Ryan Sherstobitoff

Chief Corporate Evangelist

 

Herd Intelligence and Automated Malware Analysis: True Protection from Targeted Attacks
 
With an estimated 4,000 new malware samples cropping up every day, even the most sophisticated anti-virus vendors are inefficient in detecting, and more importantly, vaccinating against this new threat landscape. This new breed no longer relies on massive propagation or that of destructive pay-loads, but rather attacks solely for economical gain. The traditional means of receiving signature files in the lab from various feeds and then to a certain degree, manually conducting a suspect file analysis on each sample, is severely antiquated and highly inefficient. With the overwhelming rate of new and unique malware samples, the manual tedium of the reverse engineering and signature creation process creates an eternal and never ending backlog of malware samples that will never be addressed. That is a reality and a risk that no company can afford to take.

 This evolving threat landscape is in dire need of a solution that is proactive, but provides better protection than current resident proactive models such as HIPS; more importantly, also address the immediate need for real-time automated detection and vaccination of emerging threats. Herd intelligence, which relies on an entire community of users for malware detection, coupled with the automatic processing of new behavioral traits and suspect information discovered by the community, offers exponentially greater protection from the very real threat of targeted malware. Yankee Group contends that security labs must “make herd intelligence central to their long-term survival strategies” in order to stay ahead of the insidious threat landscape.

New layers of protection are needed to take advantage of automating the entire malware protection cycle – from sample collection, analysis, classification, to remediation. But automation by itself is not enough. The added layer of defense is where herd intelligence comes into play. By using the immediate correlations of all the detections by the community of users, it provides real-time targeted attack detection on a truly global basis.

In this presentation, Panda Security will provide a highly technical overview on:

  • How herd Intelligence is critical for staying one-step ahead of the hackers by increasing visibility into the threat landscape
  • Enhancing the collection, classification and remediation process through an automated approach
  • Protecting companies against targeted attacks – which focus on very few users through the process of aggregating intelligence gathered within the community of users, versus locally and by correlating behavioral traits with historical information

Biography

Ryan Sherstobitoff is chief corporate evangelist of Panda Security, where he oversees and manages the strategic response to new and emerging virus attacks. Sherstobitoff's extensive experience includes work designing and managing network infrastructures, as well as mobilizing and managing security technologies throughout widely dispersed large-scale networks. He has worked on a variety of security technologies in a myriad of platforms and environments, including financial, industrial, and service infrastructures. Prior to joining Panda Security, Sherstobitoff worked as a consultant for GE and Crystal Decisions (Business Objects).