(Baidu)About Baidu Antivirus' detection

Status
Not open for further replies.

xywcloud

From X-Sec Antivirus
Thread author
Verified
Top Poster
Developer
Well-known
Aug 8, 2013
2,818
Some people may notice that BAV "loves" to copy ESET & Kasperskys' Detection Name.
In fact, on the one hand, you' re right, the name are so similar and sometimes are the same.
But on the other hand, it' s just copy ESET and Kasperskys' Detection Name, not their virus database[Copy others' VDB may be illegal:D, and we have to do reserve engineering to analyse the structure of others' VDB, it costs lots of time, and it' s not worthy and moral]
About "Cloud Security", a simple description of how it works is:"Calc hash of file -> Check it in Cloud Database[a hash with a virus-name] -> Return result"
The Cloud Database relys on virus-analyse-machine & virus collection, how can we get a large number of virus? Human contributes few percents, most are from machine(by using Spider, virus-exchange, etc)
1.virus-exchange
Example:https://www.opswat.com/partners/metascan-engine-suppliers
"Once your scanning engine is included in Metascan Online, you will be eligible to receive virus samples to help your engine discover potential false positives and false negatives."
VirusTotal, VirScan, etc... are the same.
Also, virus-exchange can happen on two(or more) av-vendors.
2.a virus-name
When we get a large number of virus, after analyse(human or machine), if it was analysed by a human, we would get a accurate virus-name[Most of the time][In fact, BAV Team is a small team, 100+ (less than 200) members], but when it was analysed by machine, it' s not easy to get a accurate virus-name.
As I mentioned before, we can get virus samples from Online-Scan-Site, we can also get others' result. So, we can use others' name as our detection name, but it' s just a name(with a hash or [something I mentioned later]).

Using others' detection name is not a long-term solution, so we have developed some techs(In order to save manpowers, haha~)
[something I mentioned later]
Micro-Signature, it' s similar to hash but not the same. Sometimes you changed the file's hash, but BAV still can detect it by using Cloud Engine. It can save time and manpowers, but has few FPs.
That' s all.


BTW: Due to strategy changes, if you are newly installed BAV 5.3.2.100074, you may not use BAV's Sandbox normally, please try to uninstall and reinstall 5.2 version, and this bug will be fixed ASAP(Maybe you have to reinstall a newer beta version), sorry for the inconvenience.
 
Last edited:
Y

yigido

S
As I mentioned before, we can get virus samples from Online-Scan-Site, we can also get others' result. So, we can use others' name as our detection name, but it' s just a name(with a hash or [something I mentioned later]).
Why don't you create a name for machine analysis results?
You do not have to copy others name. You do not want to cost to give detection names, but you steal (love) others name, it means they paid for this technology . Baidu is stealing this technologies features ,which paid by other vendors, by copying them.

Create a name for your machine detection.
Like "Heur.Machine.Adware" "Heur.Machine.Trojan" "Heur.Machine.Backdoor" etc.
I did not like your way, sorry.
Thank you for giving this article to us.
 

Dani Santos

From Xvirus
Verified
Top Poster
Developer
Well-known
Jun 3, 2014
1,136
Why don't you create a name for machine analysis results?
You do not have to copy others name. You do not want to cost to give detection names, but you steal (love) others name, it means they paid for this technology . Baidu is stealing this technologies features ,which paid by other vendors, by copying them.

Create a name for your machine detection.
Like "Heur.Machine.Adware" "Heur.Machine.Trojan" "Heur.Machine.Backdoor" etc.
I did not like your way, sorry.
Thank you for giving this article to us.

I agree with yigido, because you receive samples detected by other companies doesnt mean you can use their names.
 
  • Like
Reactions: xywcloud and yigido

xywcloud

From X-Sec Antivirus
Thread author
Verified
Top Poster
Developer
Well-known
Aug 8, 2013
2,818
Why don't you create a name for machine analysis results?
You do not have to copy others name. You do not want to cost to give detection names, but you steal (love) others name, it means they paid for this technology . Baidu is stealing this technologies features ,which paid by other vendors, by copying them.

Create a name for your machine detection.
Like "Heur.Machine.Adware" "Heur.Machine.Trojan" "Heur.Machine.Backdoor" etc.
I did not like your way, sorry.
Thank you for giving this article to us.
:)Maybe some people do not like this way(Or some people do not like Baidu(Privacy, Stealing, etc)), but at present, we have chose this type of virus-name([Type].[Platform].[Name].[Varient], our Heuristic Engine(Local Engine) also uses this, eg: Trojan.Crypt.Heur.Gen)(Change it may cost lots of time,temporary copy just to get a better result & for further Virus-Classification(Maybe you can see that if you scan a virus twice, but on a different time, you may get two virus-name)).
But it just a name, if BAV copies others' VDB, I will not tolerate it.
And if we can have more people, things may change a lot, we may have a better idea, a better Machine Analysis(In fact we can still improve our machine, but we have no time, lots of things need to be done but we have very very limited manpower(Such as new engine module(Script Detection(Offline))))
Things can be changed in the future, but need to wait(limited manpower(Maybe I have to say: "Fu*k"))
 
Last edited:
  • Like
Reactions: yigido
Y

yigido

:)Maybe some people do not like this way(Or some people do not like Baidu(Privacy, Stealing, etc)), but at present, we have chose this type of virus-name([Type].[Platform].[Name].[Varient], our Heuristic Engine also uses this)(Change it may cost lots of time,temporary copy just to get a better result & for further Virus-Classification(Maybe you can see that if you scan a virus twice, but on a different time, you may get two virus-name)).
But it just a name, if BAV copies others' VDB, I will not tolerate it.
And if we can have more people, things may change a lot, we may have a better idea, a better Machine Analysis(In fact we can still improve our machine, but we have no time, lots of things need to be done but we have very very limited manpower(Such as new engine module(Script Detection(Offline))))
Things can be changed in the future, but need to wait(limited manpower(Maybe I have to say: "Fu*k"))
I see, you also have reasons to behave like this. I have a question?
Are you an employee of Baidu?
 

xywcloud

From X-Sec Antivirus
Thread author
Verified
Top Poster
Developer
Well-known
Aug 8, 2013
2,818
I see, you also have reasons to behave like this. I have a question?
Are you an employee of Baidu?
No(Maybe to some peoples' surprise).:)
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top