Microsoft’s endpoint security software now uses Intel’s Threat Detection Technology (TDT) to detect cryptomining on customers’ devices.
While Microsoft Defender for Endpoint already used Intel TDT’s accelerated memory scanning capabilities, today it expanded its use to include CPU-based cryptoming detection.
As cryptocurrency prices rise, deploying coin miners as a payload for malware becomes more lucrative for attackers. In fact, coin miner malware attacks increased 53% sequentially in the fourth quarter of 2020, according to research from Avira Protection Labs.
The Intel technology uses machine learning to detect certain malicious behavior — in this case, cryptomining. Here’s how it works: The CPU performance monitoring unit (PMU) sits below the applications, operating system, and virtualized layers to provide a greater view into active threats across the stack. Intel TDT bolsters endpoint detection and response (EDR) products and improves visibility where it has historically been a challenge such as malware attempts to cloak itself in a virtual machine (VM).
“This partnership is one example of our ongoing investment and deep collaboration with technology partners across the industry,” said Karthik Selvaraj, principal security research manager at Microsoft, in a statement. “We work closely with chipmakers to explore and adopt new hardware-based defenses that deliver robust and resilient protection against cyberthreats.”
Intel first introduced TDT at the RSA security conference in 2018 following the Meltdown and Spectre attacks earlier in the year. At launch, the silicon-level security technology provided accelerated memory scanning, and both Cisco and Microsoft said they would use TDT in their products.
Since then, Intel has expanded TDT’s capabilities to include machine-learning based malware detection. Earlier this year Cybereason said it would provide ransomware protection at the CPU level using Intel TDT’s malware-detection built into its latest vPro processors.
Comments