cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3503
Views
1
Helpful
3
Replies

Spero and ETHOS

llomjaria
Level 1
Level 1

Hello,

I am just getting familiar with Secure Endpoint and would like to know more about Spero and Ethos engine.

I could not find DETAILED information about how these engines work and what they do.

Would be grateful if someone provides documentation.

Thanks  

1 Accepted Solution

Accepted Solutions

Troja007
Cisco Employee
Cisco Employee

Hello @llomjaria ,
enclosed some infos:

SPERO (Machine Learning): We use hundreds of infos of a file, which we call a SPERO fingerprint. This is sent to the cloud and SPERO trees determine whether a file is malicious. Note, a Spero Hash is a hash based on file characteristics, not the file itself

ETHOS (File Grouping): The engine is designed to detect polymorphic threats by checking specific characteristics of a file. Much malware tries to pack/unpack/re-pack to change itself and to hide from detection. The engine is detection such activity and is able to "group" an unknown file based on its behaviour to a known malware family.

Greetings,
Thorsten

View solution in original post

3 Replies 3

Thank you for the information.

It's useful but not as detailed. 

Troja007
Cisco Employee
Cisco Employee

Hello @llomjaria ,
enclosed some infos:

SPERO (Machine Learning): We use hundreds of infos of a file, which we call a SPERO fingerprint. This is sent to the cloud and SPERO trees determine whether a file is malicious. Note, a Spero Hash is a hash based on file characteristics, not the file itself

ETHOS (File Grouping): The engine is designed to detect polymorphic threats by checking specific characteristics of a file. Much malware tries to pack/unpack/re-pack to change itself and to hide from detection. The engine is detection such activity and is able to "group" an unknown file based on its behaviour to a known malware family.

Greetings,
Thorsten