WatchGuard launches AI-based antivirus to help defend against zero day malware

WatchGuard announced version 12.2 of its Fireware operating system for its Firebox Unified Security Platform appliances. Key to the update is IntelligentAV, a new antivirus scan service that uses an artificial intelligence (AI) engine to predict, detect and block evolving zero day malware.

IntelligentAV joins Threat Detection and Response (TDR), Gateway AntiVirus, and APT Blocker as an additional layer of industry-leading malware defense on the Firebox platform.

“Data from our quarterly Internet Security Report shows that nearly half of all malware targeting our customers is zero day. Traditional signature-based antivirus, while still an important part of one’s overall security posture, no longer provides adequate protection against modern malware, which is often obfuscated to evade detection,” said Brendan Patterson, vice president of product management at WatchGuard Technologies.

“That’s why WatchGuard believes that layering multiple advanced security solutions is the best way for businesses to protect their assets and their customer’s data. IntelligentAV is the latest example of how we use best-in-class technologies to deliver high-performance layered security for customers.”

IntelligentAV uses Cylance’s malware detection engine based on machine learning technology, which can predict and detect future malware samples even without access to the latest threat intelligence and signature databases.

For example, in a third-party test by SE Labs, a 2015 version of this AI detection engine identified and blocked threats 33 months before they appeared in the wild. This means that IntelligentAV continues to detect and block malware without relying on signatures.

“The threat of zero day malware is a big issue for our clients, and IntelligentAV is an important part of a strong ‘defense in-depth’ strategy,” said Tony Petrella, vice president of engineering at Advanced Network Systems.

“Having an AI component provides a more robust, proactive defense against new forms of malware and ransomware that legacy AV would typically miss.”

Along with IntelligentAV, Fireware version 12.2 also includes other upgrades:

  • Firebox Cloud Management Upgrades: WatchGuard System Manager for management of multiple Firebox Cloud instances hosted on Amazon Web Services or Microsoft Azure.
  • Geo-Blocking by Policy: Users can now set granular policies to restrict certain traffic types to or from specific countries.
  • TLS Proxy Protocols: Enables proxy and malware inspection for the POP3S and SMTPS (or POP3 and SMTP over TLS) mail retrieval protocols.
  • WebBlocker Updates: Adds the ability to generate alerts by categories (for example, weapons, militancy, or mental health issues).
  • Multiple Server Certificates: Users can now host multiple different servers and applications behind a single Firebox, each with their own proxy certificate.

IntelligentAV is available only as part of WatchGuard’s Total Security Suite and can be used now for all WatchGuard customers with a Total Security Suite license on M270 or higher Firebox appliances, and on all Cloud and virtual appliances.

More about

Don't miss