Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus/Smart Security Beta
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 9th, 2011, 10:56 PM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,612
Default Regarding Cloud-Based Detection

I am requesting more detailed information about how the whole new
Cloud-based detection system works.

Regarding the Cloud-based detection, is it similar to Symantecs reputation detection "WS.1 Reputation" ? Or what will we see when the cloud detects something?

So basically, we really need more info on How it works?, What will the detections look like?. Is it behavior based?
Are the Cloud-Powered Reputation and Cloud-Based Detection systems connected? etc etc.....

Am I alone wondering this?

I got more Questions but let's start with these Cheers!
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-

Last edited by SweX : May 9th, 2011 at 11:17 PM.
  #2  
Old May 9th, 2011, 11:34 PM
Thankful Thankful is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: New York City
Posts: 2,407
Default Re: Regarding Cloud-Based Detection

Not alone.
http://www.wilderssecurity.com/showthread.php?t=298882
  #3  
Old May 10th, 2011, 02:02 AM
Rompin Raider's Avatar
Rompin Raider Rompin Raider is offline
Frequent Poster
 
Join Date: May 2010
Location: North Texas
Posts: 639
Default Re: Regarding Cloud-Based Detection

More info is appreciated!
  #4  
Old May 10th, 2011, 03:38 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Regarding Cloud-Based Detection

The cloud system is subject to evolution. The principle behind any cloud system is collection of data that can be used to calculate the reputation of files. At this point it is not safe to flag files with low reputation as bad and we're yet to see if that will ever be possible as such detections would cause FPs on less common files.
Using cloud will reduce the number of scanned files and thus decrease scan times. It will also help ESET optimize existing or new detections for better malware variant coverage and improve scanning of files which take a lot of time to emulate.
  #5  
Old May 10th, 2011, 04:05 AM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,612
Default Re: Regarding Cloud-Based Detection

Quote:
Originally Posted by Marcos
The cloud system is subject to evolution. The principle behind any cloud system is collection of data that can be used to calculate the reputation of files. At this point it is not safe to flag files with low reputation as bad and we're yet to see if that will ever be possible as such detections would cause FPs on less common files.
Using cloud will reduce the number of scanned files and thus decrease scan times. It will also help ESET optimize existing or new detections for better malware variant coverage and improve scanning of files which take a lot of time to emulate.

This was the particular feature that I was unsure of if you had starting to use or not. Yes I agree perhaps it will increase the FP's too much to actually be useful . Time will tell I guess

Thanks a lot Marcos
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-
  #6  
Old May 10th, 2011, 09:08 AM
Ego_Dekker's Avatar
Ego_Dekker Ego_Dekker is offline
Regular Poster
 
Join Date: Aug 2010
Location: Russia
Posts: 97
Thumbs up Re: Regarding Cloud-Based Detection

I really liked Cloud-based detection. I've launched malware that has been blocked by the clouds, but NOD32 was unable to clean or delete it. Is it a bug? A9ACA94F7DACE7BBCF534C7DC77C6B92 — caught by the clouds (a part of 5FB86DDC4E4C6781743805F4CB22C564), but after update all infiltrations were quarantined.
Quote:
Originally Posted by Ego_Dekker
Marcos is right, i'm wrong. Detection for that small BAT file was added long time ago, but i thought it was detected by the clouds.

Last edited by Ego_Dekker : May 10th, 2011 at 10:44 AM.
  #7  
Old May 10th, 2011, 09:32 AM
cupez80's Avatar
cupez80 cupez80 is offline
Frequent Poster
 
Join Date: Jun 2005
Location: Surabaya Indonesia
Posts: 594
Default Re: Regarding Cloud-Based Detection

