About DayZero

Malware

Trojan Horse

Development

Try Now ButtonAbout SigFree DLL

The SigFree DLL is signature free, does not rely on string matching, and does not slow down the host system.

SigFree Performance Summary

The SigFree DLL was tested extensively throughout its development, in both lab and real-world scenarios.

With every test, improvements were made in methods of detection and SigFree's effectiveness.

Improvements included the development of unique techniques to defeat polymorphism, encryption, metamorphism, and self-modification. SigFree is also anti-disassembly and anti-emulation.

And the development of real life applications as a test bed were also instrumental in SigFree's continuous improvement, a standard we intend to maintain.

SigFree Performance Summary

  • Against attack
    • In-lab: 12,000 polymorphic payloads, plus 5 worms
      • Zero false negatives
    • In the wild: 1 month 475,297 incoming packets
      • Detected 2,074 attack packets
      • 45 of them were not detected by Snort
  • Against benign packets
    • Tested against 1.77GB real traces that include 378,158 HTTP requests/replies
      • False positive rate: 0.0079%
      • Throughput: 11.65 Mbps
      • Collected by honeypots
 

Solution Sets