrypted before the transfer.
When such activity is detected you are suggested either Allow, Block or Finish the process and send the suspicious software to quarantine.
Attempt to access personal data and passwords
Protected Storage is an OS mechanism developed to store personal data, such as encrypted keys, to prevent unauthorized access of services, processes and users. This storage usually stores local passwords and web-info (autofill). Protected Storage usually stores passwords and logins to e-boxes, forums, chats, web-stores and other web-services.
These data are entered into corresponding fields of the mail clients and browsers. As a rule, when these data are entered you can save them by checking the necessary box. If the “save password” box is checked these data are saved by the Protected Storage service.
Tip: users who are afraid of info leak from the Protected Storage and as a consequence do not save passwords and data in the browser, still save their passwords of mail boxes as it takes much time to enter a password each time you get or send a mail. We should also consider that e-mail password and Internet access password usually coincide by internet-providers. Getting a password would give access both to a mail box and to internet connection.
Data from the Protected Storage can be extracted by a special Spyware and then sent to cyber-criminals. To prevent such situations the module Protection of confidential data informs us of each attempt to read data from the Protected Storage by the application which is not digitally signed by Microsoft Corporation. Depending on whether you trust the application or not - which tries to get access to read the data from the storage - you can Allow or Block execution of the operation or Finish the process and send this software to quarantine.
|