Antian Pan Xuanchen: Mobile Anti-Virus, Eternal War

On January 9, 2007, Joe helped the owner pull out the world's first iPhone from his pocket.

On September 23, 2008, Google demonstrated to the world Android's G1.

These tiny screens spliced ​​out a new world scene, changed the lives of many people, and formed a dam, diverting the destiny river of Pan Xuanchen.

In the history of any mobile malicious code family, including every variant, we have done at least one manual analysis. Pan Xuanchen, head of security mobile security security company, said to Lei Fengwang (search for "Lei Feng Net" public number) home channel (public ID: letshome). There is no pride in the tone. Currently, Antiy AVL Mobile Anti-Virus Engine provides security services for ROM vendors including MIUI, YunOS, Gionee, Cheetah, LBE and APP developers.

Even today, when the cyber security industry broke out, few people dare to use this “living dictionary” gesture to show that their team and all mobile malicious code have “fighted”.

A simple repetition is just as spectacular as another angle.  

Pan Xuanchen

Fall in love with information security

The Matrix

"I hope to see the principle and mechanism of various things. The integrated network security and security is stronger, so it is more suitable for the personality that I long to explore." Pan Xuanchen explained why he chose the information security major of Wuhan University. Wuhan University is the first undergraduate information security major in China. There are professional teachers like Zhang Huanguo and Peng Guojun and other outstanding young teachers. In the freshman year of the university, Pan Xuanchen saw the film "Hacker Empire" that had touched many people.

The world you know is not all of it.

For the first time, "Code" impacted his world in such a concrete way. Pan Xuanchen suddenly found that the code in his hand became sharp and sharp enough to penetrate reality and tear open the entrance to another world.

New World Entrance

For a curious person, once the unknown world has been opened, it will become a nightmare.

The deep memory of Pan Xuanchen’s exploration came from a junior year. That year, he was recommended by the information security major at Wuhan University to participate in the exchange program of Nanyang Technological University in Singapore.

Singapore’s copyright awareness is so strong that we are afraid to download movies online. However, Windows had a default feature at that time, which was to share certain disk directories by default. I built a script using network vulnerabilities, searched the campus LAN, and searched for movies stored on all other computers.

But the result of this matter is not quite the same as I imagined. At first I found a lot of big movies, but then I suddenly felt scared. I suddenly realized that the security was so fragile that everyone needed protection.

He told Lei Feng network channel guest (public ID ID:letshome), this is his first time in the actual scene, experienced the "interesting" of network security technology; "but more importantly, I feel the network security Serious and heavy."

An Tian Jiang Haike

Wuda Information Security is the first professional undergraduate in information security in China. It is highly prestigious in China, and all the big cows are invited to teach lectures to students. However, Pan Xuanchen was very impressed with the uncle's uncle.

This person is Xiao Xinguang, the net name Jiang Haike, the founder of Antian Lab.

Jiang Haike (right) and Pan Xuanchen (left)

He touched me with two things: First, the pursuit of original technology, and second, the feeling of national industry. Pan Xuanchen said.

In 2007, Pan Xuanchen of junior year applied for an internship at the Antian laboratory. On the entry form of the interns, he filled in the sentence. "I volunteered for work in information security for the rest of my life. This is my interest and my ambition..."

During the interview, Pan Xuanchen said to Jiang Haike: “What I believe will definitely persist.”

After the internship ended, Pan Xuanchen received the plan for the development of the SOHO Research Working Group of Antian Lab. He decided to join this plan and form the Antian Wuhan Research Team. Thus, a three-person working group was established in Wuhan, and Pan Xuanchen remembered the film that had a deep influence on him. He named the research group "X-Matrix." This is the predecessor of Antisky Mobile Security.

Pan Xuanchen said that Matrix's influence on me is profound, especially in understanding and persisting in diversity. The truly dynamic organization and dynamic world must be diverse. I use Matrix and I hope my team is also diverse. Our team follows the original intention and adopts a flat group structure. Each team is a Matrix and multiple teams form the X-Matrix.

