McAfee Will Add Malware Sandboxing to Its Securityware | eWeek

McAfee Will Add Malware Sandboxing to Its Securityware

McAfee Will Add Malware Sandboxing to Its Securityware
Feb 28, 2013
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

SAN FRANCISCO — Intel’s McAfee security subsidiary has acquired advanced functionality designed to identify sophisticated, hard-to-detect malware than eludes most conventional securityware.

The company said Feb. 26 at the RSA Security Conference that it has acquired the ValidEdge “sandboxing” technology from LynuxWorks to augment its anti-malware portfolio.

This approach identifies a suspected intruder, isolates suspected malware from the rest of the device operating system, runs it in the protected sandbox, and then deletes, quarantines or holds it for further action by the user.

“Regardless of whether a file is going through the IPS, Web gateway, email gateway—it doesn’t matter —we analyze the file in three ways,” Pat Calhoun, McAfee’s senior vice president of network security, told eWEEK. “First, we do a standard AV [antivirus] check, then we figure out the reputation of that file [matching it against a database with 110 million other file types in the McAfee database], and we look at the machine code to see if it’s doing anything suspicious. We do that today.

“What we just acquired [ValidEdge] allows us to take the file, re-create the endpoints [devices] in a virtual machine that talks to our EPO [ePolicy Orchestrator], which knows the configuration of every endpoint. Malware takes advantages of vulnerabilities in a specific operating system, a version, a patch level, whatever. We know the precise configuration of the endpoint, we re-create them in a VM, we run the file and we see if it does anything malicious.”

Calhoun said that unlike other sandboxing solutions, this one—when integrated with McAfee’s other network and endpoint anti-malware products—will automatically block future attacks by convicted malware samples. It also will provide signature information so that already infected endpoints can be remediated automatically by ePolicy Orchestrator.

McAfee plans to deliver the first product that integrates the sandboxing functionality in the second half of 2013.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.