{"id":27,"date":"2013-06-17T09:52:17","date_gmt":"2013-06-17T09:52:17","guid":{"rendered":"http:\/\/www.3lectrik.com\/normanshark\/?page_id=27"},"modified":"2013-11-12T16:51:42","modified_gmt":"2013-11-13T00:51:42","slug":"hybrid-sandboxing","status":"publish","type":"page","link":"https:\/\/www.3lectrik.com\/normanshark\/products-solutions\/technology\/hybrid-sandboxing\/","title":{"rendered":"Hybrid Sandboxing"},"content":{"rendered":"<h3>Hybrid Sandboxing technology for Malware Analysis<\/h3>\n<p>Norman Shark Malware Analyzer G2 takes malware analysis to the next level with our unique hybrid malware sandboxing model.<\/p>\n<p>Norman Shark delivers unmatched threat intelligence by integrating the latest virtualization technology with the award-winning Norman Shark malware sandbox.\u00a0 This powerful dual-detection approach combines the benefits of code emulation with virtual machine introspection to capture more malicious behavior across a wider range of custom environments than competing solutions that typically rely on a single methodology.<\/p>\n<h3>Norman Shark SandBox \u2013 Powerful Emulation<\/h3>\n<p>Norman Shark pioneered SandBoxing technology, an emulated Windows operating system environment where suspicious samples are run in simulation and examined for malicious behavior.\u00a0 Files execute within the simulator as they would on a real system, but no code ever executes on the targeted CPU, loads into real memory, or communicates with any other physical system components.<\/p>\n<p>Malware samples infect virtual systems inside the SandBox, create and delete files, replicate, connect to carefully controlled IRC servers and URLs, send emails, set up listening ports, or perform most other functions as they would on real systems. Working at the kernel level, the emulator exercises the malware, intercepting behavior and converting it into step-by-step forensic intelligence, providing a map of the damage the threat would cause if allowed to run on a real machine, without ever putting actual systems at risk.<\/p>\n<h3>IntelliVM \u2013 Intelligent Virtual Machines<\/h3>\n<p>A virtual machine (VM) is a software implementation of a computer system that executes programs just like a physical machine, but without putting the physical machine at risk of malware infection.\u00a0 By using virtual machine profiles to mirror alternative types of environments, analysts can quickly spot anomalies and differences in behavior that unveil anti-analysis and other advanced malware evasion techniques.<\/p>\n<p>Norman Shark\u2019s IntelliVM technology monitors a wide range of system events for signs of malicious behavior in a safe, instrumented virtualized Windows system environment.\u00a0 IntelliVM profiles can be customized to add flexibility to analyze non-traditional malware and to precisely mirror custom productions environments to detect advanced and targeted threats.\u00a0 Security analysts can analyze any threat type, in any version of any application they choose, and can precisely match their organizations\u2019 desktop environments, gathering intelligence on malware targeting their specific organizations which may be looking to exploit specific application vulnerabilities.<\/p>\n<h3>KernelScout Technology<\/h3>\n<p>IntelliVM uses Norman Shark\u2019s KernelScout driver, embedding the intelligence observation agent at the lowest level of the system\u2019s kernel. This technology offers several benefits over traditional monitoring techniques, including:<\/p>\n<ul>\n<li>Unrivaled transparency into all critical system events<\/li>\n<li>Superior accuracy of observed intelligence to guide remediation efforts<\/li>\n<li>Faster behavior monitoring to accelerate analysis processes<\/li>\n<li>Generates more intelligence by embedding detection at the lowest level<\/li>\n<li>Avoids detection by common anti-analysis malware techniques<\/li>\n<li>Security against malicious behavior seeking to compromise analysis labs<\/li>\n<li>Advanced rootkit monitoring<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Hybrid Sandboxing technology for Malware Analysis Norman Shark Malware Analyzer G2 takes malware analysis to the next level with our unique hybrid malware sandboxing model. Norman Shark delivers unmatched threat intelligence by integrating the latest virtualization technology with the award-winning Norman Shark malware sandbox.\u00a0 This powerful dual-detection approach combines the benefits of code emulation with [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":0,"parent":25,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-27","page","type-page","status-publish","hentry"],"jetpack_shortlink":"https:\/\/wp.me\/P5TlPb-r","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/27","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/comments?post=27"}],"version-history":[{"count":7,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/27\/revisions"}],"predecessor-version":[{"id":1294,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/27\/revisions\/1294"}],"up":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/25"}],"wp:attachment":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/media?parent=27"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}