McAfee Will Add Malware Sandboxing to Its Securityware

Published: Feb 28, 2013
Updated: Feb 2, 2021
2 minute read
McAfee Will Add Malware Sandboxing to Its Securityware
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

SAN FRANCISCO — Intel’s McAfee security subsidiary has acquired advanced functionality designed to identify sophisticated, hard-to-detect malware than eludes most conventional securityware.

The company said Feb. 26 at the RSA Security Conference that it has acquired the ValidEdge “sandboxing” technology from LynuxWorks to augment its anti-malware portfolio.

This approach identifies a suspected intruder, isolates suspected malware from the rest of the device operating system, runs it in the protected sandbox, and then deletes, quarantines or holds it for further action by the user.

“Regardless of whether a file is going through the IPS, Web gateway, email gateway—it doesn’t matter —we analyze the file in three ways,” Pat Calhoun, McAfee’s senior vice president of network security, told eWEEK. “First, we do a standard AV [antivirus] check, then we figure out the reputation of that file [matching it against a database with 110 million other file types in the McAfee database], and we look at the machine code to see if it’s doing anything suspicious. We do that today.

“What we just acquired [ValidEdge] allows us to take the file, re-create the endpoints [devices] in a virtual machine that talks to our EPO [ePolicy Orchestrator], which knows the configuration of every endpoint. Malware takes advantages of vulnerabilities in a specific operating system, a version, a patch level, whatever. We know the precise configuration of the endpoint, we re-create them in a VM, we run the file and we see if it does anything malicious.”

Calhoun said that unlike other sandboxing solutions, this one—when integrated with McAfee’s other network and endpoint anti-malware products—will automatically block future attacks by convicted malware samples. It also will provide signature information so that already infected endpoints can be remediated automatically by ePolicy Orchestrator.

McAfee plans to deliver the first product that integrates the sandboxing functionality in the second half of 2013.

Chris Preimesberger

Chris J. Preimesberger is Editor Emeritus of eWEEK. In his 16 years and more than 5,000 articles at eWEEK, he distinguished himself in reporting and analysis of the business use of new-gen IT in a variety of sectors, including cloud computing, data center systems, storage, edge systems, security and others. In February 2017 and September 2018, Chris was named among the 250 most influential business journalists in the world (https://richtopia.com/inspirational-people/top-250-business-journalists/) by Richtopia, a UK research firm that used analytics to compile the ranking. He has won several national and regional awards for his work, including a 2011 Folio Award for a profile (https://www.eweek.com/cloud/marc-benioff-trend-seer-and-business-socialist/) of Salesforce founder/CEO Marc Benioff--the only time he has entered the competition. Previously, Chris was a founding editor of both IT Manager's Journal and DevX.com and was managing editor of Software Development magazine. He has been a stringer for the Associated Press since 1983 and resides in Silicon Valley.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。