Risk
2/16/2012
01:36 PM
50%
50%

CIA Hunts For Malware In Binary Code

Agency invests in ReversingLabs, whose TitaniumCore software analyzes code at its most basic level to identify anomalies that might be malware.

Slideshow: Who's Who In U.S. Intelligence
Slideshow: Who's Who In U.S. Intelligence
(click for larger image and for full slideshow)
The CIA is investing in security technology that analyzes application code at the binary level to help identify anomalies that might indicate the presence of malware.

In-Q-Tel (IQT), a CIA-based nonprofit that identifies emerging technologies to support the U.S. intelligence community, has struck a strategic partnership with ReversingLabs, which offers technology for the rapid analysis of unknown binary content, according to IQT.

Specifically, ReversingLabs' TitaniumCore platform decomposes code and attempts to analyze every file in a system, kicking out anything that it doesn't recognize as being legitimate code so those bits can then be analyzed for malware.

Although binary analysis tools like the company offers are widely used to find any strange code coming into the enterprise, most look for malware by identifying code that's recognized to be bad. TitaniumCore's analysis of all of the code in an enterprise sets it apart from these tools.

[ Hackers have embarrassed the CIA. See LulzSec Claims Credit For CIA Site Takedown. ]

The data resulting from the analysis can be mapped against ReversingLabs' database of artifacts on more than 100 TB of goodware and 30 terabytes of malware files, according to IQT. This allows security pros to analyze unknown threats even with a large volume of code samples.

IQT will develop ReversingLabs' technology for the Department of Homeland Security Science and Technology Directorate, which is one of IQT's customer agencies.

In return, the company's technology--which has broad appeal for enterprise customers outside of the intelligence community as well--will get more visibility with its potential market, said Mario Vuksan, company CEO, in a press statement.

"Our partnership with IQT will create new opportunities for leveraging ReversingLabs' versatile and multifunctional binary analysis and scalable cloud-based technologies into related applications," he said.

The CIA launched In-Q-Tel in 1999 as an independent entity to find useful new technologies to support the intelligence community's mission.

Security technologies have been a particular area of investment over the past year, with In-Q-Tel striking deals with companies that offer continuous monitoring of security infrastructure; secure virtualization technology; and technology that protects PCs from visual eavesdroppers.

How 10 federal agencies are tapping the power of cloud computing--without compromising security. Also in the new, all-digital InformationWeek Government supplement: To judge the success of the OMB's IT reform efforts, we need concrete numbers on cost savings and returns. Download our Cloud In Action issue of InformationWeek Government now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2382
Published: 2014-11-20
The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (crash) and execute arbitrary code via a crafted IOCTL request that writes to arbitrary memory locations, related to the IofCallDriver function.

CVE-2014-3625
Published: 2014-11-20
Directory traversal vulnerability in Pivitol Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVE-2014-8387
Published: 2014-11-20
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

CVE-2014-8493
Published: 2014-11-20
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.

CVE-2014-8767
Published: 2014-11-20
Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of service (crash) via a crafted length value in an OLSR frame.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?