Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity
    • Networking

    NetWitness Spectrum Appliance Automates Malware Detection and Analysis

    Written by

    Fahmida Y. Rashid
    Published January 25, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      NetWitness announced on Jan. 24 a malware analysis appliance that works with the company’s network monitoring platform.

      The appliance automates malware analysis so that IT managers get real-time monitoring, immediate feedback on threats in the network and prioritization on which issues to address, Eddie Schwartz, NetWitness chief security officer, told eWEEK. Malware can be difficult to find and require “elite skills” the organization might not have, he said. Spectrum provides security managers with a prioritized list of “invisible” threats without the security managers having to look for them, according to Schwartz.

      Spectrum tells the managers which threats they should address first or what the potential risks are if a specific vulnerability is not quickly resolved, he said. The information also provide links to full details about the appliance’s performance including logs and scanning session information, he said.

      “With a detailed record of everything that has happened on the network, the analytic possibilities are vast,” said Joshua Corman, Research Director of Enterprise Security at The 451 Group.

      The appliance is installed right at the Internet gateway so that it can examine all traffic as it enters and exits the network, said Schwartz. It examines each inbound and outbound byte in real-time, as well as looks for signs of emerging “zero day” malware, hidden executables, or unknown processes, said Schwartz. It also analyzes outbound traffic to determine whether there may be any botnet activity from zombies within the network, according to NetWitness.

      The appliance promises “100 percent protocol coverage,” including Samba/CIFS, said Schwartz. The network analysis includes looking at the country where the network session originated, time of day, referrer sites, JavaScript, PDF executables, and the size of the content, as well as static scanning to determine if a file contains malicious code or has been obfuscated, he said.

      Spectrum doesn’t block suspicious malware on its way into the network, said Schwartz. The malware has to “pass by” the appliance for it to examine it, before the appliance can determine that it’s bad, he said, so there is no blocking mechanism in place. Instead, the appliance immediately issues a warning to the security manager about the suspicious traffic and “leaves it to the discretion of the security team” to do damage assessment, said Schwartz.

      In fact, not all prevention is putting a block on the traffic, but rather, stopping user behavior, said Schwartz.

      “This type of analysis also helps assess the attacker’s intent and the potential damage that may have occurred,” according to Rob McMillan of Gartner. It also allows managers to predict similar attacks and indentify other potential targets so they can use the predictions to make business decisions, he said.

      The appliance does not depend on signatures or known “bad” actions to identify malware, said Schwartz. Spectrum knows what is “good” behavior, and looks for any deviations across all ports and protocols to flag suspicious activity. Over half of the data breaches are the result of customized malware that had unknown signatures at the time of the exploit, the company said. Relying on signatures can’t be effective because it ignores the rapid changes in malware, according to NetWitness.

      NetWitness Spectrum will be unveiled at the RSA Security Conference Feb. 14-18, the company said. The appliance will compete with Damballa’s similar malware analytics box.

      Spectrum works with the other components in the network monitoring platform from NetWitness, which includes Informer, which automates threat reporting and alerts, Investigator, which performs freeform analytics and finds real-time answers, and Visualize, a data visualization module.

      The appliance are priced at $50,000 and orders are being accepted, but general availability will start at the time the RSA conference opens and the appliances will ship thereafter, Schwartz said. Netwitness doesn’t segment the appliance or pricing on the number of users or bandwidth. “We don’t pull those tricks,” said Schwartz.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×