Actionable Intelligence for Malware Defense.

Threat Protection » Build vs. Buy
Build vs. Buy

Approach to Analyzing Malware

Your approach to analyzing malware is perhaps the single most important factor to understand before making your build or buy decision.  The approach you take drives your usage of any given solution, which in turn determines your needs.

Factors to consider:

  1. Nature of the Problem
  2. Time to Productive Use
  3. Expertise to Build and Maintain
  4. Costs –Initial and Ongoing
  5. Service Levels
  6. Reliability and Support
  7. Continuous Innovation
  8. Obsolescence and Replacement
  9. Accountability
  10. Return on Investment

Challenges of building in-house

Are you able to acquire sufficient knowledge of malware analysis, indicators of compromise, and actionable intelligence, on your own, and maintain it at a consistent level throughout the life of the project?  Are you able to build a malware analysis solution to fit your use cases?  Will you be able to easily integrate the tool into any workflow? How will you allow for changing needs over time?

Home-grown solutions often lose momentum after the initial deployment, especially if they fail to keep pace with COTS products, and developers are not typically eager to perform maintenance and support tasks for these solutions.  Are you prepared to manage the complete product life cycle, including obsolescence planning and eventual replacement?

Factors to consider

  • Facing problems common to others
  • Prefer to engage in higher level work, customizing no more than 10-15%
  • Your stakeholders demand near-term results and insist upon accountability
  • Need to get things right the first time
  • High opportunity cost between time and money –time is of the essence
  • If you are mandated to buy something

A proper malware analysis workbench typically involves a wide range of tools and employs a broad array of techniques in the never-ending fight to defend your organization.  Norman Shark’s Malware Analyzer G2 can complement other components –both off-the-shelf and home-grown –and can integrate into multi-step workflow processes through its API.

“In today’s climate of persistent threats, network defense alone is no longer enough. In order to protect networks from the proliferation of targeted attacks and unknown threats, analysts need dynamic malware intelligence capabilities that allow them to respond quickly in the event of an incursion.”