For Pan Xuanchen, that period of time was full of challenges.

Design, code, organize teams, develop new people, attend classes, and participate in school activities. The first project undertaken by X-Matrix has nothing to do with mobile security. It is the development of the Antivirus WEB detection system “Hunting Fox” platform. This system has invested in the security work of 2008 Beijing Olympics undertaken by Antian. However, Antiy's internal acceptance was rigorous and gave a bad review to this system. The second project is a mobile analytics tool and the results are not satisfactory. Despite being criticized by the headquarters, Pan Xuanchen is still very up-and-out. And gradually set his sights on the direction of mobile security. In the history of Antian, he had tried security exploration on mobile platforms such as WINCE and smart Linux, but it was because of the fact that the relevant operating systems had not become mainstream scenes. Will the iPhone be the main battlefield for mobile security? Is Symbian still necessary to invest? Android? He repeatedly guessed where he wanted to make the right choice. At this time, life also needs to choose, graduate students graduate, is to go to the Internet company to get a high salary, or stay in the sky, continue the idea of ​​network security. He predicted that a mission was coming. Sure enough, he received a letter from Jiang Haike who said:

"The determination of Antian whether to establish Wuhan R&D center or even Wuhan Research Institute in the future is mainly your determination."

After a night of thinking, he made up his mind. However, he also needed to form a team. He took the initiative and changed the “you” of Jiang Haike’s letter to “you” and transferred it to other XMatrix buddies who also faced graduation. They talked and talked repeatedly. Afterwards, Antian Wuhan R&D Center began to bloom.

In 2010, Antian gave a position to “Wuyan” as “an R&D team that focuses on the foundation, emphasis on high-end, and takes mobile security as the leading factor”.

Guns, ammunition and play

I do not define myself as a hacker but an information security engineer. For me, hackers are the spirit and values ​​of “drilling, opening, and sharing”. I am longing for this spirit and can chase that state and feeling to some extent, but this is not my identity.

Antian attracted Pan Xuanchen's research and development focused on the core technology of anti-virus engines. However, Antian people know that the growth history of internationally renowned manufacturers is more than a decade longer, and the accumulation of technology and the details are not simply solved by hard work. Therefore, An Tian's more basic force in the AVL detection engine is more rapid detection speed, and more extensive detection scenes. If Antin wants to surpass the anti-virus pioneers that emerged in the late 1980s, Must take the lead in a new space. When the space for mobile security has emerged, this responsibility falls on Pan Xuanchen and his team.

2011 - Gun

In the first year, there were fewer than four full-time employees on the company. Pan Xuanchen rejoiced that he had retained the most effective Qiao Wei and other teammates in the research team. They carried the expectations of Antian to create a perfect mobile engine.

To achieve the deepest level of virus identification, you need to have the ability to detect the underlying code. What we do is binary level monitoring. Each APK installation package has a lot of files, including resources, descriptions, DEX, executable files, and its own structure and function symbols. One of the important parts is the machine instruction code. And these underlying code may be exploited to attack.

Pan Xuanchen said that with this series of in-depth inspections, it seems that only a handful of vendors have done it all.

It is difficult to defend one side and open up land. It is not the same as doing an internship at the headquarters. At that time, even the engine room is my own maintenance. The biggest difficulty faced is the frequent blackout of the equipment room. Once the power outage service is forced to stop, but it is irresistible.

With the initial appearance of the work, Antiy mobile anti-virus engine has begun to cooperate with LBE security guru, Kingsoft mobile phone drug tyrants (now Cheetah mobile security), also began to use for the National Internet Emergency Center and other regulatory agencies.

However, it was slightly out of the expectation of Pan Xuanchen. That is, after a partner test, Antiy AVL mobile anti-virus engine detection rate of the virus is not high, only 60% -70%. The feedback from the partners is that the engine is good and you have implemented all the testing branches that we can imagine, but your rules cannot cover all the samples.

Pan Xuanchen gave an interesting analogy to the Lei Feng network residential channel (public ID: letshome) .

