The Asian Age

Kaspersky Labs puts KLara into open source domain

KLara can run a fast, distribute­d series of YARA searches, involving multiple rules and diverse sample collection­s

- AGE CORRESPOND­ENT

Kaspersky Lab’s security researcher­s have placed KLara, a tool created internally to accelerate the search for related malware samples, into the open source domain for everyone to use. KLara is a distribute­d, rule- based malware scanner able to run multiple rules through multiple databases at the same time, allowing researcher­s to hunt advanced threats more effectivel­y. Detecting related malware samples is a key part of threat research, helping researcher­s to track cyberthrea­ts over time and protect users against the full scope of a malicious operation. Many researcher­s rely on YARA rules, which help them identify related malware by looking for specific characteri­stics or patterns. YARA rules are particular­ly useful when tracking advanced threat actors and operations involving ‘ fileless’ malware, or legitimate tools, or those where malicious code is adapted to individual campaigns or even victims. However, creating quality YARA rules and testing them can be a timeconsum­ing operation.

To address this problem, Kaspersky Lab’s researcher­s created KLara — a distribute­d system that can run a fast, distribute­d series of YARA searches, involving multiple rules and multiple sample collection­s, including researcher­s’ own private malware collection­s. This allows related samples to be identified more quickly, leading to faster protection for users. The team has now passed KLara to the open source domain where it is available for everyone to use.

“Detecting cyber- threats requires tools and systems that can hunt effectivel­y for malware – particular­ly when tracking advanced targeted threat campaigns through months or even years of activity. We created KLara to help us hunt threats better and faster and we’d now like to share it with the rest of the security community so that everyone can enjoy the benefits of the tool,” said Dan Demeter, a security researcher at Kaspersky Lab and one of KLara’s creators.

 ?? PHOTO: PIXABAY ??
PHOTO: PIXABAY

Newspapers in English

Newspapers from India