« Ransom malware from Russia
A link between developers and end-users »

Zheng™ File Analysis

May 15th, 2009

I am proud to announce the official release of our File Analysis service, using our heuristic engine, nicknamed Zheng™.

I have been working with several people that have contributed to this project and I must say I have been very impressed by their expertise.

As Manager of our SWAT Team I have always been interested in innovative and creative ideas. That is one of our strengths as a young company, to always be pushing the boundaries and achieve the best level of service.

I, myself, am young to this industry. It has been roughly 4 years now but I have seen many trends in the security field. It all started with the spyware and adware craze… and along the way Botnets have taken over the stage with the Storm Worm for example.

Another drastic change is in the number of malware samples we see each day. This number has skyrocketed and shown the limitations of current Anti-Virus products.

Signature-based scanning is proven and solid, but it simply cannot keep up with the volume of samples. New methods have to be employed to detect malware.

If you look closely, those millions of threats do have things in common. Actually most of them are variants of each other. Capitalizing on that, it is possible to detect automatically generated malware that normally evades MD5 checks, for example.

Our team is working on several different techniques and algorithms. From the scientist’s point of view, to the software developper’s implementation.

There are many challenges along the way. Those make the research projects all the more fascinating and mind-boggling. We know we have to think fast though, otherwise we would be trailing behind.

So, today, we are presenting a great milestone in our research and we encourage you to give it a try and tell us what you think.

Thanks!

zheng

Jerome

    This entry was posted on Friday, May 15th, 2009 at 1:46 pm and is filed under Research. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    2.      by
    3.      by
    4.      by
    • (0) comments
    • |
    • Add your comments




RSS feed to this site
Jerome Segura is a Security Researcher at ParetoLogic.

Twitter

 

Malicious URLs

ParetoLogic, a Microsoft Certified Partner

 

 

Links

  • Malicious URLs
  • Phishing Emails
  • Free PDF Scanner
  • About
  • MalwareDiaries in the press
  • Contact Us



Archives

  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (3)
  • Banker Trojans (4)
  • Botnets (9)
  • Conferences (7)
  • DDos (2)
  • Debates (2)
  • Exploits (68)
  • Fake codecs (48)
  • Gaming (1)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (3)
  • Mac security (15)
  • Malware Trends (71)
  • P2P (1)
  • Phishing (47)
  • Podcast (1)
  • ransomware (7)
  • Research (67)
  • Rogue software (58)
  • Rootkits (2)
  • scams (13)
  • Social Networking (7)
  • Spam (4)
  • Uncategorized (122)
  • Wireless Security (2)
  • world map (1)



 
 
 
Microsoft is a registered trademark of Microsoft Corporation in the United States and/or other countries.

© 2010 ParetoLogic Inc.