|
|
Herd Intelligence and Automated
Malware Analysis: True Protection from Targeted Attacks
With an estimated 4,000 new malware samples cropping up
every day, even the most sophisticated anti-virus vendors
are inefficient in detecting, and more importantly,
vaccinating against this new threat landscape. This new
breed no longer relies on massive propagation or that of
destructive pay-loads, but rather attacks solely for
economical gain. The traditional means of receiving
signature files in the lab from various feeds and then to a
certain degree, manually conducting a suspect file analysis
on each sample, is severely antiquated and highly
inefficient. With the overwhelming rate of new and unique
malware samples, the manual tedium of the reverse
engineering and signature creation process creates an
eternal and never ending backlog of malware samples that
will never be addressed. That is a reality and a risk that
no company can afford to take.
This evolving threat landscape is in dire need of a solution that is proactive, but provides better protection than current resident proactive models such as HIPS; more importantly, also address the immediate need for real-time automated detection and vaccination of emerging threats. Herd intelligence, which relies on an entire community of users for malware detection, coupled with the automatic processing of new behavioral traits and suspect information discovered by the community, offers exponentially greater protection from the very real threat of targeted malware. Yankee Group contends that security labs must “make herd intelligence central to their long-term survival strategies” in order to stay ahead of the insidious threat landscape. New layers of protection are needed to take advantage of automating the entire malware protection cycle – from sample collection, analysis, classification, to remediation. But automation by itself is not enough. The added layer of defense is where herd intelligence comes into play. By using the immediate correlations of all the detections by the community of users, it provides real-time targeted attack detection on a truly global basis. In this presentation, Panda Security will provide a highly technical overview on:
Biography
Ryan Sherstobitoff is chief corporate evangelist of
Panda Security, where he oversees and manages the
strategic response to new and emerging virus attacks.
Sherstobitoff's extensive experience includes work
designing and managing network infrastructures, as well
as mobilizing and managing security technologies
throughout widely dispersed large-scale networks. He has
worked on a variety of security technologies in a myriad
of platforms and environments, including financial,
industrial, and service infrastructures. Prior to
joining Panda Security, Sherstobitoff worked as a
consultant for GE and Crystal Decisions (Business
Objects).
|