10-26-2022 07:34 AM
Hello,
I am just getting familiar with Secure Endpoint and would like to know more about Spero and Ethos engine.
I could not find DETAILED information about how these engines work and what they do.
Would be grateful if someone provides documentation.
Thanks
Solved! Go to Solution.
11-02-2022 12:21 PM
Hello @llomjaria ,
enclosed some infos:
SPERO (Machine Learning): We use hundreds of infos of a file, which we call a SPERO fingerprint. This is sent to the cloud and SPERO trees determine whether a file is malicious. Note, a Spero Hash is a hash based on file characteristics, not the file itself
ETHOS (File Grouping): The engine is designed to detect polymorphic threats by checking specific characteristics of a file. Much malware tries to pack/unpack/re-pack to change itself and to hide from detection. The engine is detection such activity and is able to "group" an unknown file based on its behaviour to a known malware family.
Greetings,
Thorsten
10-26-2022 07:48 AM
10-26-2022 11:42 PM
Thank you for the information.
It's useful but not as detailed.
11-02-2022 12:21 PM
Hello @llomjaria ,
enclosed some infos:
SPERO (Machine Learning): We use hundreds of infos of a file, which we call a SPERO fingerprint. This is sent to the cloud and SPERO trees determine whether a file is malicious. Note, a Spero Hash is a hash based on file characteristics, not the file itself
ETHOS (File Grouping): The engine is designed to detect polymorphic threats by checking specific characteristics of a file. Much malware tries to pack/unpack/re-pack to change itself and to hide from detection. The engine is detection such activity and is able to "group" an unknown file based on its behaviour to a known malware family.
Greetings,
Thorsten
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide