2022-08-08 13:07:58

How does Intezer Analyze™ reduce false positives when detecting malware? As our genome database contains not only bad code but also legitimate code, we can identify whether a file is good or bad by analyzing code reuse and code similarities.Are you then able to identify Zero Day Attacks? Absolutely.Just like Google must index more and more websites every day, we need to index more software and more malware every day, so our database is constantly growing. Secondly, it can help you understand what you are dealing with.So, this scenario is very, very unlikely.It's this concept that makes our technology so effective – even a modest database that does not include all the threats or all the software in the world is of huge value.

Imagine you are a sophisticated threat actor who has spent about ten years developing your code for malware and cyber-attacks.So, this scenario is very, very unlikely.Secondly, it can help you understand what you are dealing with. You know, the amazing thing is that everybody reuses code.The idea is to create this huge database of all the genes of all the pieces of code in the world of both legitimate and malicious software so that we can detect code reuse and code similarities in unknown or suspicious files.I always say that Skype is basically a virus resembling a spy tool as it records your keystrokes and has a camera.

For example, if you know that you're dealing with an APT or an advanced threat actor, then the response itself would be significantly different than if you were dealing with just a common internet scam.You know, the amazing thing is that everybody reuses code.That tells us right away that this cannot be a Windows file. So, you see that even years after an attack, the original malicious code is still being used to create new malware.So, you are constantly analyzing files and adding to the Genome database as new threats are detected? Correct.Two main reasons.

