Author Topic: About "Dyna" detection  (Read 18203 times)

0 Members and 1 Guest are viewing this topic.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: About "Dyna" detection
« Reply #15 on: February 19, 2013, 10:50:43 AM »
Besides what pk said, there's one more innovation with respect to those Dyna detections. We call it snxsql and it basically allows us to use the full richness of SQL queries to detect viruses in the sandbox. That is, the whole execution trace from the sandbox is stuffed to an in-memory SQL database and we consequently make queries to that DB (including some pretty complex/rich ones). This allows the detections to be fairly sophisticated, while minimizing the FP rates.

While the actual creation of these dyna detections / sql queries is now still a manual process (done by our virus analysts), we are close to actually implementing an automated generator for this - technically, this would be sort of "Evo-gen" for dyna detections.

Pretty fascinating stuff, especially if you see the results.

So, please, stay tuned, more stuff is coming. :)

Thanks
Vlk

Do tell more. So what you're working on is basically a Dyna-Gen? So, if i understand this correctly, you'll be able to generate Dyna detection rules automatically from bunch of existing samples like you do with Evo-Gen at the moment? By "close" you mean for the release (or at least sometime around that time) of avast! 8 or sometime during year 2013?
Either way i'm looking forward to this as it would mean we will see even more Auto Sandbox detections.
Visit my webpage Angry Sheep Blog

kev797

  • Guest
Re: About "Dyna" detection
« Reply #16 on: February 19, 2013, 11:18:05 AM »
thank you avast team for a great product and all your hard work, :)

Pubert E

  • Guest
Re: About "Dyna" detection
« Reply #17 on: February 19, 2013, 02:09:40 PM »
Sounds fantastic!
If all this becomes real i'm almost ready to buy up some licenses  ;D

spywar

  • Guest
Re: About "Dyna" detection
« Reply #18 on: February 19, 2013, 06:41:18 PM »
Besides what pk said, there's one more innovation with respect to those Dyna detections. We call it snxsql and it basically allows us to use the full richness of SQL queries to detect viruses in the sandbox. That is, the whole execution trace from the sandbox is stuffed to an in-memory SQL database and we consequently make queries to that DB (including some pretty complex/rich ones). This allows the detections to be fairly sophisticated, while minimizing the FP rates.

While the actual creation of these dyna detections / sql queries is now still a manual process (done by our virus analysts), we are close to actually implementing an automated generator for this - technically, this would be sort of "Evo-gen" for dyna detections.

Pretty fascinating stuff, especially if you see the results.

So, please, stay tuned, more stuff is coming. :)

Thanks
Vlk
"Sort of Evo-Gen for Dyna detections"  ;D ... Thanks for this info !

spywar

  • Guest
Re: About "Dyna" detection
« Reply #19 on: February 19, 2013, 09:48:36 PM »

Offline Charyb-0

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2508
Re: About "Dyna" detection
« Reply #20 on: February 19, 2013, 09:51:37 PM »
That's awesome. I am anxious to see everything up and running.
« Last Edit: February 19, 2013, 09:53:12 PM by Charyb »

spywar

  • Guest
Re: About "Dyna" detection
« Reply #21 on: February 20, 2013, 09:14:02 AM »

spywar

  • Guest
Re: About "Dyna" detection
« Reply #22 on: February 20, 2013, 06:01:51 PM »