What is Host Intrusion Prevention System (HIPS) and how does it work?

May 11, 2013 | BY

Malware today is so numerous and diverse that security professionals have known for some time that signature based solutions would no longer be able to cut it alone. Not only are there too many new malware files each day, some of them are able to change their shape and signature as they go along. But,if you can’t recognize something by its looks, you might be able to categorize it by its behavior. This is where methods like HIPS (Host Intrusion Prevention System) come into play.

By definition HIPS is an installed software package which monitors a single host for suspicious activity by analyzing events occurring within that host. In other words a Host Intrusion Prevention System (HIPS) aims to stop malware by monitoring the behavior of code. This makes it possible to help keep your system secure without depending on a specific threat to be added to a detection update.

Historically HIPS and firewalls are closely related. Where a firewall regulates the traffic to and from your computer based on a rule set, HIPS do more or less the same, but for the major changes made on your computer.

HIPS photo

The major changes that can be allowed for a program when creating a rule-set

HIPS solutions protect the computer against known and unknown malicious attacks. In case of attempted major changes by a hacker or malware, HIPS blocks the action and alerts the user so an appropriate decision about what to do can be made. What does the HIPS consider major changes? I made a list of possible major changes and why malware might want to make them. The list is far from complete, but more like a bare minimum of what your HIPS should be guarding:

  • Take control of other programs. For example sending a mail using the default mail client or  sending your browser to a certain site to download more malware.

  • Trying to change important registry keys, so that the program starts at certain events.

  • Ending other programs. For example your virus scanner.

  • Installing devices or drivers, so that they get started before other programs

  • Interprocess memory access, so it can inject malicious code into a trusted program.

What can you expect of a good HIPS?

At the very least it should have the power (authority) to stop active malware. If it is unable to stall another program while waiting for your decision, the battle is already lost. Additionally it should have a basic set of rules that any user can apply until he is more familiar with the software and/or the need for more elaborate rules emerges. Adapting or creating new rules should be possible (there are always exceptions to be made) and it should be user friendly to do so. For one thing it has to be very clear to the user what the consequences of his changes are, or he will find himself wondering at some point why this or that no longer works. For these cases and other help, I would also check out if there are forums (or other places) where you can find help in individual cases. A knowledge base is not always enough to find all the answers.

The normal method of a HIPS is runtime detection. It intercepts actions when they occur, but some HIPS also offer pre-execution detection. This means that the nature of an executable is analyzed before it runs, to check for suspicious behavior.

Are there any risks?

Risks associated with HIPS are false positives and wrong user decisions. HIPS respond to certain changes that other software wants to make on your system. For example any HIPS will keep an eye on the registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run and others like that, from where programs are started automatically when Windows boots up. But obviously there are many legitimate programs that use this key as well. So when a change is made to the content of that key (an extra value is added), the user will be presented with a choice, Block or Allow. For this key there are many online resources on which you can base an informed choice, but most users will hit Allow, especially if they are in the process of installing something. Some HIPS will let you know what other users have decided in this particular case, but especially when numbers are still small, this can be deceiving and it is not really a decision based on relevant information. You are only hoping the majority of the users before you was right. The system is only as good as the responses of the user to the popup alert. Even if the HIPS software correctly identifies a threat, the user may inadvertently approve the wrong action and the PC could still become infected.

Conclusions: HIPS can be a valuable part of a layered defense, but I would advise to add at least one detection based security solution. While HIPS should be for everyone, it requires at least a decent knowledge of computing to use them effectively.

Sources :

  • xyz360400 .

    “While HIPS should be for everyone, it requires at least a decent knowledge of computing to use them effectively.”

    This is why I hate HIPS and software firewalls in general. The people who truly need them most often (novice computer users who aren’t educated on PC security and what high risk behaviors are) aren’t going to know enough to make informed decisions and will typically do more harm to their systems than good in attempting to operate a HIPS or software firewall.

    I consider myself to be pretty knowledgeable with regards to computing. I understand security software, the registry, policies, malware and spent several years working as a PC technician, yet I’ve never found a HIPS that even I could operate efficiently and effectively with any level of comfortable certainty that every response I gave to an ‘Allow’ or ‘Block’ prompt was the correct one.

    I’d rather use an anti-malware tool that uses signatures based on behaviors to positively identify malicious executables and actions without relying on me to make that determination. The entire point of security software to me is to identify malicious activity and prevent it, not rely on my judgment to do so. If I was able to make such decisions intelligently, I probably wouldn’t need any security software.

  • Pingback: Security: Finding the balance | Malwarebytes Unpacked()

  • Pingback: How can I use Windows XP safely now it’s no longer supported? |

  • Pingback: Host Intrusion Prevention System (HIPS) and How it works? | Cyber Security News, Information, Tips and Hacks()

  • Jaydeep Dave

    Trend Micro’s Deep Security is the top most HIPS in the world.

  • Pieter Arntz

    I’m glad you found one that you like. :)

  • wbf850

    HIPS… all for them

  • Pingback: .Net framework update 4.5.2 breaks State server …. - Irfank - Blogs - Site Home - MSDN Blogs()

  • Gordon King

    I am an XP diehard and have secured my system with Malware Defender 2.88 and have achieved excellent results even though I do not consider myself to be an expert. I tested Malware Defender with the Commodo Firewall Test Suite sometimes known as the Commodo Leak Test and it achieved a score of 330/340 which I think is an awesome result.