About Us

The Immunet Blog is maintained by the Immunet team as a forum for discussing news and issues related to AntiVirus, security and cloud technology.

Search

Entries in ccloud antivirus (1)

Wednesday
Feb172010

The Immunet Protect ETHOS Engine, A Week In the Life...

Earlier in this month the Immunet team shipped and enabled a new engine to our Immunet Protect Beta. This Anti-Virus engine, titled ETHOS, is focused on helping us leverage our community to help protect our community. Essentially the engine looks for threats (heuristically) on the desktops of our community. If it finds a suspected threat it remediates it and then communicates about it (and sometimes the file itself) to our Cloud so the rest of the Immunet Community is protected from it instantly.

It's long been our opinion that the most dangerous malware our community faces is malware which is making the rounds in the 'here and now' . This 'active malware' is what we all need to be worried about. This is the stuff that you and those around you are most likely to encounter. Sounds like common sense right? It is, but the vast  amount of Anti-Virus signatures (well over 97%) created for most Anti-Virus products are created from traded malware collections (which are tired and old) or collected/crawled from malware web sites which are often fallow and no longer active. This results in most Anti-Virus products downloading millions of largely useless definitions a year. We believe it's the small minority of threats which are live and on the move which need your attention.

So with the small minority in mind we built ETHOS. I am going to present some data here for you put context around our findings.

General Threat Data (Based off the last 7 days)

  • Every 24 hours we block 1910 (on average, outliers removed) threats
  • We process (create cloud definitions) for 17,500 files a day. This malware comes from crawling and malware collections which we trade. We will refer to this as 'Cloud Processed' malware.
  • We separately collect and process 50 threats a day (on average) from our ETHOS engine. This engine is only active on 7,120 users in our community this is about 10% of the whole user base.

So with these numbers in mind here is the story so far, of the 1910 threats we stop each day, 382 or 20% come from ETHOS.  So to put this into perspective graphically our overall processing looks like this:

Now, if we look at what our actual user base is seeing for 'in-field' protections it looks like this:

 

What you should take away from this is that ETHOS is contributing a wildly disproportionate amount of protection to our Community when compared to our other protection generation. This is with only 10% of the Immunet Community running ETHOS right now. As we grow ETHOS will see wider deployment and these numbers should become even more compelling.