Risk
2/16/2012
01:36 PM
Connect Directly
RSS
E-Mail
50%
50%

CIA Hunts For Malware In Binary Code

Agency invests in ReversingLabs, whose TitaniumCore software analyzes code at its most basic level to identify anomalies that might be malware.

Slideshow: Who's Who In U.S. Intelligence
Slideshow: Who's Who In U.S. Intelligence
(click for larger image and for full slideshow)
The CIA is investing in security technology that analyzes application code at the binary level to help identify anomalies that might indicate the presence of malware.

In-Q-Tel (IQT), a CIA-based nonprofit that identifies emerging technologies to support the U.S. intelligence community, has struck a strategic partnership with ReversingLabs, which offers technology for the rapid analysis of unknown binary content, according to IQT.

Specifically, ReversingLabs' TitaniumCore platform decomposes code and attempts to analyze every file in a system, kicking out anything that it doesn't recognize as being legitimate code so those bits can then be analyzed for malware.

Although binary analysis tools like the company offers are widely used to find any strange code coming into the enterprise, most look for malware by identifying code that's recognized to be bad. TitaniumCore's analysis of all of the code in an enterprise sets it apart from these tools.

[ Hackers have embarrassed the CIA. See LulzSec Claims Credit For CIA Site Takedown. ]

The data resulting from the analysis can be mapped against ReversingLabs' database of artifacts on more than 100 TB of goodware and 30 terabytes of malware files, according to IQT. This allows security pros to analyze unknown threats even with a large volume of code samples.

IQT will develop ReversingLabs' technology for the Department of Homeland Security Science and Technology Directorate, which is one of IQT's customer agencies.

In return, the company's technology--which has broad appeal for enterprise customers outside of the intelligence community as well--will get more visibility with its potential market, said Mario Vuksan, company CEO, in a press statement.

"Our partnership with IQT will create new opportunities for leveraging ReversingLabs' versatile and multifunctional binary analysis and scalable cloud-based technologies into related applications," he said.

The CIA launched In-Q-Tel in 1999 as an independent entity to find useful new technologies to support the intelligence community's mission.

Security technologies have been a particular area of investment over the past year, with In-Q-Tel striking deals with companies that offer continuous monitoring of security infrastructure; secure virtualization technology; and technology that protects PCs from visual eavesdroppers.

How 10 federal agencies are tapping the power of cloud computing--without compromising security. Also in the new, all-digital InformationWeek Government supplement: To judge the success of the OMB's IT reform efforts, we need concrete numbers on cost savings and returns. Download our Cloud In Action issue of InformationWeek Government now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0485
Published: 2014-09-02
S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.

CVE-2014-3861
Published: 2014-09-02
Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted reference element within a nonXMLBody element.

CVE-2014-3862
Published: 2014-09-02
CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.

CVE-2014-5076
Published: 2014-09-02
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.

CVE-2014-5136
Published: 2014-09-02
Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.