Home > Ask the Security Experts > Information Security Threats Questions & Answers > Can 'herd intelligence' effectively stop malware?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Can 'herd intelligence' effectively stop malware?

Ed Skoudis EXPERT RESPONSE FROM: Ed Skoudis

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 30 December 2007
How effective has "herd intelligence" been in fighting malware?

>
EXPERT RESPONSE
It's actually been quite an effective tool in our arsenals. For the uninitiated, "herd intelligence" involves having thousands of machines -- often including production desktop and laptop computers -- running antimalware software to identify new forms of malicious code as they are released. Some antimalware vendors have products whose code can report back new infectious specimens to the vendors for analysis. In effect, all users of the antimalware tool become a distributed sensor net, finding new specimens that are potentially evil.

One example of this approach is Microsoft's Windows Defender, which allows a "vote" on newly discovered threats. Users can determine whether the threats should be deleted, quarantined, or allowed by default. Automatic reports are sent across the network to a system that Microsoft calls "Microsoft SpyNet". Despite the ominous name, the functionality behind it is an excellent example of distributed computing that implements a form of herd intelligence. Such techniques allow Microsoft to determine what specimens it should write signatures for. Based on real-world customer needs, a company can optimize detection and the actions that its product should take.

Other herd intelligence systems include behavior-based detection mechanisms, which hunt for phishing imposter Web sites and other sites that contain browser-exploiting URLs. The findings are all reported back to the vendor in a distributed fashion, improving the collective intelligence of the antimalware system. I whole-heartedly expect to see more of this kind of technique in the future.

More information:

  • Like other antivirus vendors, Panda Security is trying to update its products to fit the times. Company execs explain why a focus on Internet transaction security is the answer.
  • Endpoint security is changing at a breathtaking pace. Senior Technology Editor Neil Roiter reveals why signature-based AV may not be enough.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Information Security Threats
    What are the dangers of cross-site request forgery attacks (CSRF)?
    Should social engineering tests be included in penetration testing?
    What kind of data is compromised during a Google hack?
    Best practices for using restriction policy whitelists
    Defining mobile device security concerns
    What security measures can be taken to stop crimeware kits?
    What software development best practices can prevent input validation attacks?
    What is the most secure way for application developers to manage cookies?
    Is there a market for standalone antivirus products?
    Should keystroke loggers be used in enterprise investigations?

    Viruses, Worms and Other Malware
    Yahoo, McAfee to warn users of dangerous websites
    Botnets and ethics
    Trojan downloaders, droppers skyrocket, Microsoft says
    New phishing, Zeus Trojan technique spreads crimeware
    Researchers uncover tool used to infect websites, spread malware
    RSA 2008: Defeating botnets
    Malware found on HP ProLiant server USB keys
    Is there a market for standalone antivirus products?
    Panda latest AV firm trying to adapt with the times
    PDF spam reemerges in some inboxes

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    bot worm  (SearchSecurity.com)
    directory traversal  (SearchSecurity.com)
    Kraken  (SearchSecurity.com)
    man in the browser  (SearchSecurity.com)
    Mytob  (SearchSecurity.com)
    polymorphic malware  (SearchSecurity.com)
    RavMonE virus  (SearchSecurity.com)
    RFID virus  (SearchSecurity.com)
    Rock Phish  (SearchSecurity.com)
    Zotob  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts