« Bad practices, left right and center expose MyWebSearch and Ask.com
Got Root? »

Research projects

November 14th, 2008

It’s been a while since I last posted. So here is what’s been keeping us busy at Paretologic:

- we’ve been working on live CDs as a way to eradicate rootkits. Well, the task is actually harder than it looks. There are many distros available that we are trying to customize to our needs.

- our ongoing heuristic research is showing some good results. We are developping technology capable of detecting malware without signatures. For example, brand new threats for which no vendor has had a chance to analyze can be proactively detected based on many static attributes. This is a more sophisticated way than MD5 matching but obviously there are more difficulties in deploying it.

- we have our own sandbox, which we call “logmachine”. Several improvements were done to it. It has in fact become a good resource for collecting more malware samples.

All in all, I’ve been really busy with all that stuff, which kept me off from reading my regular blogs or posting on this blog for that matter.
Also have a couple of security books on my bed side table that I’ve been reading late at night. I have a particular interest in honeypots, so this book is a good read: Virtual Honeypots: From Botnet Tracking to Intrusion Detection.

Jerome

    This entry was posted on Friday, November 14th, 2008 at 5:37 pm and is filed under Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • About
  • Contact Us



Malware Top 10

  • Privacy Center
  • Pro AntiSpyware 2009
  • Antivirus XP
  • Antivirus 2009
  • Antivirus 360
  • Internet Antivirus Pro
  • Ultimate Antivirus 2008
  • Ultimate Cleaner
  • Ultimate Defender
  • Renus



Archives

  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Botnets (2)
  • Exploits (14)
  • Fake codecs (14)
  • IM threats (1)
  • Keyloggers (1)
  • Mac security (4)
  • Malware Trends (64)
  • Phishing (5)
  • Research (25)
  • Rogue software (45)
  • Rootkits (2)
  • Uncategorized (66)
  • Wireless Security (1)



 
 
 

© 2009 ParetoLogic Inc.