{"id":29,"date":"2013-06-17T09:53:14","date_gmt":"2013-06-17T09:53:14","guid":{"rendered":"http:\/\/www.3lectrik.com\/normanshark\/?page_id=29"},"modified":"2013-10-30T15:52:22","modified_gmt":"2013-10-30T22:52:22","slug":"customized-pattern-matching","status":"publish","type":"page","link":"https:\/\/www.3lectrik.com\/normanshark\/products-solutions\/technology\/customized-pattern-matching\/","title":{"rendered":"Malware Classification"},"content":{"rendered":"<h3>Malware Classification and Customized Pattern Matching<\/h3>\n<p>Well over 100,000 malware variants are released into the wild each day, and while the samples themselves may be unique, the behaviors they exhibit can give them away through advanced pattern matching and heuristic analysis.<\/p>\n<p>The <span style=\"text-decoration: underline;\">Malware Analyzer G2 (MAG2)<\/span> uses behavior-based malware classification patterns \u2013 not code-based signatures \u2013 to flag detected system events based on potential malicious activity.\u00a0 Patterns form the core basis of MAG2\u2019s embedded intelligence and provide risk scoring based on criteria determined by Norman Shark\u2019s malware analysts and a customer\u2019s own unique criteria.<\/p>\n<p>Patterns are used with both the SandBox and the IntelliVMs and include anti-VM (virtual machine) detection patterns.\u00a0 Patterns cover everything from generic malicious behavior (i.e. creating files, modifying registry keys) to family-specific behavior patterns (i.e. banking Trojans, keyloggers).\u00a0 The Malware Analyzer G2 reports all of the patterns that \u201ctriggered\u201d during an analysis run based on the behavior exhibited by a particular sample.\u00a0 These combinations of indicators can be used by the customer for further malware classification into families based on related behavioral characteristics.\u00a0 The highest scoring triggered pattern determines the overall risk score.<\/p>\n<p style=\"text-align: center;\"><a  href=\"http:\/\/www.3lectrik.com\/normanshark\/wp-content\/uploads\/2013\/06\/image-1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter  wp-image-131\" alt=\"image-1\" src=\"http:\/\/www.3lectrik.com\/normanshark\/wp-content\/uploads\/2013\/06\/image-1.jpg\" width=\"559\" height=\"136\" srcset=\"https:\/\/www.3lectrik.com\/normanshark\/wp-content\/uploads\/2013\/06\/image-1.jpg 621w, https:\/\/www.3lectrik.com\/normanshark\/wp-content\/uploads\/2013\/06\/image-1-300x72.jpg 300w\" sizes=\"auto, (max-width: 559px) 100vw, 559px\" \/><\/a><\/p>\n<h3>Detects Polymorphic Binaries<\/h3>\n<p>Because they look for behavior and not code signatures or hash values, Norman Shark\u2019s malware detection patterns are highly resistant to polymorphic binaries, new malware variations with equivalent instruction sequences where each variant carries its own signature and hash value.\u00a0 Polymorphs are designed to evade traditional signature-based detection mechanisms, but the Malware Analyzer G2 records events directly from the kernel and thus patterns match against kernel-level events which are extremely difficult for malware to evade.<\/p>\n<h3>Continuously Updated by Malware Classification Experts<\/h3>\n<p>Norman Shark has an experienced malware\u00a0classification and analysis\u00a0team that develops and maintains an updated set of efficient patterns optimized for analysis and detection of the latest cyber threats collected, reported and analyzed in our malware classification\u00a0lab.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malware Classification and Customized Pattern Matching Well over 100,000 malware variants are released into the wild each day, and while the samples themselves may be unique, the behaviors they exhibit can give them away through advanced pattern matching and heuristic analysis. The Malware Analyzer G2 (MAG2) uses behavior-based malware classification patterns \u2013 not code-based signatures [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":0,"parent":25,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-29","page","type-page","status-publish","hentry"],"jetpack_shortlink":"https:\/\/wp.me\/P5TlPb-t","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/29","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/comments?post=29"}],"version-history":[{"count":9,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/29\/revisions"}],"predecessor-version":[{"id":1209,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/29\/revisions\/1209"}],"up":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/25"}],"wp:attachment":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/media?parent=29"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}