Analytics
11/30/2007
07:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

AV Vendor Adopts 'Herd' Intelligence

Panda Security on Monday will roll out new anti-malware solution that analyzes new malware 'in the cloud' rather than in the lab

The flood of new malware samples anti-malware firms are sorting in their labs is so overwhelming that AV vendor Panda Security compares it to a denial-of-service attack: "It's a denial of service on AV labs trying to keep up with it," says Gary Leibowitz, general manager of Panda Security USA, which receives 3,000 to 4,000 samples of new malware daily. So his company on Monday will release a new version of its AV software that moves that analysis from the lab to the "cloud" to help it get a better handle on emerging threats such as those targeting Web 2.0 applications, Dark Reading has learned.

Panda's new version of its Panda Security for Business will include this "community cloud" feature, where the anti-malware process, computation, analysis, and signature comparisons are done by Panda's SaaS, drawing from threat information and trends with its users as well as the wider Internet community. It also comes with host intrusion prevention and auditing features.

A handful of other AV vendors have made similar moves, including ESET, Sana Security, and Prevx. Symantec's Norton Anti-Bot is based on its licensing of Sana's product, notes Andrew Jaquith, program manager for security research at The Yankee Group.

Jaquith says this strategy of moving what he calls "herd" intelligence into the cloud represents a major strategy shift for AV vendors. "Herd intelligence turns every endpoint into a malware collector, and allows decisions to be made collectively and much, much faster -- minutes versus days or months," he says. "Essentially, it inverts the laboratory model (top-down) that the AV vendors have been using for the last 20 years."

AV vendors just can't process the mounds of malware samples they receive quickly enough, he says, which is exactly what malware authors have intended. "Vendors need to figure out how to counter a very deliberate strategy by malware authors, which is to flood the labs with unique samples," he says.

Jaquith says it's a matter of survival for AV vendors, which increasingly are looking for ways to reinvent themselves as their products struggle to thwart new types of infections. "Cloud-based, collective intelligence services are the next big thing for anti-malware. I expect that every AV vendor will need to embrace an approach like this if they expect to survive."

Ryan Sherstobitoff, chief corporate evangelist for Panda, says Panda's so-called Collective Intelligence technology would allow Panda to detect a new crimeware strain, for instance, by testing it against other samples as well as correlating any trends with it with various honeynet projects as well as its partners. "We could take behavioral traces and take it back to the cloud to do an instant calculation," Sherstobitoff says. "We go from analysis to remediation to automatically generating a signature file.

"And it's also gathering information from users in the community, and provides an instantaneous correlation with other parts of the globe to predict certain threat patterns, and whether something may be very targeted, or evolving on [multiple] machines," he says.

The key is that it's a software-as-a-service model, he says. "Normal online scanners have to download a 15 megabyte file with 200,000 threats," he says. "This sits up in cloud and has the capability taking the data and analyzing it and delivering the vaccines, but not as a huge file to the PC's."

Panda's new Panda Security for Business version 4.02SP1 is a free upgrade to existing corporate customers, and priced between $44 and $85, depending on the number of seats.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Panda Security
  • Yankee Group Research Inc.
  • Sana Security Inc.
  • ESET
  • Prevx Ltd.

    Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Register for Dark Reading Newsletters
    White Papers
    Cartoon
    Current Issue
    Dark Reading Tech Digest, Dec. 19, 2014
    Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
    Flash Poll
    Threat Intel Today
    Threat Intel Today
    The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
    Video
    Slideshows
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2014-7241
    Published: 2014-12-19
    The TSUTAYA application 5.3 and earlier for Android allows remote attackers to execute arbitrary Java methods via a crafted HTML document.

    CVE-2014-7249
    Published: 2014-12-19
    Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745, AR750S, AR750S-DP, AT-8624POE, AT-8624T/2M, AT-8648T/2SP, AT-8748XL, AT-8848, AT-9816GB, AT-9924T, AT-9924Ts, CentreCOM AR415S, CentreCOM AR450S, CentreCOM AR550S, CentreCOM AR570S, CentreCOM 8700SL, CentreCOM 8948XL, CentreCOM 992...

    CVE-2014-7267
    Published: 2014-12-19
    Cross-site scripting (XSS) vulnerability in the output-page generator in the Ricksoft WBS Gantt-Chart add-on 7.8.1 and earlier for JIRA allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-7268.

    CVE-2014-7268
    Published: 2014-12-19
    Cross-site scripting (XSS) vulnerability in the data-export feature in the Ricksoft WBS Gantt-Chart add-on 7.8.1 and earlier for JIRA allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-7267.

    CVE-2014-8272
    Published: 2014-12-19
    The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.

    Best of the Web
    Dark Reading Radio
    Archived Dark Reading Radio
    Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.