Actionable Intelligence for Malware Defense.

Threat Protection » Automated Malware Analysis
Automated Malware Analysis

Malware Analysis and the Cyber threat landscape

Enterprise IT organizations face a cyber threat landscape that is constantly changing, and rarely for the better. The complexity of attacks on IT systems grows exponentially as the number of systems and interconnections between them increases.  Additionally, the types of attacks from malicious software (malware) are changing, ranging from the more ‘traditional’ (viruses/worms) to newer targeted attacks such as spear-phishing and advanced persistent threats (APT). With no technology immune to cyberattack, and with many ways to break into a network, enterprise IT organizations face an uphill battle in attempting to keep their systems and data safe from advanced threats and targeted attacks

Malware analysis has been part of this attempt to keep IT entities safe for more than a decade.  An organization can reverse engineer any sample(s) they obtain to get an idea of what the attacker is trying to accomplish, and by what methods.  Traditionally this has been the purview of the highly technical, requiring arcane computer knowledge and high levels of patience and exactitude.  Such difficulties may not be insurmountable with the proper people and equipment, and the benefits to the organization are numerous: indication of what vulnerabilities were exploited in the attack, an idea of what a particular attacker was attempting to do (theft, disruption, etc.), and a complete blueprint of the cyber-weapon(s) used in the attack.  By examining these indicators of compromise (IoC), the enterprise IT organization can gird their defenses against this attack and attacks of a similar nature.

Malware analysis – a specialized skillset

Analyzing and/or reverse engineering malware requires a highly specific skill-set, and while the number of people with malware analysis skills is increasing as the field matures, that increase does not currently keep pace with the ever-growing number and complexity of cyberattacks. And the volume of attacks is expected to continue their rapid growth.  Without the right type and number of staff, enterprises face the risk of being unable to address the issue at its most basic level, and certainly not as it advances.  This risk is especially onerous, as being unable to investigate incidents or respond properly to attacks leaves the organization open to a host of issues.  Additionally, when it is discovered that a particular firm is vulnerable, this information may be shared publicly, thereby compounding the initial problem.

Malware analysis provides the critical information you need to effectively respond to malicious software threats that elude traditional defenses.

  • Detect suspicious files on your network
  • Determine a suspect file’s capabilities
  • Identify all infected machines and files
  • Understand exactly how the breach occurred
  • Measure and contain any damage done
  • Remediate to reduce future vulnerabilities
“In today’s climate of persistent threats, network defense alone is no longer enough. In order to protect networks from the proliferation of targeted attacks and unknown threats, analysts need dynamic malware intelligence capabilities that allow them to respond quickly in the event of an incursion.”