When automatic updates don’t always succeed at blocking malware, a decentralized network might just do the trick. This is the basic disruption that LevelNet wants to introduce to the security community and the internet at large.
Every year, hundreds of millions of new, unique pieces of malware are discovered. According to Symantec’s Internet Security Threat Report, 2015 saw 430 million unique new malware. And while this went down to 401 million in 2016, the growing threat is not just in the numbers, but rather in execution. According to the report, attacks usually evolve, in order to exploit new or pre-existing loopholes.
Some attacks are purely based on social engineering alone, but majority of malware attacks can be detected through heuristics – or the detection through behavior – which means anti-malware software will still play a big role in detecting, preventing, and dealing with potential virus or other security attacks.
There is a big challenge in ensuring protection for internet users, however, in terms of using virus definitions and updates. For one, different anti-malware apps use different ways to detect an attack – some use databases, while some use heuristics. In addition, with so-called zero-day attacks (those that have not yet been identified), not all antivirus apps might have the definitions yet. And in reality, malware authors take pains to disguise the activity of their creations, which makes it all the more difficult to detect and capture.
Perhaps the biggest challenge is from the users. Not everyone utilizes automatic updates on their operating system, applications, and anti-malware software. This means that some users might be missing out on important updates that could otherwise help keep their systems more secure.
The differences in heuristics capability, plus the non-compliance in terms of updating, are a deadly combination. Even an over-reliance on security updates can lead to a false sense of security.
A decentralized approach
GData estimates that this year, a new malware specimen will emerge every 4.2 seconds, up from last year’s 4.6 seconds. Short of knowing what each kind of malware actually does, a device user will need a capable defense against such emerging threats. The problem is that security patches and updates only come so often, and even critical updates are only pushed out once a developer finds a fix.
Here’s where a decentralized approach to security can improve things. Security startup LevelNet aims to leverage its distributed network in order to ensure that all of its users benefit from anti-malware applications and security updates whether or not they actually have these updates installed.
“On average, one virus attack by hackers takes no more than 30 minutes, and at this point antivirus products do not have time to update their own mechanisms to protect users,” says Daniel Fadeev, data analyst at LevelNet. “Those who manage to make an update protect their users, and who do not have time to do it leave their users unprotected.”
To address this, LevelNet will ensure that all members of its network are protected, in a one-for-all approach, by essentially sharing data and information across its entire network, so that all connected computers can benefit from updated signatures, which are essentially synchronized across the network.
No need for local antivirus deployment
The innovative nature of LevelNet means users do not even have to have anti-malware applications installed locally, as the platform itself acts as the intrusion detection and mitigation solution. “LevelNet End-Point Security App works as a stand-alone solution and with any installed antivirus product without the need to delete it,” says Fadeev. “Our application extracts a response to the checked object of the installed antivirus and transfers it to all users of our network, in order to prevent a virus attack.”
Still, having LevelNet’s solution does not preclude having an existing anti-virus application in the first place; Fadeev says this will further complement the solution, and that it will not result in a conflict.
A hybrid approach
Perhaps unique with LevelNet is its hybrid approach to blockchain-based security. LevelNet’s technology does not run on blockchain, per se. Instead, the company uses the blockchain to tokenize its service, which utilizes its own proprietary distributed network. “We use a peer-to-peer network for fast distribution of information on emerging threats; plus a cloud model for identifying and verifying threats,”says Fadeev.
He adds that the use of blockchain technology on the end-user application itself “does not make sense because of security and user-friendliness reasons.”However, the use of tokens can be an innovative approach to value exchange.
To this end, the company is launching its tokensale later this year, seeking to raise $55 million to fund its development and deployment. LVL tokens will be the “currency” use to gain access to LevelNet’s network.
The takeaway: Hybrid approach has its advantages
LevelNet’s P2P and cloud-based approach to security is innovative in that it gives users better assurance of security without being tied to separate security software providers. The hybrid approach also provides insights and lessons into how existing businesses can effectively leverage blockchain technology in their solutions and services, without fully deploying on the blockchain. This could be done by tokenizing their digital services, or even through raising capital through a tokensale.