Home Cloud Computing Palo Alto Networks finds hundreds of malware samples unknown to security researchers

cloud computing

Get all your tech news delivered to your mail box five days a week
iTWire UPDATE - it's FREE!


As part of a typical sales engagement, Palo Alto Networks will place one of their next-generation firewalls onto a potential customer's network to determine 'what's going on.'  Turns out, rather a lot.

Palo Alto Networks' recently launched Wildfire malware analysis engine is a cloud-based service that is able to check for malware in any files that are intended to be downloaded via various on-line repository services or email.  This is achieved by interaction with their in-line firewall which passes the files to the cloud service for analysis.  In return, the cloud system communicates updated signatures to all firewalls at customer sites.

What the company found was that 7% of all such files destined for corporate users contained some form of malware.

Even more surprising was that a significant portion of the malware was previously unknown to security researchers.

"I think we were all a bit surprised by the volume and frequency with which we were finding unknown malware in live networks," said Wade Williamson, Senior Security Analyst at Palo Alto Networks. "Unknown malware often represents the leading edge of an organized attack, so this data really underscores the importance of getting new anti-malware technologies out of the lab and into the hands of IT teams who are on the front lines. The ability to detect, remediate and investigate unknown malware needs to become a practical part of a threat prevention strategy in the same way that IPS and URL filtering are used today."

In the previous three months, over 700 unique malware examples were detected, of which 57% were unknown at the time of discovery to either Virus Total or the various anti-virus vendors.  Further, 15% of the newly discovered malware generated what appeared to be malicious or unknown outbound traffic to command-and-control servers.

Of interest was the wider view that Wildfire was able to take.  Using the tool, the company was able to identify specific phishing campaigns based on the unique communication channels; for instance, Palo Also Networks was able to identify one attacker who almost exclusively made use of AOL Mail and another who hosted his malware laden files at the Hotfile hosting service.


RECRUITMENT & RETENTION REPORT 2013

HIRE OR FIRE? BUY OR BUILD

2013 is well underway and Australian companies need to know whether they should invest in IT skills training or pay a premium for the people they need.

If you want to know which choices are being made in your sector, what skills are hard to find, which sectors intend to hire or fire and where the IT spend is going, this free report is must have.

GET YOUR REPORT NOW

David Heath

joomla statistics

David Heath has over 25 years experience in the IT industry, specializing particularly in customer support, security and computer networking. Heath has worked previously as head of IT for The Television Shopping Network, as the network and desktop manager for Armstrong Jones (a major funds management organization) and has consulted into various Australian federal government agencies (including the Department of Immigration and the Australian Bureau of Criminal Intelligence). He has also served on various state, national and international committees for Novell Users International; he was also the organising chairman for the 1994 Novell Users' Conference in Brisbane. Heath is currently employed as an Instructional Designer, building technical training courses for industrial process control systems.

Connect