Get 40% Off
⚠ Earnings Alert! Which stocks are poised to surge?
See the stocks on our ProPicks radar. These strategies gained 19.7% year-to-date.
Unlock full list

CrowdStrike, other cybersecurity firms integrating industry cooperative

Published 08/25/2016, 02:45 AM
Updated 08/25/2016, 02:45 AM
© Reuters. A padlock is displayed at the Alert Logic booth during the 2016 Black Hat cyber-security conference in Las Vegas

By Joseph Menn

SAN FRANCISCO (Reuters) - Some information security companies that were shut out of the leading system for sharing data on malicious software are revealing more about how their own systems work in hopes of rejoining the cooperative effort, a shift that should improve protections for customers throughout the industry.

CrowdStrike, one of the most prominent young security companies threatened with exclusion from some shared services, said it has integrated part of its system for detecting malicious software with VirusTotal, the main industry repository for disclosing and rating risks of malware and suspect files.

Alphabet (NASDAQ:GOOGL) Inc's Google runs the VirusTotal database so security professionals can share new examples of suspected malicious software and opinions on the danger they pose. In May, the 12-year-old service said it would cut off unlimited ratings access to companies that do not share their own evaluations of submitted samples.

CrowdStrike is opening up a machine-learning process for malware evaluation, after discussions with VirusTotal on how to make the systems compatible.

"It will be very helpful to have the engine out so people can see for themselves how well it is working," CrowdStrike Chief Technology Officer Dmitri Alperovitch told Reuters ahead of a public announcement on Thursday.

VirusTotal did not respond to a request for comment. People familiar with the situation told Reuters said that two other "next-generation" security companies are expected to integrate with VirusTotal by the end of next month.

More are likely, the people said, a hopeful sign that a serious rift between older and newer security companies can be healed in service of the general good.

Some newer companies disparage the way that older vendors such as Symantec Corp (NASDAQ:SYMC), Intel Corp (NASDAQ:INTC) and Trend Micro Inc recognize malware based on signatures, or characteristics that have been spotted before. The younger companies say they use behavioral monitoring, machine-learning and other modern techniques to stop fast-changing malware.

Symantec, Intel, Trend Micro and other older companies say they also use similar new methods.

But some of the younger companies still used VirusTotal's assessments from old-line companies, without contributing their own evaluations. The dispute was partly based in technological compatibility with VirusTotal's system, an issue CrowdStrike said it and VirusTotal had solved.

Dennis Batchelder, general manager of an industry group called the Anti-Malware Testing Standards Organization, predicted that more new companies would re-integrate with VirusTotal. Machine learning systems would benefit from access to the VirusTotal database, he said.

But some of the companies who parted with the VirusTotal ratings said they had no plans to make up.

"We did make attempts early on to engage with VirusTotal with the hopes that they would find a way to take advantage of our behavior-based detection model," said SentinelOne Chief Marketing Officer Scott Gainey. "To our knowledge, those interfaces still do not exist today." 

And Stuart McClure, chief executive of Cylance Inc, pointed out that his company and others can still get samples of malicious software from VirusTotal, just not the opinions of other companies about those samples.

© Reuters. A padlock is displayed at the Alert Logic booth during the 2016 Black Hat cyber-security conference in Las Vegas

"We don't integrate with VirusTotal," McClure said by email. "The VirusTotal pullout has not impacted us at all."

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.