<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What's the difference between antivirus signatures and WildFire signatures in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/what-s-the-difference-between-antivirus-signatures-and-wildfire/m-p/580870#M2128</link>
    <description>&lt;P&gt;Thanks for your reply Tom.&lt;/P&gt;
&lt;P&gt;Would it be fair to say that Antivirus signatures work against HTTP, HTTP2, FTP, SMB, and email protocols (POP3, IMAP, SMTP), where WildFire signatures work over a much larger set of App-IDs, which is why WildFire databases are relatively large?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Riad.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2024 03:43:53 GMT</pubDate>
    <dc:creator>r9i0a0d</dc:creator>
    <dc:date>2024-03-19T03:43:53Z</dc:date>
    <item>
      <title>What's the difference between antivirus signatures and WildFire signatures</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/what-s-the-difference-between-antivirus-signatures-and-wildfire/m-p/580688#M2125</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm trying to understand the difference between the antivirus signatures and WildFire signatures. To my understanding, antivirus signatures identify known malicious files based on the signatures in the antivirus database.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1- But what signatures does the WildFire database contain? are they signatures to identify supported file types that can be forwarded to the cloud or the private appliance? or are they signatures of newly identified malicious files that will eventually make it to the antivirus database?&lt;/P&gt;
&lt;P&gt;2- and if they are signatures of newly identified malicious files, then why aren't they included in antivirus signatures database instead?&lt;/P&gt;
&lt;P&gt;3- and why is the WildFire database file size relatively large, approximately 10% of the antivirus database file size?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Riad.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 00:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/what-s-the-difference-between-antivirus-signatures-and-wildfire/m-p/580688#M2125</guid>
      <dc:creator>r9i0a0d</dc:creator>
      <dc:date>2024-03-18T00:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between antivirus signatures and WildFire signatures</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/what-s-the-difference-between-antivirus-signatures-and-wildfire/m-p/580757#M2127</link>
      <description>&lt;P&gt;1. wildfire offers faster identification of malicious files. many of the wildfire signatures will make it into the AV database, but those are released once or twice daily usually&lt;/P&gt;
&lt;P&gt;2. because AV is not updates (once or twice daily) as frequently as wildfire (live)&lt;/P&gt;
&lt;P&gt;3. because wildfire is also cloud connected and provides coverage for 0days whereas AV has a large database of currently active threats in the wild&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the big difference between wildfire and AV is that WF protects against 0day and AV protects against all known active threats&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 09:23:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/what-s-the-difference-between-antivirus-signatures-and-wildfire/m-p/580757#M2127</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-03-18T09:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between antivirus signatures and WildFire signatures</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/what-s-the-difference-between-antivirus-signatures-and-wildfire/m-p/580870#M2128</link>
      <description>&lt;P&gt;Thanks for your reply Tom.&lt;/P&gt;
&lt;P&gt;Would it be fair to say that Antivirus signatures work against HTTP, HTTP2, FTP, SMB, and email protocols (POP3, IMAP, SMTP), where WildFire signatures work over a much larger set of App-IDs, which is why WildFire databases are relatively large?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Riad.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 03:43:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/what-s-the-difference-between-antivirus-signatures-and-wildfire/m-p/580870#M2128</guid>
      <dc:creator>r9i0a0d</dc:creator>
      <dc:date>2024-03-19T03:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between antivirus signatures and WildFire signatures</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/what-s-the-difference-between-antivirus-signatures-and-wildfire/m-p/580899#M2129</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sort of &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WildFire content packages are about 8MB whereas AV packages are 101MB, but WildFire relies heavily on cloud connectivity:&lt;/P&gt;
&lt;P&gt;AV uses signatures (markers in the payload) to identify threats directly in a flow whereas WildFire relies mostly on file hashes to see if a file was already processed by the online sandbox. If the verdict is already known (file already seen and inspected), the file can be let through or blocked based on the verdict. if the file has not been seen before wildfire will spring into action with some inline ML scanning of the file and uploading it to the sandbox for deeper analysis&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 09:14:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/what-s-the-difference-between-antivirus-signatures-and-wildfire/m-p/580899#M2129</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-03-19T09:14:08Z</dc:date>
    </item>
  </channel>
</rss>

