IEEE Anti-Malware Support Service

Wednesday 5 October 16:00 - 17:00, Small talks

Mark Kennedy (Symantec)

One of the truly remarkable characteristics of the Anti-Malware industry is its willingness to share information among competitors. While we all compete economically, we are united in the effort against our real competition – the bad guys. One of the great facilitators in this sharing has been the IEEE Industry Connections Security Group. This group, made up of players from across the AM space, has focused on areas of common pain. The belief being that there are certain ancillary tasks that each of us must perform, and that these tasks consume resources that could be better used fighting the fight.

A major contribution of this group is the Anti-Malware Support Services (AMSS). AMSS has focused on the common problem of false positives (FP). The Taggant system allows us to identify the common user creating packed (or commercially obfuscated) programs. Packed files have long been a FP concern, since so much malware is packed and packed files have a tendency to trip static heuristics. The other area of AMSS is the Clean-file Metadata eXchange (CMX). This allows legitimate software companies and organizations to publish metadata about their files before they are actually released. This allows cloud-based FP mitigation technologies to pre-position this data even before the first customer sees the file.

This talk will cover a little bit of history, report on the current state of things, and discuss where we might go in the future.

Click here for more details about the conference.


Mark Kennedy

Mark is a distinguished engineer with Symantec, where he has worked for the last 25 years. Apart from his work with Symantec, Mark also serves on the Board of Directors of AMTSO, as well as chairman of several IEEE committees. He has spoken at numerous conferences around the world – including several appearances at Virus Bulletin.


We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.