Quote:
Originally Posted by Ego_Dekker
I really liked Cloud-based detection. I've launched malware that has been blocked by the clouds, but NOD32 was unable to clean or delete it. Is it a bug? A9ACA94F7DACE7BBCF534C7DC77C6B92 — caught by the clouds (a part of 5FB86DDC4E4C6781743805F4CB22C564), but after update all infiltrations were quarantined.
maybe by design to minimize FP. btw could you send me the sample i just wanna see the detection
__________________

  #8  
Old May 10th, 2011, 09:49 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Regarding Cloud-Based Detection

Quote:
Originally Posted by Ego_Dekker
I've launched malware that has been blocked by the clouds
That's impossible, see my previous post. There are no cloud/reputation detections, most likely it was that the detection for your malware was added in the last update.
  #9  
Old May 10th, 2011, 10:01 AM
toxinon12345's Avatar
toxinon12345 toxinon12345 is offline
Very Frequent Poster
 
Join Date: Sep 2010
Location: Managua, Nicaragua
Posts: 1,134
Default Re: Regarding Cloud-Based Detection

Quote:
Originally Posted by Ego_Dekker
I've launched malware that has been blocked by the clouds
if you run an on-demand-scan on the file, is it detected?
__________________
Pentium M| 512 RAM
ESET NOD32 Antivirus 5
ESET Smart Security 6 RC
  #10  
Old May 10th, 2011, 10:33 AM
Ego_Dekker's Avatar
Ego_Dekker Ego_Dekker is offline
Regular Poster
 
Join Date: Aug 2010
Location: Russia
Posts: 97
Unhappy Re: Regarding Cloud-Based Detection

Marcos is right, i'm wrong. Detection for that small BAT file was added long time ago, but i thought it was detected by the clouds.
  #11  
Old May 10th, 2011, 10:55 AM
Geosoft Geosoft is offline
Frequent Poster
 
Join Date: Jan 2009
Location: Toronto, Ontario, Canada
Posts: 270
Default Re: Regarding Cloud-Based Detection

What are the chances that the Cloud service could be used to blacklist just added malware that isn't in the signature file yet, but will be released soon?

For example, a new Fake-AV was discovered and will be in the 6111 update (right now it's 6110 as of writing this) but the cloud service will come up with a prompt asking if we want to terminate the process.
__________________
Geosoft. Operating EEA 5.x on 190 nodes, across 6 satellite offices on 6 ERA 5 servers.
  #12  
Old May 10th, 2011, 10:59 AM
Ego_Dekker's Avatar
Ego_Dekker Ego_Dekker is offline
Regular Poster
 
Join Date: Aug 2010
Location: Russia
Posts: 97
Default Re: Regarding Cloud-Based Detection

Incorrect cloud info?
Name:  cloud_info.png
Views: 187
Size:  4.0 KB
B2DE3452DE03674C6CEC68B8C8CE7C78 (NTDETECT.COM) — clean file;
9E3C13B6556D5636B745D3E466D47467 (jeefo.a) — infected Microsoft file?

Quote:
Originally Posted by Geosoft
What are the chances that the Cloud service could be used to blacklist just added malware that isn't in the signature file yet, but will be released soon?

For example, a new Fake-AV was discovered and will be in the 6111 update (right now it's 6110 as of writing this) but the cloud service will come up with a prompt asking if we want to terminate the process.
I'd like to know too.
  #13  
Old May 11th, 2011, 06:04 AM
dorgane dorgane is offline
Frequent Poster
 
Join Date: Oct 2007
Posts: 362
Default Re: Regarding Cloud-Based Detection

Quote:
Originally Posted by Ego_Dekker
Incorrect cloud info?
Attachment 226953
B2DE3452DE03674C6CEC68B8C8CE7C78 (NTDETECT.COM) — clean file;
9E3C13B6556D5636B745D3E466D47467 (jeefo.a) — infected Microsoft file?

I'd like to know too.


infected : http://www.google.fr/search?sourceid...45D3E466D47467
__________________
Sorry I am French, I have bad english
Eset Smart Security User
Windows Seven 64
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus/Smart Security Beta « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:02 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums