<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does Threat Database not include any details in the description of viruses ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47083#M34609</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Any further insight into this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where does Palo Alto Networks pull the threat information from? Or do they have their own nomenclature? It is very difficult to correlate threats identified on the Palo Alto devices to our endpoint solution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Jan 2011 16:59:58 GMT</pubDate>
    <dc:creator>ss</dc:creator>
    <dc:date>2011-01-20T16:59:58Z</dc:date>
    <item>
      <title>Why does Threat Database not include any details in the description of viruses ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47077#M34603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both vulnerabilities and spyware have descriptions are useful in understanding what those signatures correspond to. But the Viruses do not contain a description. Is there any reason for that ? It would be usefull to associate them with atleast the well known names of the viruses these signatures correspond to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 12:13:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47077#M34603</guid>
      <dc:creator>sunilsadanandan</dc:creator>
      <dc:date>2010-09-13T12:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Threat Database not include any details in the description of viruses ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47078#M34604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sunil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are looking into this. The challenge, however, is that there is no consistency in nomenclature of viruses amongst A/V vendors which makes correlating viruses info amongst vendors quite tricky. Can you let us know how you are correlating this info lets say amongst your host-based A/V solutions (assuming you are using more than 1 host-based A/V solution in your network).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your feedback,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sandeep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 16:48:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47078#M34604</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-09-13T16:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Threat Database not include any details in the description of viruses ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47079#M34605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sandeep,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for that.&amp;nbsp; I assumed there was a standard, the closest I can get to it is &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://maec.mitre.org/about/index.html"&gt;http://maec.mitre.org/about/index.html&lt;/A&gt;&lt;SPAN&gt;. But I dont know if this can be used here. If anyone else has any sujjestions , please provide them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sunil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 21:22:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47079#M34605</guid>
      <dc:creator>sunilsadanandan</dc:creator>
      <dc:date>2010-10-21T21:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Threat Database not include any details in the description of viruses ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47080#M34606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sunil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAEC is a relatively new standard that is still being discussed and is intended more to "describe" malware than define a nomenclature. e.g., lets say malware A (a virus sample file) has following attributes: changes registry keys, create files in a certain location on the computer etc., it would be described in MAEC language something like following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;registry behavior/&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; modifies key a,b, and c&lt;/P&gt;&lt;P&gt;&amp;lt;file behavior&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;file1&amp;gt; created file file1 at location location1&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;file 2&amp;gt; created file file2 at location location 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... the idea behind MAEC is that a standard way of describing a malware will help quicker exchange of information amongst security researchers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does not however address the problem of "nomenclature" which I think was your question... e.g., above malware may still be referred using different names by each vendor. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, can you describe your use case scenario so that I can see if there is any other better way to address it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Sandeep &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 23:14:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47080#M34606</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-10-21T23:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Threat Database not include any details in the description of viruses ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47081#M34607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sandeep,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes , my query does relate to nomenclature. Here is the problem I am trying to solve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Palo Alto sits at the perimeter and provides me information of viruses that are being detected/blocked by the AV component. What I am trying to see is if I can map this back to the actual host based AV solutions that might be using on the endpoints within my network. E.g. Sophos/ Macfee etc. Based on your comments I do realise this would be a difficult scenario for any solution that uses different AV engines, but there are vendors that do something similar , e.g. Ironport publishes this infomation at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.ironport.com/toc/"&gt;http://www.ironport.com/toc/&lt;/A&gt;&lt;SPAN&gt;. They used to provide the corresponding singnature ID's from the other AV vendors, but I dont see that info now.I know they have tieups with Sophos and Macfee for their signatures but Trend Micro and Symantec , i am not sure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I reffered to MAEC becuase that is the closest I could get to a standard that could bring some interoprability between the vendors. If the description field in Palo Alto AV could include at least the information related to what would be used in MAEC standard , then that would give us some more visibility into the actual virus that is being blocked , and maybe use that to find the corresponding in other AV solutions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the best would be if I could actually map the AV signatures provided by Palo Alto to other host based AV solution like Ironport does (or at least used to do, i know this is difficult untill there is a proper standard).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sunil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2010 08:50:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47081#M34607</guid>
      <dc:creator>sunilsadanandan</dc:creator>
      <dc:date>2010-10-22T08:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Threat Database not include any details in the description of viruses ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47082#M34608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sunil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the explaining your requirement in detail. I understand it better now. We don't have the correlation information as of now but let me see how best to provide it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Sandeep &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2010 21:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47082#M34608</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-10-22T21:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Threat Database not include any details in the description of viruses ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47083#M34609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Any further insight into this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where does Palo Alto Networks pull the threat information from? Or do they have their own nomenclature? It is very difficult to correlate threats identified on the Palo Alto devices to our endpoint solution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jan 2011 16:59:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47083#M34609</guid>
      <dc:creator>ss</dc:creator>
      <dc:date>2011-01-20T16:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Threat Database not include any details in the description of viruses ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47084#M34610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bump..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree this is one weakness with the product.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 15:26:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47084#M34610</guid>
      <dc:creator>jickfoo</dc:creator>
      <dc:date>2011-03-11T15:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Threat Database not include any details in the description of viruses ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47085#M34611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nomenclature provided here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1469"&gt;https://live.paloaltonetworks.com/docs/DOC-1469&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 13:01:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-threat-database-not-include-any-details-in-the/m-p/47085#M34611</guid>
      <dc:creator>sunilsadanandan</dc:creator>
      <dc:date>2011-07-28T13:01:50Z</dc:date>
    </item>
  </channel>
</rss>

