3 ms·
Next-gen AV does not rely on signatures to detect malware so much as heuristics on steroids. I am especially familiar with SentinelOne. It can detect 0-day rans
by teilo 6y ago
Next-gen AV does not rely on signatures to detect malware so much as heuristics on steroids. I am especially familiar with SentinelOne. It can detect 0-day ransomeware, for example, as soon as it tries to encrypt files, and stop it in its tracks. Any product that does rely on signatures is useless these days.
- dogma1138 6y agoThe heuristics aren’t on steroids but rather basic, SentinalOne, CrowdStrike, CarbonBlack etc. are still as dumb as a door knob, yes they can detect ransomeware because it’s quite easy to detect but their heuristics don’t extend to anything that is remotely sophisticated and doesn’t simply nuke the entire system.
- tgragnato 6y agoI can’t upvote this enough. An heuristic will always be an heuristic, it does not matter of which kind or what you are looking at. These products are not deterministic and they give you no assurance whatsoever.
- dogma1138 6y agoTo add to how simplistic their heuristics are we had a demo of one of the mentioned above ransomware detection. Their demo was about 2 hours long, during it I’ve written my own ransomware in a few lines. It used cipher.exe a command line utility that allows you to encrypt files, with about 5 lines of a batch script (well it was pinvoke in my case) I had a ransomware that would encrypt all document files in the user’s home directory with a new EFS cert, generate an EFS recovery agent and upload it to a webdav share, delete the EFS certificate from the system, then using the same cipher.exe utility secure wipe option (/w) nuke the file system and overwrite all deleted data to make both forensics and recovery near impossible. Since cipher.exe is a signed Microsoft executable it wasn’t detected. Their response was that they haven’t seen malware use this before and they were looking for windows crypto API calls, CPU metrics and other nonsense and assured us that it’s highly unlikely that anyone would use built-in command line utilities when compromising our network.
- sb23 6y agoSeems like if it were feasible it would already be being used by malware authors. Why would they not already be using cipher.exe?
- dogma1138 6y agoSome do, at least according to Sophos https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophoslabs-ransomware-behavior-report.pdf https://www.sophos.com/en-us/medialibrary/PDFs/technical-pap... And why would not re-inventing the wheel be a problem that malware developers have solved? ;)