Technology Sectors

Market Sectors

Netwitness Spectrum tops anti-malware list

Netwitness Spectrum

RSA Netwitness Spectrum software, which allows operators to scan almost every corner of their electronic networks for paralyzing malicious code, took the “Best Anti-Malware Solution” trophy home from the 2011 GSN homeland security awards.

Nearly 100,000 new malware samples are found daily, said the company in nominating its product. Criminals and nation-state elements quickly adapt to security solutions, rendering signature-dependent malware defenses obsolete, it said. New approaches, said the company, that look exclusively for “bad,” based on certain predictable behavioral patterns, can also be defeated. The company’s Spectrum product changes the game by allowing organizations to automatically analyze every executable on their network to determine its maliciousness.

The software, it said, uses multidiscipline methodology to look for deviations from a known good state without signatures and prioritizes the results, so security analysts can focus their remediation efforts. Competing technologies only provide limited capabilities and visibility into modern malware because they rely on their own threat intelligence (blacklist “cloud” of signatures) or are dependent on one or two possible analytical methodologies such as sandboxing, it said. Sandboxing is suspect to environmentally VM-aware malware and temporal subterfuge, missing many potential advanced threats. There are numerous examples in which zero-day malware and APTs slip past technologies that rely heavily on proprietary cloud-based intelligence and a sandbox. Only Spectrum employs four distinct and concurrent analytic methodologies to deliver consolidated and prioritized malware analysis that blends diverse threat intelligence, deep packet inspection, multi-vendor sandboxing, and static analysis to ensure maximum visibility into advanced threats.

Spectrum alerts users to valid threats, false positives, or lower priority beacons and spam bots and perhaps most importantly, tells users where the threat made its entry, how it moved laterally, what systems were owned, what data was exfiltrated, and when. In contrast to current approaches, Spectrum is the only platform that analyzes everything;  fuses and triangulates information from multiple third-party intelligence/reputation services; delivers precise and multidimensional answers on the structure and behavior of suspect malware and provides the content and context of all network activity associated with suspect malware, said the company.

Once NetWitness records the data, it is reused for a variety of purposes, allowing economy of scale and efficiency of operations. This “big data” aggregation and data re-use model, and central analytics on an N-tier architecture differs from current models where security investments become obsolete, said the company.

NetWitness can act as a force multiplier by automating deep malware analysis that is typically a manually intensive process conducted by highly skilled individuals, said RSA. Spectrum delivers prioritized results with workflow that enables the security team to efficiently track and remediate the greatest areas of risk. Spectrum removes the guesswork and definitively answers whether or not malware is on the network.

The GSN homeland security awards were handed out during a festive celebratory dinner in Washington, DC, on Nov. 14. For a complete list of all categories and all winners, click here.

 

Upcoming Events

Event Details Dates of Event
Mission Command Jun 10 - 12
Cyber Securty Brainstorm Jun 11 - 11
EDGE Summit 2013 Jun 11 - 11
IPv6 Summit 2013 Jun 14 - 16
SANSFIRE 2013 Jun 15 - 22
Oak Ridge National Laboratory's 2nd Biosurveillance Symposium Jun 17
Biodetection Technologies 2013 Jun 18 - 19
Southwest Microwave Seminar Jun 18 - 18
Cyber Defense and Network Security Summit Jun 24 - 26
Vanguard Security & Compliance 2013 Jun 24 - 27
SANS Canberra 2013 Jul 1 - 13
Border Management & Technologies Summit Jul 2 - 5
SANS Rocky Mountain 2013 Jul 15 - 20
SANS Mumbai 2013 Jul 22 - 27
Cyber Security Brainstorm Jul 24 - 24
SANS San Francisco 2013 Jul 29 - Aug 3
SANS Boston 2013 Aug 5 - 10
Cyber Security for Government Aug 12 - 14
SANS Thailand 2013 Aug 19 - 31
SANS Virginia Beach 2013 Aug 19 - 30
Maritime Security 2013 West Aug 19 - 21
930gov: Strategic Buying at Year-End Showcase Aug 21 - 21
SANS Melbourne 2013 Sep 2 - 7
SANS Capital City 2013 Sep 3 - 8
US/Canada Border Conference Sep 12 - 13
Network Security 2013 Sep 14 - 23
Cyber Intelligence Europe Sep 17 - 19
EnergySec 9th Annual Security Summit Sep 17 - 19
iFSO International Facility Security Officer Conference Sep 17 - 19
International Facility Security Officer Conference Sep 17 - 19
DefendUSA Sep 19 - 20
ASIS Foundation Golf Tournament Sep 23 - 23
NCT: CBRNe Asia, 24-27 September 2013, Kuala Lumpur Sep 24 - 27
ASIS Foundation Night at ASIS 2013 Sep 26 - 26
SANS Bangalore 2013 Oct 14 - 26
SOS SANS October Singapore 2013 Oct 21 - Nov 2