Tuesday, April 27th 2021

Intel Collaborates with Microsoft against Cryptojacking

Starting today, Microsoft Defender for Endpoint expands its use of Intel Threat Detection Technology (Intel TDT) beyond accelerated memory scanning capabilities to activate central processing unit (CPU) based cryptomining machine learning (ML) detection. This move further accelerates endpoint detection and response for millions of customers without compromising experience.

"This is a true inflection point for the security industry as well as our SMB, mid-market and enterprise customers that have rapidly adopted Windows 10 with built-in endpoint protections. Customers who choose Intel vPro with the exclusive Intel Hardware Shield now gain full-stack visibility to detect threats out of the box with no need for IT configuration. The scale of this CPU-based threat detection rollout across customer systems is unmatched and helps close gaps in corporate defenses," said Michael Nordquist, senior director of Strategic Planning and Architecture in the Business Client Group at Intel.
Intel TDT, part of Intel Hardware Shield's suite of advanced capabilities on Intel vPro and also available on Intel Core platforms, equips endpoint detection and response (EDR) solutions with CPU heuristics for advanced memory scanning, cryptojacking and ransomware detection. With nearly a billion Intel TDT-capable PCs in the market, these are the only CPU-based malware behavior-monitoring capabilities in market that go beyond signature and file-based techniques.

"Intel is unlocking capabilities in its system on a chip that fundamentally change the rules of the game," said Frank Dickson, program vice president of Security and Trust at IDC. "The silicon-level telemetry and functionality enable the hardware compute platform to play an active role in threat defense against 'above-the-OS' attacks. Clearly the goal is to empower Intel -based systems of today and tomorrow to be fundamentally more secure and have lower malware infection rates than AMD, Apple and other ARM-based processor systems."

In April 2020, nearly 5,400 cryptocurrencies with a total market capitalization of $201 billion were traded. Since then, the market value has increased as cryptocurrency is making its way into the mainstream. The financial rewards of cryptocurrency create new threats and risks. As their value rises, cybercriminals shift their focus from ransomware to cryptojacking.

Cryptojacking is malicious cryptomining where cybercriminals install malware into business and personal computers, laptops and mobile devices. This malware uses the computer's power and resources to mine for cryptocurrencies or steal cryptocurrency wallets that can slow computers dramatically and keep them from operating normally. Some cryptojacking scripts have worming capabilities that allow them to infect other devices and servers on a network.

Intel TDT helps endpoint security solutions harness CPU telemetry and hardware acceleration to help identify threats and detect anomalous activity. It uses a combination of CPU telemetry and machine learning (ML) heuristics to detect specific behavior. The CPU performance monitoring unit (PMU) sits below the applications, operating system and virtualized layers to provide a greater view into active threats across the stack. Intel TDT bolsters EDR solutions and improves visibility where it has historically been a challenge, including the increasing trend of malware attempts to cloak itself in a virtual machine.

"This partnership is one example of our ongoing investment and deep collaboration with technology partners across the industry. We work closely with chipmakers to explore and adopt new hardware-based defenses that deliver robust and resilient protection against cyberthreats," Karthik Selvaraj, principal security research manager at Microsoft. "As organizations look to simplify their security investments, built-in platform-based security technologies, such as the integration of Intel TDT with Microsoft Defender for Endpoint, combine best of breed in a streamlined solution."

As threats are detected, Intel TDT sends a high-fidelity signal that triggers remediation workflows of EDR solutions to help protect the infected PC and prevent lateral movement across the corporate fleet. The telemetry and ML heuristics are seamlessly incorporated as part of the endpoint solution and multiple concurrent detectors can run in parallel.

This advanced threat detection doesn't create a performance hit requiring IT leaders to make a tradeoff between better security or a good user experience. Intel TDT can offload performance-intensive security workloads to the integrated graphics controller and return performance back to the CPU, allowing for increased scanning and reduced impacts to the computing experience.

The threat detection capabilities are native to Intel Core and vPro platforms and operate seamlessly with EDR solutions without the need for installation or deployment IT configuration. When combined with remote monitoring and maintenance, rigorous cybersecurity defenses of Intel Hardware Shield, and no-contact deployment of the 11th Gen Intel Core vPro mobile processor, customers are assured they have the world's most comprehensive hardware-based security for business.
Add your own comment

8 Comments on Intel Collaborates with Microsoft against Cryptojacking

#1
R-T-B
Crptojacking is a fancy new term. From when I used to hear about people being prosecuted for this, they'd just call it what it was "energy theft."
Posted on Reply
#2
AsRock
TPU addict
R-T-BCrptojacking is a fancy new term. From when I used to hear about people being prosecuted for this, they'd just call it what it was "energy theft."
Well that be to much for anyone to handle now HAHA, TBH i am tired of the BS.

All so makes me thing of a George Carling clip too.
Posted on Reply
#3
Lycanwolfen
Hmmm Microsoft says it going to stop this yet they use telemetry which is tracking in there OS themself's. I never trust microsoft period bunch of lies. Every new OS update or patch they install it's like what the hell did they change this time without letting anyone know.
Posted on Reply
#4
1d10t
Clearly the goal is to empower Intel -based systems of today and tomorrow to be fundamentally more secure and have lower malware infection rates than AMD, Apple and other ARM-based processor systems
So they admitted to have many shortcomings compared to competitors.
Posted on Reply
#5
Tartaros
LycanwolfenHmmm Microsoft says it going to stop this yet they use telemetry which is tracking in there OS themself's. I never trust microsoft period bunch of lies. Every new OS update or patch they install it's like what the hell did they change this time without letting anyone know.
And everyone and her mother uses telemetry in their software, so moot point. And whenever they will succeed or not in the criptominers problem, it's something that hasn't anything to do with that, what's your point?
Posted on Reply
#6
Caring1
R-T-BCrptojacking is a fancy new term. From when I used to hear about people being prosecuted for this, they'd just call it what it was "energy theft."
I've only heard of "mining bots" as a malware, to me energy theft is stealing power from a neighboring property or directly from the power lines.
Posted on Reply
#7
ThrashZone
Hi,
Yeah defender samples sending funny all your personal files will be samples sooner or later that's how ms finds stuff lol
Posted on Reply
#8
R-T-B
Caring1I've only heard of "mining bots" as a malware, to me energy theft is stealing power from a neighboring property or directly from the power lines.
They are talking about employees mining on company hardware / power though, which is the same thing really.
Posted on Reply
Nov 21st, 2024 13:12 EST change timezone

New Forum Posts

Popular Reviews

Controversial News Posts