Advice Request Symantec started to use AI?

Please provide comments and solutions that are helpful to the author of this topic.

Status
Not open for further replies.

TheMalwareMaster

Level 21
Thread author
Verified
Honorary Member
Top Poster
Well-known
Jan 4, 2016
1,022

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,346
Don't see that detection.

hqbGHyZ.png
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Symantec: Suspicious.Cloud.2.A
Suspicious.Cloud.2.A is a detection technology designed to detect entirely new malware threats without traditional signatures. This technology is aimed at detecting malicious software that has been intentionally mutated or morphed by attackers.
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,346
Strange. The detection name changed. I was sure it was that one
It did change, I saw both also. So you are not going mad after all. :D
I've seen a few Symantec detections on VT stating Malicious confidence = X. And I'm pretty sure that they are indeed using AI.
If i was evil i would say they are stealing detection signatures but everyone knows this is something no antivirus company does. /s
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Symantec: ML.Attribute.HighConfidence
Was not able to find their definition meaning, but I am going to guess it's similar to their Heur.AdvML.C
Heur.AdvML.C is a heuristic detection designed to generically detect malicious files using advanced machine learning technology. A file detected by this detection name is deemed by Symantec to pose a risk to users and is therefore blocked from accessing the computer.

ML = Machine Learning aka AI
 

Wingman

Level 4
Verified
Well-known
Feb 6, 2017
154
This is a new feature introduced with sep 14.x endpoint (advance Machine Learning).Previous sep version (12.x) do not have that functionality but might still detect the samples based on sonar/insight technologies

Consumer products (aka norton) benefit from the Heur.advML signature
 

XhenEd

Level 28
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 1, 2014
1,708
The answer to the question depends on one's perspective. If one considers Machine Learning to be Artificial Intelligence, then the answer is yes. But if not, then the answer is no. :)

Kaspersky uses ML, but does not consider it AI (Eugene Kaspersky has blog posts about this).

Besides, I think Symantec has been using ML ages ago. I doubt they were manually classifying files in their headquarters until now. Probably they developed, or further developed, their ML to act as immediate cloud detector.
 

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
Symantec is using new machine learning techniques, but it is necessary to say that the artificial intelligence is just like an empty box.
Now all the big AV vendors are speaking of AI for their products, but the real effectiveness is in the collected data, where AI algorithms are performed.
It is necessary to have a huge number of information to process, getting the patterns to predict new malware, Symantec seems to have nearly 200 million computers in the world that use their products collecting tons and tons of analyzable data.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top