Question: Why does ETA for Malware Detection ( ETA - MD ) require connectivity to Cognitive Threat Analytics ( CTA ) ? ETA - MD cannot
Why does ETA for Malware Detection ETAMD require connectivity to Cognitive Threat Analytics CTA
ETAMD cannot decipher the Initial Data Packet IDP to determine which negotiated cipher suites and protocols are in use between the endpoints.
ETAMD cannot use the packetrecirculation engine in the UADP ASIC because the packetrecirculation bus in the ASIC is encrypted and would lead to double encryption if it were used.
CTA is the architectural entity that is able to perform unsupervised machine learning to determine anomalies, relationships, and final classification of unknown entities.
CTA is the architectural entity that is able to consult the Global Risk Map for matching the hash of the encrypted traffic to knowndeciphered malware.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
