Analytics
11/30/2007
07:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

AV Vendor Adopts 'Herd' Intelligence

Panda Security on Monday will roll out new anti-malware solution that analyzes new malware 'in the cloud' rather than in the lab

The flood of new malware samples anti-malware firms are sorting in their labs is so overwhelming that AV vendor Panda Security compares it to a denial-of-service attack: "It's a denial of service on AV labs trying to keep up with it," says Gary Leibowitz, general manager of Panda Security USA, which receives 3,000 to 4,000 samples of new malware daily. So his company on Monday will release a new version of its AV software that moves that analysis from the lab to the "cloud" to help it get a better handle on emerging threats such as those targeting Web 2.0 applications, Dark Reading has learned.

Panda's new version of its Panda Security for Business will include this "community cloud" feature, where the anti-malware process, computation, analysis, and signature comparisons are done by Panda's SaaS, drawing from threat information and trends with its users as well as the wider Internet community. It also comes with host intrusion prevention and auditing features.

A handful of other AV vendors have made similar moves, including ESET, Sana Security, and Prevx. Symantec's Norton Anti-Bot is based on its licensing of Sana's product, notes Andrew Jaquith, program manager for security research at The Yankee Group.

Jaquith says this strategy of moving what he calls "herd" intelligence into the cloud represents a major strategy shift for AV vendors. "Herd intelligence turns every endpoint into a malware collector, and allows decisions to be made collectively and much, much faster -- minutes versus days or months," he says. "Essentially, it inverts the laboratory model (top-down) that the AV vendors have been using for the last 20 years."

AV vendors just can't process the mounds of malware samples they receive quickly enough, he says, which is exactly what malware authors have intended. "Vendors need to figure out how to counter a very deliberate strategy by malware authors, which is to flood the labs with unique samples," he says.

Jaquith says it's a matter of survival for AV vendors, which increasingly are looking for ways to reinvent themselves as their products struggle to thwart new types of infections. "Cloud-based, collective intelligence services are the next big thing for anti-malware. I expect that every AV vendor will need to embrace an approach like this if they expect to survive."

Ryan Sherstobitoff, chief corporate evangelist for Panda, says Panda's so-called Collective Intelligence technology would allow Panda to detect a new crimeware strain, for instance, by testing it against other samples as well as correlating any trends with it with various honeynet projects as well as its partners. "We could take behavioral traces and take it back to the cloud to do an instant calculation," Sherstobitoff says. "We go from analysis to remediation to automatically generating a signature file.

"And it's also gathering information from users in the community, and provides an instantaneous correlation with other parts of the globe to predict certain threat patterns, and whether something may be very targeted, or evolving on [multiple] machines," he says.

The key is that it's a software-as-a-service model, he says. "Normal online scanners have to download a 15 megabyte file with 200,000 threats," he says. "This sits up in cloud and has the capability taking the data and analyzing it and delivering the vaccines, but not as a huge file to the PC's."

Panda's new Panda Security for Business version 4.02SP1 is a free upgrade to existing corporate customers, and priced between $44 and $85, depending on the number of seats.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Panda Security
  • Yankee Group Research Inc.
  • Sana Security Inc.
  • ESET
  • Prevx Ltd.

    Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Register for Dark Reading Newsletters
    White Papers
    Cartoon
    Current Issue
    Flash Poll
    Threat Intel Today
    Threat Intel Today
    The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
    Video
    Slideshows
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2014-3352
    Published: 2014-08-30
    Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh...

    CVE-2014-3908
    Published: 2014-08-30
    The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    CVE-2010-5110
    Published: 2014-08-29
    DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

    CVE-2012-1503
    Published: 2014-08-29
    Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

    CVE-2013-5467
    Published: 2014-08-29
    Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM)...

    Best of the Web
    Dark Reading Radio
    Archived Dark Reading Radio
    This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.