查看: 16172|回复: 119
收起左侧

[资讯] [佳哥资讯]诺顿2011中的SONAR 3(原创翻译){正式开贴}

  [复制链接]
皇甫暮云
发表于 2010-4-24 12:21:21 | 显示全部楼层 |阅读模式
本帖最后由 jiayan72392 于 2010-4-24 13:21 编辑

以下内容转自Norton Protection Blog,原文链接:http://community.norton.com/t5/Norton-Protection-Blog/SONAR-3-A-new-level-of-behavioral-security-in-Norton-2011/ba-p/224116
SONAR 3: A new level of behavioral security in Norton 2011
by sourabhsatish on 04-23-2010 11:47 AM


This year we have some innovative changes that build upon the successful, effective, and efficient SONAR 2 behavioral security engine. For those who are not familiar with SONAR technology, here is a link to an article that describes it. With SONAR 2, we have a proven track record of being able to convict malware and secure Norton users from malware designed to evade most other security features. In the last nine months alone we prevented upward of 4.2 million infections out of about 140 million incidents that we analyzed for Norton users. Most of these incidents were never-before-seen malware and infection scenarios, thus truly providing "zero-day" protection! The effectiveness of our technology was repeatedly confirmed by external 3rd-party tests  and reviews (specifically behavioral security tests and reviews), where we performed at or near 100% detection rates. Behavioral security is a critical security solution, especially in this era of server-side polymorphic malware where each and every infection can have a unique piece of malware file (unique from the file fingerprint perspective) downloaded on the victim's machine. We are very excited about our next SONAR 3 release outperforming SONAR 2!
What's next?
We believe that security is a journey and not a destination.  Over the last year, we have taken note of a couple of interesting trends in the malware world, such as a surge in the misleading application threat category and targeted, sophisticated attacks like Hydraq. It was gratifying to see that SONAR 2 detected Hydraq without any changes to our classifier. We have further fine-tuned the classifier to deal with these trends. We have also added about 60 new features to our classifier and have seen significant improvement in threat detection rates in our internal lab testing. This brings our set of features to about 400!
This large number of features give us the advantage that, with SONAR tracking and inspecting so many aspects about a file, a process, or its related activity for classification, it becomes that much harder for a malware variant to get past our classification engine or for a clean sample to be misclassified. Of course the challenge is in analyzing all this information almost instantaneously without impacting system performance, while making decisions automatically for the user. And SONAR 3 is proof of how all of this is possible.

Having analyzed more than 140 million incidents for millions of Norton users, in SONAR 3 we have added many more features and provisions for identifying clean samples so that we can specifically focus on suspicious scenarios. This is what enables us to continue to add to our feature set for an even more accurate classifier. The quicker we can ignore a sample and classify it as clean, better the user experience.

In addition to the changes we have made to add many more attributes, the SONAR team has been very busy adapting and creating new classifiers as the world of malware and clean software evolves. The team has been busy updating our classifiers and releasing seven definition updates in the last nine months since shipping SONAR 2. The SONAR team generated and evaluated over 200 different classifiers since we shipped SONAR last year, addressing the feedback we have gotten from our Norton users to convict more malware and reduce the infrequent false-positive incidents that have occurred.

One major threat category that we have focused on with SONAR 3 is misleading applications. This class of threat has gotten much attention and we are glad to be able to provide significant improvements for detecting it in SONAR 3.

We have also made further improvements in the area of behavioral signatures, where we can quickly react to new and upcoming threats by writing behavioral signatures that leverage specific features. While our classifier has been quite successful at detecting new and emerging threats and their variants, we believe in a layered security model. In some specific threat scenarios it is more effective and worthwhile to target the threat with its specific characteristics than to leave it to a classifier.

As has been detailed in the SONAR 2 posts,  SONAR aggregates and correlates information from a number of engines within the product like the Firewall, AV Engine, Intrusion Prevention Engine, etc. All this information is then used by the classifier to improve efficacy. We feel this is a big differentiator for Norton over other vendors. Most other security products simply don’t have this depth and breadth of information to make a good classifier. In SONAR 3 we have further enhanced our integration with the network component in order to classify, convict, and remediate malware on the basis of its malicious network activity. With this feature in place, we will continue to block and remove many new variants of malware that leave their network footprint unchanged.

