Security firm 'detonates' copies of suspicious files to sniff out malware, botnet attacks
Network World - HBGary on Monday introduced an appliance that sits at the perimeter of the enterprise network to watch for possible incoming malware and outgoing traces of botnet infections.
Called Razor, the appliance uses a "virtual-machine system" that takes all files and copies them to inspect for malware by "detonating" the file copies in a sandbox to examine whether any document contains malicious content, according to HBGary CEO Greg Hoglund. It also watches for malicious command-and-control activity, and can automatically block further traffic associated with a malicious site.
PRODUCT NEWS: Appliance automates malware detection
Hoglund says the Razor appliance uses the same Digital DNA and Active Defense technology found in HBGary's end-node products. In deploying Razor at the perimeter, the idea is that if malware is detected in transit, an alert would be sent to the enterprise security information management point, with the goal of examining the machine where it's headed. The method does not rely on "static signature-based security," says Hoglund, adding customers feel this is no longer enough.
Interest in non-signature-based protection methods is on the rise. Razor is intended to compete with the detection approaches used by FireEye and Damballa, which do not rely on malware signatures. The announcement of HBGary's Razor comes on the heels of yet another new product to compete in this arena, the Spectrum appliance announced by NetWitness earlier this month.
Razor, which starts at $23,500, is now in beta and expected to ship in the February time frame.
Read more about wide area network in Network World's Wide Area Network section.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Securing Internet File Transfers This solution brief describes the four essential elements of secure Internet transfers.
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts