New Update Announcing End of Life for Kaspersky Engine in Harmony Endpoint

Trident

Level 34
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
What's happening?
Recent federal regulations in the US have led Check Point to taking the decision to suspend offering of E1 (Kaspersky Engine).

When?
By 29th of September 2024

What's next?
As of now, default engine for all installations is Sophos. By the 29th of September 2024, all Harmony Endpoint customers must migrate to E2 engine (Sophos). Kaspersky engine will not receive any updates after this date. Engines can be switched through the Infinity Portal and reboot is required, unlike with other updates that support hot installation.

Is this a problem?
The anti-malware engine that was many years ago the heart and soul of Check Point products, represents a very insignificant part of the whole architecture today. Customers remain protected against threats through Threat Cloud, Threat Emulation, CDR, Behavioural Guard and Forensics, Anti-Bot, Anti-Ransomware and others. In the next few weeks, we'll discuss a lot of the 60+ Threat Cloud engines. The Sophos engine now runs with cloud look-ups (Live Protection) enabled, which boosts its capacity in protecting machines. But the real strength comes through Check Point proprietary technologies.

So why is third-party engine being used at all?
Check Point already offers NGAV based on deep learning, as part of Harmony Endpoint and has a proprietary AV engine which runs on Quantum (Next-Gen Firewalls). This engine is very heavy, based on many Yara rules (not signatures), including Yara rules on process memory. For this reason, Check Point does not wish to offer the engine as a software component (it runs on the cloud emulator), and is instead paying a third-party, namely Sophos, to help cover local signatures. Check Point remains focused on signature-less technologies, AI and deep learning.

Will performance be degraded?
No, the Sophos SAVI engine is light, updates are infrequent and small, with minimal traffic consumption, disk and CPU activity.

What happens to Kaspersky feeds?
There is no law that prohibits dual-listed (American-Israeli) companies from Trading with Russian-based companies -- the law prohibits components from being installed locally on US-citizen computers, and providing access to customer data. Check Point just consumes the feeds without any telemetry to Kaspersky whatsoever, so feeds are still remaining a part of Threat Cloud for now.

Is there any official documentation to read?
Absolutely!

What's next for Harmony Endpoint?
In Q3, the major focus will be on performance improvements, including a drastic reduction of memory usage from the Endpoint Forensic Recorder engine (as soon as 88.80 client, which will be released around October-November). Major upgrades are planned for the Infinity Portal in the meantime. The roadmap for the next 6-12 months is almost being laid out with Check Point actively collecting feedback and feature requests from customers and partners.
 
Last edited:

Decopi

Level 8
Verified
Oct 29, 2017
355
I'm not an expert, but from my outsider point of view, if ZoneAlarm has already used Sophos for two years, and if Harmony also already used (and still uses) Sophos and Bitdefender... everything indicates that absolutely nothing will change with the current news... it seems that Kaspersky was only offered as an alternative, it was never an irreplaceable or critical piece.

Personally, I have a good impression of this company, and its future seems very interesting to me. From time to time I install the Beta version of ZoneAlarm to see the progress... and I like it more and more.
 

Trident

Level 34
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
it seems that Kaspersky was only offered as an alternative, it was never an irreplaceable or critical piece.
Kaspersky was powering ZoneAlarm and Check Point for many years. Then Check Point developed ForceField (about 15 years ago) that used to emulate files in a local sandbox (similar to the much later released Avast DeepScreen).
They then invested few years after and acquired companies like Hyperwise (CPU level threat detection) which made them leaders in cloud emulation.

Throughout the years they released loads of proprietary technologies and Kaspersky is not needed anymore. It won’t be long before Sophos is removed too, the fact that they allow you now to run Harmony without it, is indicative that they are testing that.
 

Decopi

Level 8
Verified
Oct 29, 2017
355
What's next for Harmony Endpoint?
In Q3, the major focus will be on performance improvements, including a drastic reduction of memory usage from the Endpoint Forensic Recorder engine (as soon as 88.80 client, which will be released around October-November). Major upgrades are planned for the Infinity Portal in the meantime. The roadmap for the next 6-12 months is almost being laid out with Check Point actively collecting feedback and feature requests from customers and partners.

Can I step out of the thread's focus a bit to ask the following peripheral questions?:

Do improvements in Harmony "always" also automatically mean improvements in ZoneAlarm? Or are they two projects that do not necessarily have correlations?

What's next for ZoneAlarm?

Thks!
 
  • Like
Reactions: Trident

Trident

Level 34
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
Can I step out of the thread's focus a bit to ask the following peripheral questions?:

Do improvements in Harmony "always" also automatically mean improvements in ZoneAlarm? Or are they two projects that do not necessarily have correlations?

What's next for ZoneAlarm?

Thks!
The two projects are connected as one is a rebrand of the other. Improvements to Threat Cloud and emulation, such as newly released engines (improved local brand spoofing detection, doclink defender, memdive and others) are automatically available in ZoneAlarm. These are the core features that ensure you are protected.

For any other, non-core features, the ZoneAlarm team will have to work to ensure they are there. I know documentation, quarantine management and uninstall tool are coming in the very near future but not sure what else.
 

SumTingWong

Level 28
Verified
Top Poster
Well-known
Apr 2, 2018
1,782
It has been using it for about 2 years. For about 5 years, Harmony clients had a choice of Kaspersky and Bitdefender, which was later on changed to Sophos, as Bitdefender runs on the cloud emulation.

Wait, so sophos signatures + bitdefender cloud for consumer products listed on here?!
 

Trident

Level 34
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
Wait, so sophos signatures + bitdefender cloud for consumer products listed on here?!
Not the Bitdefender Cloud, within the Threat Cloud space, cloud emulation is included. The Cloud emulation uses a bunch of proprietary engines and also, the Bitdefender engine.
 

SumTingWong

Level 28
Verified
Top Poster
Well-known
Apr 2, 2018
1,782
Not the Bitdefender Cloud, within the Threat Cloud space, cloud emulation is included. The Cloud emulation uses a bunch of proprietary engines and also, the Bitdefender engine.

oooo I see.

How many times does Zonealarm update virus signatures per day?
 
  • Like
Reactions: simmerskool

Trident

Level 34
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
oooo I see.

How many times does Zonealarm update virus signatures per day?
The term NextGen refers to a set of technologies that don't require signatures. ZoneAlarm signatures are updated when Sophos is ready with an update, which is usually twice a day. The product provides protection through a variety of signature-less technologies such as NGAV, Emulation, Online and Offline Reputation, CDR and Behavioural Guard.
 

Shadowra

Level 36
Verified
Top Poster
Content Creator
Malware Tester
Well-known
Sep 2, 2021
2,582
The term NextGen refers to a set of technologies that don't require signatures. ZoneAlarm signatures are updated when Sophos is ready with an update, which is usually twice a day. The product provides protection through a variety of signature-less technologies such as NGAV, Emulation, Online and Offline Reputation, CDR and Behavioural Guard.

I must admit that ZA's announcement gave me a bit of a fright, given the mediocrity of Sophos's engine....
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top