With these and all the improvements we are continuing to work on, we believe we are taking behavioral security to a whole new level. We hope that these new improvements will prove to be invaluable in dealing with the fast-evolving threat landscape and in keeping you safe. We cannot wait to ship SONAR 3 out to millions of Norton users. All the Norton 2010 and N360v4 users will also benefit from these advances, thanks to the ability to use Live Update for SONAR enhancements that we adopted with SONAR 2.

So that’s what we are up to! Let us know what you think--the SONAR team values your feedback and we hope you see all the improvements in the public Beta. Your feedback helps us know where we need to improve and we take your comments and suggestions as our most important barometer of success!

评分

参与人数 10经验 +20 魅力 +1 人气 +8 收起 理由
ikimi + 1 2L精品文章
田藏锋 + 1 刚下班不久~ 速来支持汝!
kav2046 + 1 期待NIS2011
xffsfy + 20 版区有你更精彩: )
gujiutian + 1

查看全部评分

皇甫暮云
 楼主| 发表于 2010-4-24 13:09:26 | 显示全部楼层

以下内容为佳哥人工翻译文

本帖最后由 jiayan72392 于 2010-4-24 14:53 编辑

SONAR 3:诺顿2011中的一种全新行为判断安全技术

今年我们基于成功的,有效的和高效率的SONAR 2行为判断安全引擎上有了一些新的创新性改变。对于不熟悉SONAR技术的用户,请点击此处阅读一篇详细描述它的文章。在SONAR 2的帮助下,我们拥有一套被证实的跟踪记录,此记录记载了判断恶意软件的能力以及帮助诺顿用户安全地防范一些专门被设计躲避多数其它安全功能的恶意软件。仅在过去的9个月里,我们为诺顿用户分析1.4亿安全事故,其中阻止了将近420万个恶意感染。这些事故中多数都曾经没有看到过恶意软件或者入侵情况,因此他们被我们真正提供了“极光”防护!我们技术的效率多次被外界的第三方评测机构所肯定(尤其是行为安全评测),他们确信我们能够达到近100%的检测率。行为安全是一项至关重要的安全解决方案,尤其对于目前服务器端来说:多样化的恶意软件可能拥有独自的,与众不同的恶意文件(从文件指纹中可以区别出),然后被下载到受害者的机器中。我们对于下一代SONAR 3的发布并且取代SONAR 2感到无比兴奋。

下一步会是什么?

我们相信安全技术是一趟旅程而非终点。在去年,我们记录了在恶意软件领域中一部分有趣的趋势,比如说,诱导恶意威胁大爆发,被定向且成熟的黑客攻击Hydraq。令人高兴的是,在不改变我们分类器的情况下,SONAR 2完全可以检查出Hydraq。之后我们进一步改进了分类器使它能够更好地处理这一系列威胁。同样,我们为分类器增加了60多种新功能,在我们内部的实验室测试中威胁检测率被大幅提高。这个使我们的功能数量达到了近400!
这个巨大的功能数量给我们带来了很多优势。在SONAR跟踪并检测多种文件,进程或者相关活动的方方面面然后对其进行分类,某个恶意软件变种想要通过我们的分类引擎会变得更加困难。相似地,要将一个正常的实例错误归类也会不太可能。显然,对我们的挑战就是不影响系统性能的前提下,在将近片刻的时间内分析出所有信息,并且为用户自动作出最后的决定。SONAR 3正是将这一切变成现实的证明。

分析了数以亿计的诺顿用户中超过1.4亿的安全事件后,在SONAR 3中我们添加了许多新功能和区分正常文件的实例,这样我们就能将重点放在那些恶意实例了。以上这些使我们继续添加了新功能来创建出一个更加准确的分类器。要是我们忽略一个实例并把它划分为正常文件的速度越快,用户体验就越好。

