Live data from Hacker News

Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

vice.com

51–60 of 60 posts

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#51
post #44

Earlier quoted context omitted.

Which is something a novice computer user might try when 'hacking'. Really Cylance?

Some early spam filters could also be tricked using the same technique. I think PG might have written about this.

http://www.paulgraham.com/antispam.html

http://www.paulgraham.com/sofar.html

> More Good Tokens

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#52
Rice's theorem is pretty clear on this. You PROVABLY CANNOT inspect a piece of code and answer any nontrivial question about any nontrivial property of it.

"Is this code evil?" is a VERY nontrivial (bordering on philosophical) question

Adding buzzwords like "AI" into the mix doesn't affect this in any way

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#54
post #40

I'm a little baffled by how this could be news. It's an antivirus system. Someone bypassed it. That's what people do with antivirus systems. Was there a widespread belief that Cylance had somehow cracked the code on reliable antivirus?

Is this news to nerds? No. The effectiveness of virus software has been measured over and over and holes are always found, cause that’s software.

It’s a useful talking point nonetheless. Naive managers can feel pressured to make purchase decisions around these things.

Pointing to data and these stories has been helpful to me in getting time to truly vet our choices.

Nothing hurts credibility like saddling the company with a service contract that provides fuck all nothing.

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#55
post #40

I'm a little baffled by how this could be news. It's an antivirus system. Someone bypassed it. That's what people do with antivirus systems. Was there a widespread belief that Cylance had somehow cracked the code on reliable antivirus?

Because AI

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#56
post #39

I have used their home offering Cylance Smart Antivirus, and I essentially concluded that machine learning is just not enough to detect malware. It's nice signature is small and works even when you do not have latest signature, but there are a lot of false positives. (and it's generally identify the threat just by class of its threat, and not by specific identify of a threat, so there's no way to assess its impact.)…

You're in for a bad time trying to run Cylance or something similar at home. I generally have a positive opinion of Cylance having run it for 3 years. I think where those types of products shine is in larger environments where the end user is your biggest risk, you have layers of security and it's worthwhile to invest the effort in getting your AV config right. I would never put that thing on my home machine. I know…

Well, I'm talking about the specific version of the Cylance PROTECT intended for homes, which I believe similar engine sans memory protection and other controls in their management dashboard. I guess it's bad execution on their end, too, not necessarily their engine itself, perhaps. I guess their engine is more appropriate for corporate IT environment where what goes inside gets more vetting on what goes in.

The reason I looked at Cylance was part curiosity, and other that that I do manage machines beyond my own use; so "end user is your biggest risk" actually applies to me as far as malware vector goes.

In any case, I'm not really sure how Cylance's trying to position for their home offering; seems to allow very little control over its configuration and while protection is inadequate. I haven't use their enterprise version but I'm assuming it gives you a lot more configuration options...

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#57
post #38
post #3

I literally make customers disable cylance on their servers or we are not guaranteeing servers operations. Too many buggy conflicts.

How does that usually work out? Personally, I would throw out a vendor who asked me to disable my AV. I don't mind whitelisting a directory or making certain adjustments, but it's hard to take them seriously if they can't work with AV. Cylance isn't that bad. I ran it for 3 years. The false positives were annoying, but it also stopped a lot of nasty stuff that our traditional AV wasn't detecting. I'm in an environmen…

Basically when Cylance is enabled - other software dies.

We report problem, customer complains to cylance and cylance people come begging for logs to debug. Some admin volunteer his time to babysit cylance people to give them what they need.

Week or two pass by productively with cylance disabled and then some software dies again. ps aux | grep cylance -- some other admin turned it back on.

Rinse and repeat.

Quickest way to solve any problem for us is to check if cylance running.

We basically charge customer extra to keep them happily married to cylance.

I do realize that it's some exec' reputation on the line for approving this vendor purchase - hence we're being diplomatic by charging extra and being quiet.

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#58

Whenever I’ve used AV I have found it to be worse than useless. Only detections are false positives, uses tons of systems resources, breaks commonly used apps. I generally agree with Tavis Ormandy[1] that AV products often just increase the attack surface. Especially for applications that already have a high security focus (e.g. browsers). I’m somewhat surprised to see so many AV believers in the HN comments section.…

Neither you nor Mr. Ormandy is taking into account realistic threat models.

I also suspect you're lumping traditional AVs with modern EDRs.

If you anticipate targeted attacks you need an EDR solution of some sort (even if that meand cooking up your own with sysmon or auditd).

If you anticipate crimeware, depending on your technical sophistication you need an EDR. If you're confident in yourself,consider the financial and data loss risks and you might be well off with only hardening your system and being careful.

If the security company is considered a possible threat,try and come up with at lesst some sort of aggressive behavioral log monitoring.

I have no idea why your comment is #1 on HN. Does no one here at least occadionally stumble upon malware and threat intelligence write ups? I thought I saw the post of krebsonsecurity on here last week or so where he exposed a member of Gandcrab after they retired the affiiate network ransomware after supposedly raking in $2B? You think EDRs can't catch that easily?

I suspect you and even possibly Mr. Ormandy might be suffering from availability bias. Just because you don't see the prevalance and dynamic nature of the threat landscape,your threat model(or lack of one) might not be well informed.

Patches and keeping up to date prevents vulnerabilities. Malware and hackers alike do not depend on software vulnerabilities,even if they did you can't defend against a zero by hardening against exploits alone(at least on windows)

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#59
post #54
post #40

I'm a little baffled by how this could be news. It's an antivirus system. Someone bypassed it. That's what people do with antivirus systems. Was there a widespread belief that Cylance had somehow cracked the code on reliable antivirus?

Is this news to nerds? No. The effectiveness of virus software has been measured over and over and holes are always found, cause that’s software. It’s a useful talking point nonetheless. Naive managers can feel pressured to make purchase decisions around these things. Pointing to data and these stories has been helpful to me in getting time to truly vet our choices. Nothing hurts credibility like saddling the company…

just a heads up, i think your comments are autodead now

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#60

Earlier quoted context omitted.

Neither you nor Tavis are taking into account non-technical people. Nobody forces you to use AV -- if you feel you have the skill to defend yourself, do yourself a favor (and us), and remove AV from your boxes. But leave non-technical people alone.

Herein lies the challenge. The user that is so ill trained that AV is a great idea actually needs an environment locked down sufficiently that he can't ruin his own day not a tool to analyze in real time whether he is doing so right now. Those more skilled would be better off just using their wits. The set between is empty.

You mean the user should not have access to computers? Because that is what you're implying. If the user can send and receive emails, this user is susceptible to attack.
Post reply on HN