"Detonated" Win10 malware: Microsoft Sonar plans to expose, recruit security software engineer

  

Microsoft is working on a new service called "Sonar Project" (Project Sonar).

The purpose of the program is to rely on virtual machines to detect and analyze malware before malware reaches the user's system, and to destroy it. In fact, similar malware interception methods have been applied to the Win10 application store and Exchange Online, but Microsoft may want to apply the technology more widely to the user level in the future, for example, to strengthen the detection and interception of Win10 malware.

This malware is handled in a similar way to the sandbox, so it is not new in principle.

But how to deal with data collection is still a big problem for Microsoft. Mary Jo Foley, a longtime observer of Microsoft research, said the company might allow users to run Sonar directly and view data collection information from their systems; or Microsoft would run Sonar itself and then let users analyze the data.

Microsoft's employment requirements in the recruitment notice revealed the company's urgent problem in the Sonar program: "You need" to figure out how to use an efficient way to store and search data, build a foundation based on Web's Analyst Studio allows analysts to discover and manipulate this data, build data pipelines to transfer our most interesting data to other Microsoft security systems in near real-time, and build public-facing Web APIs and these The entrance to the service. ”

Microsoft has hinted at malware processing, such as "malware detonation" system will work. Microsoft explained this, for example, users will receive extremely secure mail under the protection of Exchange Online, because these messages that can enter the inbox have passed the multi-filter and detection of various anti-virus engines.

The system's "detonation chamber" is a sandbox-like mechanism that can be used for the analysis of suspected files and can determine whether a file is dangerous and whether it will be transmitted to the user's computer. If it is determined that there is a problem with the file, it will be detonated & rdquo;.

At present, Microsoft's recruitment is in progress. If you have the strength and interest to participate in the "Sonar Project", you can click here to enter the Microsoft recruitment page to view the details.

Copyright © Windows knowledge All Rights Reserved