Intel adds ransomware detection capabilities at the silicon level

Intel adds ransomware detection capabilities at the silicon level

Intel Server GPU


Image: Intel

At the 2021 Consumer Electronics Show today, Intel announced it is adding ransomware detection capabilities to its new 11th Gen Core vPro processors through improvements to its Hardware Shield and Threat Detection Technology (TDT).

A partnership with Boston-based Cybereason was also announced, with the security firm expected to add support for these new features to its security software in the first half of 2021.


Both companies said that this would mark the first-ever case where "PC hardware plays a direct role" in detecting ransomware attacks.


How it will all work


Under the hood, all of this is possible via two Intel features, namely Hardware Shield and Intel Threat Detection Technology (TDT). Both are features part of of Intel vPro, a collection of enterprise-centered technologies that intel ships with some of its processors.


Hardware Shield, a technology that locks down the UEFI/BIOS and TDT, a technology that uses CPU telemetry to detect possibly malicious code.


Both of these technologies work on the CPU directly, many layers under software-based threats, such as malware, but also antivirus solutions. The idea behind Intel's new features is to share some of its data with security software and allow it to spot malware that may be hiding in places where antivirus apps can't reach.


"Intel TDT uses a combination of CPU telemetry and ML heuristics to detect attack-behavior," Intel sa ..

Support the originator by clicking the read the rest link below.