Welcome Guest. | Log In | Register | Membership Benefits

GFI Software Enhances Dynamic Malware Analysis

GFI SandBox 4.0, scheduled for release Feb. 7, will make advanced malware analysis quicker and easier

Jan 17, 2012 | 05:28 PM | 


Clearwater, Fla. – Jan. 17, 2012 – GFI Software’s Advanced Technology Group (ATG) today announced the latest in a series of enhancements to GFI SandBox™ (formerly CWSandBox) that are making dynamic malware analysis more accessible to cyber-security professionals defending enterprises of all sizes. GFI SandBox is one of the industry’s leading malware analysis solutions. It enables users to test files and URLs for potential threats within a controlled environment so they can deploy and implement appropriate defenses when advanced malware and sophisticated cyber-attacks are discovered.

GFI SandBox 4.0, scheduled for release Feb. 7, will make advanced malware analysis quicker and easier. The solution’s new Malware Determination Engine provides users with risk levels of “Low”, “Medium”, “High” or “Known” for each potential malware sample analyzed. Many users typically submit thousands of samples a day to their GFI SandBox to help identify the sophisticated malware attacks often undetected by standard security solutions. The Malware Determination Engine enables security teams to more efficiently evaluate the increasing volume of malware and cybercrime plaguing enterprises across all industries.

Additionally, users will be able to implement custom determination rules—based on the hundreds of thousands of malware behavior traits detected by GFI SandBox—to assign their own risk levels to samples that perform suspicious and potentially malicious activities.

Cybercrime a Costly, Growing Threat Sophisticated, targeted cybercrime poses a tremendous threat to large enterprises, particularly in industries such as financial services, healthcare and energy, as well as critical entities like power and water utilities.

According to the FBI, “Cyber criminals can significantly threaten the finances and reputations of United States businesses and financial institutions. …the number and sophistication of malicious incidents has increased dramatically over the past five years and is expected to continue to grow.” 1 The FBI also reported that “…of serious concern are threats to critical infrastructure, the theft of intellectual property, and supply chain issues…” and that “Intellectual property rights violations, including theft of trade secrets, digital piracy, and trafficking counterfeit goods, also represent high cybercriminal threats, resulting in losses of billions of dollars in profits annually.”2

Combating Cybercrime “Like firewalls and antivirus software before it, sandbox technology is quickly becoming a vital component of an enterprise’s cyber defense strategy,” said Julian Waits, vice president, Advanced Technology Group, GFI Software. “Enterprises are being targeted with custom-created malware developed for the singular purpose of compromising their network or even a specific user’s workstation. These persistent threats are often undetected by standard security solutions, making it more imperative than ever before that enterprises deploy a sandbox to assess suspect files for malicious behavior and defend themselves against these cyber-attacks.

GFI SandBox enables users to track how potential malware applications execute, what system changes were made, and what network traffic was generated, without risking loss of data or compromising a network. These threats range from familiar exploits on known vulnerabilities to sophisticated, custom malware attacks targeting individual corporations, government agencies, educational institutions or healthcare providers. They are created to steal credit card, bank account and social security numbers, passwords, trade secrets or other sensitive personal and corporate information.

“Previously, the effective deployment and use of sandbox technology has mostly been limited to government agencies and large enterprises with their own highly skilled security teams,” added Waits. “Starting next month with GFI SandBox 4.0, we will introduce a series of enhancements to GFI SandBox in 2012 that will make it easier for any enterprise to integrate sandbox technology into their security solutions.”

GFI SandBox already provides the most accurate and detailed malware analysis of any sandbox solution on the market today. Now, armed with the new Malware Determination Engine risk levels—coupled with the GFI SandBox Digital Behavior Traits™ summary of a suspicious file’s behavior—security professionals will be able to more efficiently and effectively act upon the threats they discover.

To learn more about GFI SandBox 4.0, visit gfi.com, send email to ATG@gfi.com or call 855-443-4284.

GFI will be demonstrating GFI SandBox 4.0 and its latest enhancements to security professionals attending the U.S. Department of Defense Cyber Crime Conference Jan. 23-25 in Atlanta.

About GFI GFI Software provides web and mail security, archiving, backup and fax, networking and security software and hosted IT solutions for small to medium-sized businesses (SMB) via an extensive global partner community. GFI products are available either as on-premise solutions, in the cloud or as a hybrid of both delivery models. With award-winning technology, a competitive pricing strategy, and a strong focus on the unique requirements of SMEs, GFI satisfies the IT needs of organizations on a global scale. The company has offices in the United States, UK, Austria, Australia, Malta, Hong Kong, Philippines and Romania, which together support hundreds of thousands of installations worldwide. GFI is a channel-focused company with thousands of partners throughout the world and is also a Microsoft Gold Certified Partner.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Advanced Threats Reports

report How Did They Get In? A Guide to Tracking Down The Source of an APT
If you think that your organization hasn't been affected by an advanced persistent threat, you probably haven't looked hard enough. Identifying that your organization is under attack is difficult enough; determining the scope of infiltration and damage presents a whole new level of challenge. To effectively protect against APTs, security pros will need to employ an arsenal of tools in a coordinated fashion, as well as develop new understandings of and approaches to system and data exploits. Here's a short and simple guide to this challenge.

report Detecting and Defending Against Advanced Persistent Threats
APTs are a growing problem for enterprises big and small. Protecting your organization from these targeted threats requires constant vigilance, ongoing employee training and a concerted effort to align security systems to address every phase of an APT. Companies also need to develop a remediation and response plan if, despite best efforts, defenses are breached.

report Smarter, Stealthier, Sneakier Malware
Increasingly sophisticated and targeted attacks are making it more difficult for organizations to detect and defend against the latest malware. In this compendium of recent coverage from Dark Reading, you?ll get a look at some of the newest -- and most dangerous -- malware on the Web, and what you can do to stop it.

Other reports from the Advanced Threats Tech Center:

Related Content

MOBILE SECURITY - Mapping an Ecosystem of Risk
This white paper highlights the various considerations for defending mobile applications-from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.

Software Security Delivered in the Cloud
This Solution Guide details the automated, turnkey service that requires no special security assessment expertise. It details HP's market-leading static and dynamic analysis technologies that help organizations worldwide gain insight into the security state of their essential business applications.

SANS Mobility/BYOD Security Survey
This survey, which includes input from more than 500 IT professionals, explores how organizations are managing risk around their end user mobile devices as well as what level of policies and controls enterprises have around mobile usage.

Expert Guide to Application Security - Real-time Hybrid Analysis
Explore the next generation of hybrid security analysis - what it is, how it works, and its benefits. This white paper details how hybrid application security enables organizations to resolve critical software security issues faster and at a lower cost than any other available technology.

A Mainstay Partners Study: Does Application Security Pay?
Measuring the Business Impact of Software Security Assurance Solutions: a study of 17 organizations that implemented solutions from Fortify Software, combining industry research and benchmark analysis to identify, qualify, and quantify the full range of benefits seen from their SSA investments.




Featured Webcasts
Featured Whitepapers
Featured Reports