Monday April 29, 2013
CUPERTINO, CA – April 25, 2013 – TaaSera, Inc., an information security technology company focused on advanced malware behavior detection, today announced significant new functionality for AWARE NetAnalyzer™, a real-time malware behavior detection solution that allows enterprises to identify attacks before they result in a breach. Based on run-time malware behavior analysis, rather than signatures or sandboxes, the new version features tight integration with TaaSera’s new Attacker Intelligence Feed. Integrated together the updated AWARE NetAnalyzer monitors external communications with malicious sites for faster, real-time malware detection, and seamless integration with the HP ArcSight security information and event management (SIEM) tool for improved reporting and analysis.
In addition, TaaSera released a new Malware Behavior Model which combines endpoint malware behavior with network behavior research from SRI International (formerly Stanford Research Institute). TaaSera’s “Advanced Infection Lifecycle Model” creates a comprehensive 12-stage behavior model that ALL malware exhibit prior to breach or theft of confidential data, personal information or other intellectual property. AWARE NetAnalyzer detects these network behaviors, including egg downloads, peer-to-peer infections, command-and-control (C&C) coordination and other malicious activities in live enterprise networks.
TaaSera Attacker Threat Feed Integration
The AWARE NetAnalyzer software tool provides integration with the AWARE Attacker Intelligence Feed, a rich database of IP and URL addresses that provides contextual intelligence about the nature of an attack (malware propagator, botnet C&C, etc.), as well as the specific industry sector being targeted (financial, government, etc.). The Attacker Intelligence Feed offers over 200,000 daily IPs focused solely on malware and specific malicious sites that TaaSera has identified as actively propagating malware. Enterprises can license the AWARE Attacker Intelligence Feed for multiple purposes, for example:
• To embed in existing security tools for monitoring or blocking connections to malicious sites.
• For enterprises to monitor their own IPs or ASN Range, or those of their partners/supply chain.
• For enterprises or analysts who want to conduct their own historical analysis on threats from a particular region, or volume of threats attacking a particular industry sector via the AWARE Attacker Threat Intelligence Portal.
“Integrating our Attacker Intelligence Feed with NetAnalyzer marries global threats with localized network sensor information giving an enterprise a complete view of malware targeting their industry sector or organization,” said Scott Hartz, CEO TaaSera. “Combining an outside-in view from our Attacker Intelligence Feed with our inside-out view with NetAnalyzer allows us to identify threats early, reducing the window of exposure. We are also reaching out to companies we find in our Attacker Intelligence Feed because they have machines that are attempting to infect other companies. I believe we all have an obligation to quickly address malware in our enterprises, not only because it is the largest single type of cyberattack resulting in a security breach, but it negatively affects our global cyberthreat level.”
Today, the AWARE Attacker Intelligence Service identifies more than 10,000 new sites daily, and contains more than 200,000 malware IP addresses, which quantifies the enormity of the malware problem enterprises now face. In recent months, the Attacker Intelligence Feed has detected an increase in Botnet Command and Control operating from Amsterdam, with a high correlation to sites associated with the Russian Business Network, a large criminal enterprise that uses malware to steal enterprise information or launch attacks on others.
HP ArcSight SIEM Integration
AWARE NetAnalyzer detects diverse network transactions to predict the order and time it takes to elude conventional network defenses. Users can choose to export alerts to SIEM platforms like HP ArcSight using the Common Event Format. Additionally, by identifying multi-vector communication sequences that occur during an infection process, AWARE NetAnalyzer generates alerts and infection warnings that are visible to security and risk administrators via a graphical user interface (GUI) for reporting and detailed analysis.
“In a very short period of time, our technologists and researchers are building one of the most powerful advanced malware behavior detection tools on the market. By integrating our Attacker Intelligence Service, expanding our malware behavior detection model, and offering third-party connectivity to HP ArcSight, AWARE NetAnalyzer is engineered to stay ahead of advanced and zero-day attacks,” said Srinivas Kumar, CTO of TaaSera.
Introducing TaaSERA’s Advanced Malware Behavior Detection Model
After several years of research, SRI International, with funding from the U.S. Army Research Office, developed a patent-pending technology for identifying malware based on an eight-stage lifecycle of behavioral activity: Infection Preparation, Egg Download, Peer Infection, Command & Control Communications, System Scanning, Attack Preparation, Malicious Outbound Scan, and Data Exfiltration. TaaSera’s AWARE NetAnalyzer uses the Advanced Infection Model to find previously unknown threats.
As malware behavior continues to evolve, TaaSera researchers extended the 8 stages to 12 by adding localized malware behaviors only detectable on endpoints, such as local reconnaissance-collecting keystrokes, password or confidential data, or malware that didn’t enter via the corporate network, such as thumb drives and unauthorized personal devices. Security and risk management teams need more than perimeter security; they need continuous monitoring with and between internal endpoints, servers, network devices, virtual machines, software defined networks, and mobile or cloud infrastructure to truly defend against today’s advanced attacks.
See all 12 stages of the Advanced Malware Behavior Detection Model.
AWARE NetAnalyzer is available today. If you are interested in evaluating the latest version of NetAnalyzer in your environment, contact TaaSera on the web, or call 855-TAASERA x702.