Risk
2/16/2012
01:36 PM
Connect Directly
RSS
E-Mail
50%
50%

CIA Hunts For Malware In Binary Code

Agency invests in ReversingLabs, whose TitaniumCore software analyzes code at its most basic level to identify anomalies that might be malware.

Slideshow: Who's Who In U.S. Intelligence
Slideshow: Who's Who In U.S. Intelligence
(click for larger image and for full slideshow)
The CIA is investing in security technology that analyzes application code at the binary level to help identify anomalies that might indicate the presence of malware.

In-Q-Tel (IQT), a CIA-based nonprofit that identifies emerging technologies to support the U.S. intelligence community, has struck a strategic partnership with ReversingLabs, which offers technology for the rapid analysis of unknown binary content, according to IQT.

Specifically, ReversingLabs' TitaniumCore platform decomposes code and attempts to analyze every file in a system, kicking out anything that it doesn't recognize as being legitimate code so those bits can then be analyzed for malware.

Although binary analysis tools like the company offers are widely used to find any strange code coming into the enterprise, most look for malware by identifying code that's recognized to be bad. TitaniumCore's analysis of all of the code in an enterprise sets it apart from these tools.

[ Hackers have embarrassed the CIA. See LulzSec Claims Credit For CIA Site Takedown. ]

The data resulting from the analysis can be mapped against ReversingLabs' database of artifacts on more than 100 TB of goodware and 30 terabytes of malware files, according to IQT. This allows security pros to analyze unknown threats even with a large volume of code samples.

IQT will develop ReversingLabs' technology for the Department of Homeland Security Science and Technology Directorate, which is one of IQT's customer agencies.

In return, the company's technology--which has broad appeal for enterprise customers outside of the intelligence community as well--will get more visibility with its potential market, said Mario Vuksan, company CEO, in a press statement.

"Our partnership with IQT will create new opportunities for leveraging ReversingLabs' versatile and multifunctional binary analysis and scalable cloud-based technologies into related applications," he said.

The CIA launched In-Q-Tel in 1999 as an independent entity to find useful new technologies to support the intelligence community's mission.

Security technologies have been a particular area of investment over the past year, with In-Q-Tel striking deals with companies that offer continuous monitoring of security infrastructure; secure virtualization technology; and technology that protects PCs from visual eavesdroppers.

How 10 federal agencies are tapping the power of cloud computing--without compromising security. Also in the new, all-digital InformationWeek Government supplement: To judge the success of the OMB's IT reform efforts, we need concrete numbers on cost savings and returns. Download our Cloud In Action issue of InformationWeek Government now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4262
Published: 2014-07-28
svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The irkerbridge.py issue is covered by CVE-...

CVE-2013-4840
Published: 2014-07-28
Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW before 5.20.R3177 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2013-7393
Published: 2014-07-28
The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions...

CVE-2014-2974
Published: 2014-07-28
Cross-site request forgery (CSRF) vulnerability in php/user_account.php in Silver Peak VX through 6.2.4 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

CVE-2014-2975
Published: 2014-07-28
Cross-site scripting (XSS) vulnerability in php/user_account.php in Silver Peak VX before 6.2.4 allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.