除了我们增加更多种参数的改变之外,随着世界上恶意软件和正常软件的变种,SONAR研发团队忙于整合和创建出新的分类器。自从采用SONAR 2以来,在过去的9个月中,研发团队曾经忙于更新我们的分类器并且发布7个定义更新。去年SONAR开发小组开发并评测了超过200个不同的分类器,从我们的诺顿用户中吸取了反馈信息来定义更多的恶意软件同时减少发生过的非正常误报事件。

诱导程序在SONAR 3中是我们重点研究的严重威胁之一。此类威胁已经被重点监测,我们跟高兴在SONAR 3中提供更显著的改进来检测它。

我们同样在行为签名领域中做出了更进一步的改进,在此我们编写了可促使相应功能改变的行为签名,这样可使我们很快地对新的威胁作出反应。我们信赖一个被分层化的安全建模,这样我们的分类器会非常成功地检测出新的威胁以及他们的变种。在一些特定的安全事例中,比起让分类器来处理某个威胁,根据它的特征属性来定向此威胁会更加值得,更加有效。

在SONAR 2帖子中所记载,SONAR是根据产品中一系列的引擎例如防火墙,防毒引擎,入侵防护引擎等等来收集和整合信息的。然后所有这些信息会分类器所使用来提高效能。我们认为这是诺顿和其他厂商的一个很大的区别。很多其他安全厂商没有如此庞大的信息来制作好的分类器。为了根据其网络恶意活动来更好地区分,定义和整合恶意软件,在SONAR 3中我们更进一步加强了我们网络部件的整合。有了这个特色功能,我们会持续阻止和移除很多新恶意软件变种并且不改变他们的网络足迹。

有了这些我们持续奋斗所产生的进步,我们相信我们将行为判断安全提升到了一个全新的境界。我们希望这些新的改进会被证明在快速变化的威胁环境中以及保障您的安全中是极其宝贵的。我们已经迫不及待地将SONAR 3推送到我们数以百万计的诺顿用户手中。多亏了使用Livepdate来接受SONAR增强组件的能力,所有诺顿2010和诺顿360 4.0版的用户会同样得到这些我们在SONAR 2中所采用的优势。

以上这些就是我们目前所达到的高度。请让我们知道您的想法。SONAR研发团队会非常重视您的想法,同样我们也希望您在公测版中体会到所有的这些改进。您的反馈会让我们知道哪里需要改进,我们会将您的评价和建议作为我们成功的晴雨表。

(完)
皇甫暮云
 楼主| 发表于 2010-4-24 13:16:21 | 显示全部楼层
此贴正式开启
woaizca
发表于 2010-4-24 13:18:49 | 显示全部楼层
来抢一个。。。。。
gujiutian
发表于 2010-4-24 13:18:56 | 显示全部楼层
顶了一下,呵呵,也快到使用时候了啊
Inner
发表于 2010-4-24 13:26:30 | 显示全部楼层
希望诺顿能变得更强
popfather
头像被屏蔽
发表于 2010-4-24 13:31:54 | 显示全部楼层
看来sonar3有望改进误报严重的问题?
皇甫暮云
 楼主| 发表于 2010-4-24 13:37:12 | 显示全部楼层
看来sonar3有望改进误报严重的问题?
popfather 发表于 2010-4-24 13:31


应该是有改进的,文中专门谈到了关于误报的问题
popfather
头像被屏蔽
发表于 2010-4-24 13:41:28 | 显示全部楼层
应该是有改进的,文中专门谈到了关于误报的问题
jiayan72392 发表于 2010-4-24 13:37



    有空跟10比较下sonar
zhilu
发表于 2010-4-24 13:44:02 | 显示全部楼层
佳哥来翻译下这篇
http://translate.googleusercontent.com/translate_c?hl=zh-CN&langpair=en|zh-CN&u=http://community.norton.com/t5/Norton-Protection-Blog/Intrusion-Prevention-System-IPS-Your-first-line-of-defense/ba-p/124400%3Bjsessionid%3D4CC50F4E4C7A8783B564C2AD378A9CE5&rurl=translate.google.com&usg=ALkJrhi8CT0q4WAxyCU1JNybS5G6N-3ONQ
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-25 07:39 , Processed in 0.124424 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表