Analytics
11/30/2007
07:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

AV Vendor Adopts 'Herd' Intelligence

Panda Security on Monday will roll out new anti-malware solution that analyzes new malware 'in the cloud' rather than in the lab

The flood of new malware samples anti-malware firms are sorting in their labs is so overwhelming that AV vendor Panda Security compares it to a denial-of-service attack: "It's a denial of service on AV labs trying to keep up with it," says Gary Leibowitz, general manager of Panda Security USA, which receives 3,000 to 4,000 samples of new malware daily. So his company on Monday will release a new version of its AV software that moves that analysis from the lab to the "cloud" to help it get a better handle on emerging threats such as those targeting Web 2.0 applications, Dark Reading has learned.

Panda's new version of its Panda Security for Business will include this "community cloud" feature, where the anti-malware process, computation, analysis, and signature comparisons are done by Panda's SaaS, drawing from threat information and trends with its users as well as the wider Internet community. It also comes with host intrusion prevention and auditing features.

A handful of other AV vendors have made similar moves, including ESET, Sana Security, and Prevx. Symantec's Norton Anti-Bot is based on its licensing of Sana's product, notes Andrew Jaquith, program manager for security research at The Yankee Group.

Jaquith says this strategy of moving what he calls "herd" intelligence into the cloud represents a major strategy shift for AV vendors. "Herd intelligence turns every endpoint into a malware collector, and allows decisions to be made collectively and much, much faster -- minutes versus days or months," he says. "Essentially, it inverts the laboratory model (top-down) that the AV vendors have been using for the last 20 years."

AV vendors just can't process the mounds of malware samples they receive quickly enough, he says, which is exactly what malware authors have intended. "Vendors need to figure out how to counter a very deliberate strategy by malware authors, which is to flood the labs with unique samples," he says.

Jaquith says it's a matter of survival for AV vendors, which increasingly are looking for ways to reinvent themselves as their products struggle to thwart new types of infections. "Cloud-based, collective intelligence services are the next big thing for anti-malware. I expect that every AV vendor will need to embrace an approach like this if they expect to survive."

Ryan Sherstobitoff, chief corporate evangelist for Panda, says Panda's so-called Collective Intelligence technology would allow Panda to detect a new crimeware strain, for instance, by testing it against other samples as well as correlating any trends with it with various honeynet projects as well as its partners. "We could take behavioral traces and take it back to the cloud to do an instant calculation," Sherstobitoff says. "We go from analysis to remediation to automatically generating a signature file.

"And it's also gathering information from users in the community, and provides an instantaneous correlation with other parts of the globe to predict certain threat patterns, and whether something may be very targeted, or evolving on [multiple] machines," he says.

The key is that it's a software-as-a-service model, he says. "Normal online scanners have to download a 15 megabyte file with 200,000 threats," he says. "This sits up in cloud and has the capability taking the data and analyzing it and delivering the vaccines, but not as a huge file to the PC's."

Panda's new Panda Security for Business version 4.02SP1 is a free upgrade to existing corporate customers, and priced between $44 and $85, depending on the number of seats.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Panda Security
  • Yankee Group Research Inc.
  • Sana Security Inc.
  • ESET
  • Prevx Ltd.

    Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Register for Dark Reading Newsletters
    White Papers
    Cartoon
    Current Issue
    Flash Poll
    Threat Intel Today
    Threat Intel Today
    The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
    Video
    Slideshows
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2013-2595
    Published: 2014-08-31
    The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, enables MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls for an unrestricted mmap interface, which all...

    CVE-2013-2597
    Published: 2014-08-31
    Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that lever...

    CVE-2013-2598
    Published: 2014-08-31
    app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory ...

    CVE-2013-2599
    Published: 2014-08-31
    A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.3.x enables debug logging, which allows attackers to obtain sensitive disk-encryption pas...

    CVE-2013-6124
    Published: 2014-08-31
    The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary fil...

    Best of the Web
    Dark Reading Radio
    Archived Dark Reading Radio
    This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.