cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2455
Views
0
Helpful
3
Replies

Spero and ETHOS

llomjaria
Level 1
Level 1

Hello,

I am just getting familiar with Secure Endpoint and would like to know more about Spero and Ethos engine.

I could not find DETAILED information about how these engines work and what they do.

Would be grateful if someone provides documentation.

Thanks  

1 Accepted Solution

Accepted Solutions

Troja007
Cisco Employee
Cisco Employee

Hello @llomjaria ,
enclosed some infos:

SPERO (Machine Learning): We use hundreds of infos of a file, which we call a SPERO fingerprint. This is sent to the cloud and SPERO trees determine whether a file is malicious. Note, a Spero Hash is a hash based on file characteristics, not the file itself

ETHOS (File Grouping): The engine is designed to detect polymorphic threats by checking specific characteristics of a file. Much malware tries to pack/unpack/re-pack to change itself and to hide from detection. The engine is detection such activity and is able to "group" an unknown file based on its behaviour to a known malware family.

Greetings,
Thorsten

View solution in original post

3 Replies 3

Thank you for the information.

It's useful but not as detailed. 

Troja007
Cisco Employee
Cisco Employee

Hello @llomjaria ,
enclosed some infos:

SPERO (Machine Learning): We use hundreds of infos of a file, which we call a SPERO fingerprint. This is sent to the cloud and SPERO trees determine whether a file is malicious. Note, a Spero Hash is a hash based on file characteristics, not the file itself

ETHOS (File Grouping): The engine is designed to detect polymorphic threats by checking specific characteristics of a file. Much malware tries to pack/unpack/re-pack to change itself and to hide from detection. The engine is detection such activity and is able to "group" an unknown file based on its behaviour to a known malware family.

Greetings,
Thorsten

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: