Approach to Analyzing Malware
Your approach to analyzing malware is perhaps the single most important factor to understand before making your build or buy decision. The approach you take drives your usage of any given solution, which in turn determines your needs.
Factors to consider:
- Nature of the Problem
- Time to Productive Use
- Expertise to Build and Maintain
- Costs –Initial and Ongoing
- Service Levels
- Reliability and Support
- Continuous Innovation
- Obsolescence and Replacement
- Accountability
- Return on Investment
Challenges of building in-house
Are you able to acquire sufficient knowledge of malware analysis, indicators of compromise, and actionable intelligence, on your own, and maintain it at a consistent level throughout the life of the project? Are you able to build a malware analysis solution to fit your use cases? Will you be able to easily integrate the tool into any workflow? How will you allow for changing needs over time?
Home-grown solutions often lose momentum after the initial deployment, especially if they fail to keep pace with COTS products, and developers are not typically eager to perform maintenance and support tasks for these solutions. Are you prepared to manage the complete product life cycle, including obsolescence planning and eventual replacement?
Factors to consider
- Facing problems common to others
- Prefer to engage in higher level work, customizing no more than 10-15%
- Your stakeholders demand near-term results and insist upon accountability
- Need to get things right the first time
- High opportunity cost between time and money –time is of the essence
- If you are mandated to buy something
A proper malware analysis workbench typically involves a wide range of tools and employs a broad array of techniques in the never-ending fight to defend your organization. Norman Shark’s Malware Analyzer G2 can complement other components –both off-the-shelf and home-grown –and can integrate into multi-step workflow processes through its API.

