查看: 2238|回复: 4
收起左侧

[资讯] 咖啡Artemis技术成果展示原文(来自官方)

[复制链接]
走丢啦
发表于 2008-10-4 12:11:58 | 显示全部楼层 |阅读模式
News about the Artemis project has been out for a little while. As the rollout continues we want to post some of juicy backstage gossip here, making you some of the first people to see this outside of the core project team!
If you’ve not heard about the Artemis technology yet, it’s our “in-the-cloud”-based malware detection; head over to the McAfee Artemis micro-site. I highly recommend the podcast (hidden on the right-hand side) as my colleague Dimitry Gryaznov outtalks our communications guru Dave Marcus.
One of the things Artemis provides to researchers is very clear telemetry on active malware campaigns, and I want to share a few interesting examples. All the “measles maps” below show a one-day period and were all taken at the same time earlier today.

First up is today’s typical ecard malware:



As you might expect, there are lots of hits all around the globe, sent very quickly. [Take note ISP’s: You’re the first line of defense and you delivered this to our users.]



This is a previous ecard campaign from a week ago:

(There’s always one.) This isn’t saying that the campaign is over and protection is no longer required. Since Artemis gets queries only for those without current detection in the DATs, this simply means that the map shows endpoint(s) that need to update.


Sex (still) sells. The current “tits.exe” campaign:

This picture looked like the first one on Friday. Protection is relatively new for this threat and we’re seeing the queries tail off as customers update. This is exactly the point of Artemis, providing protection for new threats between updates, and efficiently, too. (I’ve no idea why this one appears to be more popular in Australia.)

This is the current data from the “tits.exe” campaign from last weekend (21 September):

Yes it’s a blank map. In fact, the last query was at 00:45 on 25 September from an ISP in California. This is quite a revelation: Artemis fills a gap far wider than I first envisaged.
Dimitry’s podcast also explains how we are able to deploy Artemis without an upgrade and that Artemis has been dormant in the DATs for quite a few months already. Those on the Artemis-enabled beta programs have been enjoying its added protection for months as well.
A quick note about privacy before the vultures circle.  The dots on the map roughly represent ISPs rather than individual users (we couldn’t read it otherwise). We use the data purely on a statistical basis and we don’t keep it longer than we need to. The dots are geolocated by a service that has well-understood accuracy “limits,” so relax. Artemis does not know where you live, or what color the car on your driveway is. For that, you need to ask Google; they have pictures of it.  Artemis queries are short checksums or fingerprints. Those wishing to disable Artemis should unplug themselves from the Internet at this point. It’s far easier to track our blog readers, for instance.  
Some other trivia about Artemis:

Queries are not sent for every file, just the suspicious ones.
It will probably be invisible in the consumer products. (It’s a special driver.)
A query and a response is around 340 bytes.
It’s checksum/fingerprint independent, too.
Actionable responses are cryptographically strong.
Telemetry can be used to prioritize sample processing.
Today Artemis should gain about 1.5 million new users.
Enterprise customers, please feel free to call Platinum Support if you want to test out Artemis early.
Lastly, any malware authors who want free third-party real-time telemetry on their campaigns should contact us ASAP! Our legal hounds are waiting to take your calls.
livv8
发表于 2008-10-4 12:22:24 | 显示全部楼层
貌似有人介绍了
632978779
发表于 2008-10-4 14:14:55 | 显示全部楼层
没有 诺顿 和卡巴牛!
gho
发表于 2008-10-4 15:19:33 | 显示全部楼层
不错我喜欢跟SONAR一样?
xiaochi12
发表于 2008-10-4 16:43:52 | 显示全部楼层
翻译一下吧
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-25 07:05 , Processed in 0.121583 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表