Storage News
Security News
Networking News 
FREE NEWSLETTERS
search
 

internet.commerce
Partner With Us
Computer Hardware
Shop Online
Boat Donations
Computer Deals
Phone Cards
KVM Switch over IP
Shop
Car Donations
Calling Cards
Compare Prices
Promotional Gifts
Baby Photo Contest
Find Software
KVM over IP

internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers




Storage Networking , Part 1
eBook: A storage network is any network that's designed to transport block-level storage protocols. But understanding the ins and outs of networked storage takes you deep into several of protocols. This guide covers SANs, Fibre Channels, Disk Arrays, Fabric, and IP Storage. »

Storage Networking 2, Configuration and Planning
eBook: Picking up where Part 1 left off, Part 2 of our look at storage networking examines configurations for SAN-attached servers and disk arrays, and also includes a look at the future of IP storage. »

Storage Management Costs in the Enterprise: A Comparison of Mid-Range Array Solutions
Whitepaper: Many factors contribute to the ownership cost for enterprise storage. These include (but are not limited to): physical capacity relative to physical space requirements, performance capacity for data transfer and system reaction time, software maintenance and updates, expandability and flexibility, and much more. »

Storage Is Changing Fast  Be Ready or Be Left Behind
PDF: The storage landscape is headed for dramatic change, thanks to new technologies like Fibre Channel over Ethernet (FCoE), pNFS, object-based storage and SAS that will affect everything from NAS and SANs to disk drives. Get the knowledge you need to make the most of your storage environment, now and in the future. »

HP StorageWorks EVA4400
Demo: Dont settle for an expensive and complex array that lacks functionality. The HP StorageWorks EVA4400 delivers virtual storage with enterprise class functionality at an affordable price. »

Latest Headlines
Security News
Microsoft Patch Tuesday: May 2008
A 'SaaSy' Approach to Wireless Security
Interop: The Problem With NAC
Whitepaper: Managing Your Data Protection Infrastructure with the HP All-in-One Storage System and Data Protector Express Software. Click here to open this PDF.

Security

Anti-spam | Anti-virus | Biometrics | Encryption | Filtering/Monitoring | Firewalls | Identity | Intrusion Detection/Prevention | Privacy | Security Administration Tools | Tools
Submit Products *

SandBox

Malware Analysis Via Simulation

The SandBox line of products from Norman provide the ability to analyze the actual action of potential malware files by executing them in an isolated, simulated environment. The SandBox applications are targeted to security administrators and/or professionals who need to analyze the actual results of potential malware.

At the core of the products is the vendor's SandBox technology itself, which is able to simulate both the hardware and software environment of the host machine without actually directly using the host gear. Instead, the software creates its own isolated "SandBox" environment, within which to execute the applications, noting actions taken by the application including files removed, added, or altered; network communications; or registry changes. The vendor notes that this environment contains full simulation capabilities, including the ability to emulate the bootstrap process of the PC, using ROM BIOS capacities and loading the operating system files and command shell from a simulated drive (which contains directories and files that are necessary for the system operation).

In addition to typical file or registry changes that may be attempted by the target application, other actions--such as network communications (HTTP, FTP, SMTP, DNS, IRC, and P2P)--are also monitored. Throughout the process, the vendor emphasizes that the real hardware of the host machine is not actually used; i.e., none of the target application's code is actually executed on the host machine's CPU.

When completed, the product can provide a summary report of actions taken by the application; a full API log of kernel interactions; and an extraction of all files created by the target application on the simulated drive.

Four applications are offered in the Norman SandBox suite:

- SandBox Analyzer, with capabilities as described above. SandBox Analyzer can be used from the command line or through a user interface.

- SandBox Analyzer Pro, with extended capabilities including the ability to view loaded libraries, running threads, and created sockets; debugging-like tools including the ability to set breakpoints and enter commands; and various additional views including a disassembly view, register view, memory dump, API log view, command input view, and more.

- SandBox Reporter, which provides daily reports from the information collected at the vendor's Norman SandBox Information Center, an online service that allows users to submit individual, potentially malicious files for analysis and receive (via E-mail) a report of the file's potential actions based on the vendor's SandBox technology. The SandBox Reporter report includes a list of URLs that might contain malicious code; a list of IRC network servers that malware tries to connect to; and a SandBox summary of most of the files analyzed within the reporting period. The list is provided in both text and XML formats.

- SandBox Online Analyzer, an online service that allows users to upload potential malware files and see the results of the SandBox analysis (performed by the vendor's servers) via a Web-based interface. Also available through the Web interface is access to previous analyses and statistics.

New features in the SandBox product line include support for the analysis of compressed malware (including Themida and Slovak Protectors), and support for the detection of malware that uses rootkit technology.

Visit the vendor's Web site for further information.

product submission by EITPlanet Staff

E-Mail this page to a colleague
send info about SandBox

Suggest a link
for the SandBox fact sheet

fact sheet
DPW id#: 1180553113
date posted: Mar. 18, 2008
category: Security:Security Administration Tools
platform: Windows 2000/XP/2003
vendor: Norman Data Defense Systems
(www.norman.com/)
vendor's information:
about SandBox
about Norman Data Defense Systems


Security

Anti-spam | Anti-virus | Biometrics | Encryption | Filtering/Monitoring | Firewalls | Identity | Intrusion Detection/Prevention | Privacy | Security Administration Tools | Tools
Submit Products *

Latest category updates via our RSS feed
RSS




Jupiter Online Media: internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and Jupiter Online Media

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Web Hosting | Newsletters | Tech Jobs | Shopping | E-mail Offers