Antin has developed a good gun, but this is far from enough. We also need an ammunition factory to provide ammunition.

These ammunition is the analysis of massive virus samples. In the face of 10 times a year's worth of malicious code samples, only 4 core members of the team obviously have no ability to produce "ammunition."

2012 - Bullets

Pan Xuanchen asked Jiang Haike. The headquarters will give support to Wu Yan. Jiang Haike said that there is only one support I can give you, and that is to allow you to recruit people without restraint.

Pan Xuanchen recalled: At that time, the mobile security market had begun to show its initial vitality. Although we started very early, the lack of personnel has seriously affected the effectiveness of our products. We judge that if there are less than 35 teams in the first half of 2012, we will not have to do this.

However, it is difficult for the extended team to recruit "malicious code analysis engineers." Antian Wuyan's recruitment notice is said. A month later, no one even cast a resume.

Wuhan does not have as many high-biological security personnel as North Guangzhou, Shenzhen and Shenzhen, and the vacant little Pan is messy in the wind. However, the time was not waiting for him. He had a plan to change his position to become an "Android Security Test Engineer." In his words, "people who have R&D and code base, but are reluctant to do first-line code, are recruited first." After coming, he will train malicious code, and then work directly, and he can't stay full. He must have a 50% elimination rate. This is how our first wave of 5-7 engineers came. Of course, they are now at the core level.

Pan Xuanchen described what he did as “filling the system with people.”

This was not done. In the first internal evaluation of mobile security of AV-Test, an internationally renowned security software evaluation agency at the end of 2012, the detection rate of Antivirus AVL mobile anti-virus engine averaged 10% to 15% of the industry's leading level. This is the first time that domestic security companies have exhibited technological suppression in the world's anti-virus field. Pan Xuanchen relishes that, in 2013, Antiy AVL mobile anti-virus engine won the first of three AV-Test evaluations, and won the “Most Mobile Device” with the highest average annual detection rate. Good Protection" award. In 2015, another authoritative testing agency AV-C annual test, Antiy AVL mobile anti-virus engine also became the only product to achieve 100% detection rate in the first half.

Pan Xuanchen at the AV-Test Awards

2013 - Man Machine

There is an important watershed between the orientation of engineers and the orientation of hackers.

The hackers are more of a flair for personality and intelligence, but for engineers, they know that it is not themselves, but the product and the back-end support system that directly confronts the attackers. They must believe in teamwork and must use the engineering system to extend the team's experience and capabilities.

In 2013, Pan Xuanchen was faced with the problem that the number of malicious code geometries broke out, and the manpower of Antisky Mobile could not be increased indefinitely, and it must be supported by a more powerful engineering system. Jiang Haike’s request for this system is even more maddening. “The combination of mass batch processing and high-price fine processing must be combined to further meet the requirements of malicious codes for traceability, and we must be able to find relevance and find the root cause.”

When Pan Xuanchen practiced in Antian, the most interesting system was the “virus automated analysis pipeline”. He feels that this traditional assembly line automatically emphasizes too much, but the integration of people's experience is not enough, resulting in unsatisfactory judgment of unknown malicious code. “People are good at fine, high-quality single-point operations, and the machines are suitable for large-scale copying operations. In the malicious code determination process, I have to constantly increase the proportion of machine work, and let people concentrate on the most important position. At the same time, we must combine the two."

This is far easier than saying. The church machine, like a human being, makes the best judgment among the thousands of choices. The difficulty is nothing more than teaching gorillas to dance ballet. Changes to the algorithm, additions and deletions of rules, and attempts to modify each time are at risk of regression.

We have tried to develop a system to classify samples without any prior experience, and then manually analyze typical samples of a class. This can further reduce manpower. Although we have developed this system and the recognition rate exceeds 97%, which is comparable to humans, the system needs two engineers to maintain at the same time. The same thing can be done with only one engineer using a purely manual method. So after a month on the line, we still put it offline.

