Analytics
11/30/2007
07:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

AV Vendor Adopts 'Herd' Intelligence

Panda Security on Monday will roll out new anti-malware solution that analyzes new malware 'in the cloud' rather than in the lab

The flood of new malware samples anti-malware firms are sorting in their labs is so overwhelming that AV vendor Panda Security compares it to a denial-of-service attack: "It's a denial of service on AV labs trying to keep up with it," says Gary Leibowitz, general manager of Panda Security USA, which receives 3,000 to 4,000 samples of new malware daily. So his company on Monday will release a new version of its AV software that moves that analysis from the lab to the "cloud" to help it get a better handle on emerging threats such as those targeting Web 2.0 applications, Dark Reading has learned.

Panda's new version of its Panda Security for Business will include this "community cloud" feature, where the anti-malware process, computation, analysis, and signature comparisons are done by Panda's SaaS, drawing from threat information and trends with its users as well as the wider Internet community. It also comes with host intrusion prevention and auditing features.

A handful of other AV vendors have made similar moves, including ESET, Sana Security, and Prevx. Symantec's Norton Anti-Bot is based on its licensing of Sana's product, notes Andrew Jaquith, program manager for security research at The Yankee Group.

Jaquith says this strategy of moving what he calls "herd" intelligence into the cloud represents a major strategy shift for AV vendors. "Herd intelligence turns every endpoint into a malware collector, and allows decisions to be made collectively and much, much faster -- minutes versus days or months," he says. "Essentially, it inverts the laboratory model (top-down) that the AV vendors have been using for the last 20 years."

AV vendors just can't process the mounds of malware samples they receive quickly enough, he says, which is exactly what malware authors have intended. "Vendors need to figure out how to counter a very deliberate strategy by malware authors, which is to flood the labs with unique samples," he says.

Jaquith says it's a matter of survival for AV vendors, which increasingly are looking for ways to reinvent themselves as their products struggle to thwart new types of infections. "Cloud-based, collective intelligence services are the next big thing for anti-malware. I expect that every AV vendor will need to embrace an approach like this if they expect to survive."

Ryan Sherstobitoff, chief corporate evangelist for Panda, says Panda's so-called Collective Intelligence technology would allow Panda to detect a new crimeware strain, for instance, by testing it against other samples as well as correlating any trends with it with various honeynet projects as well as its partners. "We could take behavioral traces and take it back to the cloud to do an instant calculation," Sherstobitoff says. "We go from analysis to remediation to automatically generating a signature file.

"And it's also gathering information from users in the community, and provides an instantaneous correlation with other parts of the globe to predict certain threat patterns, and whether something may be very targeted, or evolving on [multiple] machines," he says.

The key is that it's a software-as-a-service model, he says. "Normal online scanners have to download a 15 megabyte file with 200,000 threats," he says. "This sits up in cloud and has the capability taking the data and analyzing it and delivering the vaccines, but not as a huge file to the PC's."

Panda's new Panda Security for Business version 4.02SP1 is a free upgrade to existing corporate customers, and priced between $44 and $85, depending on the number of seats.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Panda Security
  • Yankee Group Research Inc.
  • Sana Security Inc.
  • ESET
  • Prevx Ltd.

    Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Register for Dark Reading Newsletters
    Partner Perspectives
    What's This?
    In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

    As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
    Featured Writers
    White Papers
    Cartoon
    Current Issue
    Dark Reading's October Tech Digest
    Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
    Flash Poll
    Threat Intel Today
    Threat Intel Today
    The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
    Video
    Slideshows
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2014-2021
    Published: 2014-10-24
    Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.4.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

    CVE-2014-3604
    Published: 2014-10-24
    Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    CVE-2014-6230
    Published: 2014-10-24
    WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header.

    CVE-2014-6251
    Published: 2014-10-24
    Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a mining.subscribe response with a large nonce2 length, then triggering the overflow with a mining.notify request.

    CVE-2014-7180
    Published: 2014-10-24
    Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.

    Best of the Web
    Dark Reading Radio
    Archived Dark Reading Radio
    Follow Dark Reading editors into the field as they talk with noted experts from the security world.