Presentation is loading. Please wait.

Presentation is loading. Please wait.

Smart Protection Network Kelvin Liu AVP, Core Tech Development.

Similar presentations


Presentation on theme: "Smart Protection Network Kelvin Liu AVP, Core Tech Development."— Presentation transcript:

1 Smart Protection Network Kelvin Liu AVP, Core Tech Development

2 Copyright 2008 - Trend Micro Inc. Malware is multiplying Malware is sophisticated Malware is profit driven Spam Spyware Botnets Complexity Worms Web Evolving Threat Landscape Malware is getting increasingly dangerous and harder to detect.

3 Copyright 2009 - Trend Micro Inc. Internal - Confidential Example : Conficker / Downadup Internet User receive a spam mail User open the mail then automatically download a file The file register itself as a system service Monitor the Internet browser’s address bar Block access to certain websites Connect to various websites, download other malicious files

4 Copyright 2009 - Trend Micro Inc. Feb 2009 Internal - Confidential Smart Protection Network against Conficker Incident Trigger Email Reputation Web Reputation File Reputation Monitor Many clients’ processes are dropping similar filenames in a short time Many clients access or modify the same system file in a short time Many clients accessed similar/same registry keys in a short time Community Intelligence Smart Protection Network Correlate to figure out where the threat come from & where it would connect to Correlate to figure out where the threat come from & where it would connect to FileScore FromConnect to Crypt.NS.GenX129.24.11.3/aexjiire/Euwl.tsst.com:88/e34jg/ Dropper.GenXNdj.sexadult.com/ssr/ee112.42.5.112:80/ Nqe.exeVwww.xyz.comwww.abc.com Conflicker_DXqd.wqwwor.com/omnadasm0.info:80/bugsy Conflicker_DXFdjhg.wopqfe.com7f7fewf.cn:80/sina/ Correlation Customer Feedback Log Immediate Protection

5 Copyright 2009 - Trend Micro Inc. Incident Trigger Email Reputation Web Reputation File Reputation Monitor Correlation Feb 2009 Smart Protection Network against Conficker Domain / Name Server / IP / Register’s Email Correlation to build up a Spider Network Threat Intelligence Correlation Immediate Protection

6 Copyright 2009 - Trend Micro Inc. Email Reputation Web Reputation File Reputation Incident Trigger Monitor Correlation Feb 2009 Smart Protection Network against Conficker Domain / Name Server / IP / Register’s Email Correlation to build up a Spider Network Threat Intelligence Correlation Immediate Protection

7 Copyright 2009 - Trend Micro Inc. What & How Trend Micro use Cloud Computing Feb 2009 Internal - Confidential OS Server Farm Smart Protection Network Tracking System Hadoop ( HBASE / Meta Data ) Virtualization Hadoop (HDFS) Message Routing framework MapReduce Clustering Clawer Analyzer Monitor Incident Trigger Correlation HTTP DNS FTP Operating system Infrastructure Data Archive Data Processing Correlation

8 Copyright 2009 - Trend Micro Inc. Feb 2009 Internal - Confidential Why Smart Protection Network Time to Protect Less Complexity Threat Intelligence Reduce Cost Immediate Protection Early Warning Immediate Protection Early Warning Lightweight Clients Less Memory Usage Lightweight Clients Less Memory Usage Reduce Downtime Costs Reduce Hardware Costs Reduce Downtime Costs Reduce Hardware Costs Threat Lifecycle Management

9 Copyright 2009 - Trend Micro Inc.

10 Thank You 業務專線 : (02) 2378-2666


Download ppt "Smart Protection Network Kelvin Liu AVP, Core Tech Development."

Similar presentations


Ads by Google