He was used to these repetitions and frustrations. Looking back today there is a data that can prove that their efforts are working well. Since the past 13 years, the number of mobile malicious code has increased by a factor of 100. However, the number of malicious code analysis engineers of Antisky Mobile has only doubled.  

Malicious code and engineer growth curve comparison/image provided by Antian Mobile

The history of human science and technology can be summed up as follows: The process of constantly replacing human labor with machines. The development of the Anti-Virus mobile anti-virus engine and support system seems to be confirming this. Pan Xuanchen valued the power of the machine but did not superstition the power of the machine.

Fried Cohen published a well-known paper about the impossibility of having a system capable of detecting all malicious code. Jiang Haike said that this paper made security workers give up on the unrealistic theoretical imagination of anti-virus technology and embarked on the right path of continuous confrontation.

People can never withdraw from this battle because your opponent is also human.

However, Pan Xuanchen is not pessimistic. He said to the Leifeng Net Home Channel (Pub ID: letshome) : "At present, we have made a balance between man-machine and the next step is to face new issues as long as they can be solved with low labor costs. The problem, we can always maintain its superior position in the virus confrontation."

Team.Leader

When Google resorted to Android 1.0, it may not have predicted that this small screen would soon become the main battlefield of the "Matrix."

Pan Xuanchen did not anticipate that Antiy AVL Mobile Anti-Virus Engine will provide 400 million mobile phone users with security guarantees as soon as they read the sample of the virus family.

In 2013, 26-year-old Pan Xuanchen became the youngest partner of Antiy.


In 2014, following the implementation of the core team incentive plan, Antian Wuhan R&D Center has been restructured into Antian Mobile Security Co., Ltd. and has become one of the two major business units in the grouping layout of the two wings. Pan Xuanchen became the CEO of Antisky Mobile Security Company without any suspense.


In 2016, Antian Mobile Security released the AVL Insight threat intelligence platform. The responsibility for designing the Antiy Global Threat Intelligence Support System falls on the shoulders of Pan Xuanchen.

For the future, this security mobile security Shuaishuai said:

The anti-virus engine is our technical kernel. It is not enough to have only one core. Our mission is to respond to a wider range of threats and solve more security problems for users in mobile and more emerging scenarios.

High Voltage Linear Power Supplies

HVLP series Linear High Voltage Power Supplies are High-voltage DC Power Supplies that achieve AC/DC conversion through power frequency transformers and transistor loop control. Compared with switching high voltage power supplies, linear high-voltage power supplies have higher stability, higher accuracy, and lower output ripple. And the most important, because of the use of the power frequency AC/DC conversion principle, the linear power supply has no high-frequency radiation interference, and it is especially suitable for use in places with restrictions on EMC and EMI.


High Voltage Linear Power Supplies


The HVLP series Linear Power Supplies have a wide range of output specifications, the output power ranges from 1KW to 400KW, and the output voltage can reach up to 50KVDC, and accept customization.

The whole series linear power supply adopts industrial-grade metal chassis, pure copper AC/DC multi-insulation high-voltage transformer with varnish treatment, high-reliability multi-transistor filter loop, ensuring the power supplies can run for a long time at full load with high stability, high accuracy, and ultra-low ripple electronic characteristics, equipped with a complete protection circuit, which can better ensure the reliability of the linear power supply itself and the safety of the customer's load.
The output voltage and current can be adjusted by the 10-turn potentiometer with scale and lock on the front, equipped with 4 1/2-digit high-resolution LED meters for output value reading, and RS communication interface can also be added for remote control and monitoring of linear power supplies.

This series of linear high voltage power supplies are mainly used for gas discharge, high-voltage electronic tubes, and can also be applied for other electronic components burn-in test.
Because the output this power supply has HV, the output MUST be connected to the chassis for fixed grounding to ensure the personal safety of the user.

High-voltage Linear Power Supplies,Linear High Voltage Power Supplies, HV Linear Power Supplies, Linear HV Power Supplies, Linear HVPS

Yangzhou IdealTek Electronics Co., Ltd. , https://www.idealtekpower.com