<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7652481.post116161529741559178..comments</id><updated>2009-01-14T01:06:19.255-05:00</updated><category term='MySQL'/><category term='Tor'/><category term='NSM'/><category term='dns'/><category term='Snort'/><category term='book review'/><category term='Sguil'/><category term='apt'/><category term='hacking'/><category term='Perl'/><category term='Events'/><category term='WTF?'/><category term='OSSEC'/><category term='management'/><title type='text'>Comments on Infosec Potpourri: Comparing Automated Malware Analysis Services</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.vorant.com/feeds/116161529741559178/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html'/><author><name>David Bianco</name><uri>http://www.blogger.com/profile/09760835714791462863</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7652481.post-493499255669765116</id><published>2009-01-14T01:06:00.000-05:00</published><updated>2009-01-14T01:06:00.000-05:00</updated><title type='text'>A few more:&lt;br&gt;&lt;br&gt;http://camas.comodo.com/&lt;br&gt;htt...</title><content type='html'>A few more:&lt;BR/&gt;&lt;BR/&gt;http://camas.comodo.com/&lt;BR/&gt;http://anubis.iseclab.org/&lt;BR/&gt;http://www.joebox.org/&lt;BR/&gt;&lt;BR/&gt;And here you can get Web-based results for CWSandbox: http://www.cwsandbox.org/</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default/493499255669765116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default/493499255669765116'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html?showComment=1231913160000#c493499255669765116' title=''/><author><name>J</name><uri>http://www.blogger.com/profile/16520171809045089172</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html' ref='tag:blogger.com,1999:blog-7652481.post-116161529741559178' source='http://www.blogger.com/feeds/7652481/posts/default/116161529741559178' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-712385557'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-4408790629356943926</id><published>2007-04-03T19:38:00.000-04:00</published><updated>2007-04-03T19:38:00.000-04:00</updated><title type='text'>It's too bad I didn't see this post earlier! Thank...</title><content type='html'>It's too bad I didn't see this post earlier! Thank you for the kudos on our product. A couple clarifications on the post and comments:&lt;BR/&gt;- 'Sandbox' is a generic term, used by Norman, Sunbelt and others to describe the process of 'sandboxing' an app, malware or otherwise. Our product is hence, CWSandbox.&lt;BR/&gt;- The Sunbelt CWSandbox is based on Carsten Willems' CWSandbox project and we collaborate closely with his team.&lt;BR/&gt;- With respect to the reporting, that's more or less correct, the publicly accessible version isn't always in sync with the latest, nor is all the detailed exposed in the HTML report.&lt;BR/&gt;- Chad, Sunbelt-Software.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default/4408790629356943926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default/4408790629356943926'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html?showComment=1175643480000#c4408790629356943926' title=''/><author><name>Chadl</name><uri>http://www.blogger.com/profile/08696910278934284318</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html' ref='tag:blogger.com,1999:blog-7652481.post-116161529741559178' source='http://www.blogger.com/feeds/7652481/posts/default/116161529741559178' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1308243667'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-116319744716578179</id><published>2006-11-10T17:24:00.000-05:00</published><updated>2006-11-10T17:24:00.000-05:00</updated><title type='text'>David,&lt;br&gt;&lt;br&gt;I did some research on the companies...</title><content type='html'>David,&lt;BR/&gt;&lt;BR/&gt;I did some research on the companies mentioned in this posting and I came across a couple of news announcements that sounded confusingly similar. Perhaps you could shed some light here. One was from Sunbelt Software titled: Sunbelt Software Introduces Automated Sandbox Technology to Enable Rapid, Safe and Accurate Analysis of Malware (see: http://www.sunbelt-software.com/Press.cfm?id=164)&lt;BR/&gt;&lt;BR/&gt;The other one was from Norman titled: Norman's Sandbox Analysis Tools Enable UK Organizations To Deal with Unknown Malware and Targeted Security Threats (see: http://sourcewire.com/releases/rel_display.php?relid=27810&amp;hilite=)&lt;BR/&gt;&lt;BR/&gt;The content of the press releases  is eerily similar (is one ripping off the other?). One thing that did interest me was the following statement by Norman's CEO, Trygve Aasland in the Norman press release: &lt;BR/&gt;&lt;BR/&gt;“The corporate information security market is seeing a shift away from mass attacks towards numerous individual, sophisticated attacks – often mounted by criminal gangs - that as a result pass “under the radar” of heuristic and signature-based technologies. Our new SandBox tools will help organizations take action against specific attacks by allowing the nature of the threat launched against them to be understood.”&lt;BR/&gt;&lt;BR/&gt;“In particular, users urgently require analytical technologies which detect and categorize sophisticated targeted attacks, based on new forms of malicious code which are only detectable by their abnormal behavior. Used alongside other techniques in a multi-level security hierarchy, SandBox tools empower organizations to defend against targeted attacks and organized online criminal activity.”&lt;BR/&gt;&lt;BR/&gt;Do you think Sunbelt and Norman are on to something unique here? Is this a better approach to dealing with malware threats?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default/116319744716578179'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default/116319744716578179'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html?showComment=1163197440000#c116319744716578179' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html' ref='tag:blogger.com,1999:blog-7652481.post-116161529741559178' source='http://www.blogger.com/feeds/7652481/posts/default/116161529741559178' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1048478214'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-116178032847065812</id><published>2006-10-25T08:45:00.000-04:00</published><updated>2006-10-25T08:45:00.000-04:00</updated><title type='text'>Well, they do list Symantec on the page you mentio...</title><content type='html'>Well, they do list Symantec on the page you mentioned, but it's not included on the report itself, so I can't say that they're supporting it at all.  I've heard from at least one other person that Symantec was showing up on reports at least a few weeks ago, so perhaps this is just a temporary thing.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default/116178032847065812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default/116178032847065812'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html?showComment=1161780300000#c116178032847065812' title=''/><author><name>David Bianco</name><uri>http://www.blogger.com/profile/09760835714791462863</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html' ref='tag:blogger.com,1999:blog-7652481.post-116161529741559178' source='http://www.blogger.com/feeds/7652481/posts/default/116161529741559178' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2136160136'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-116171183796222634</id><published>2006-10-24T13:43:00.000-04:00</published><updated>2006-10-24T13:43:00.000-04:00</updated><title type='text'>VirusTotal *does* support Symantec.&lt;br&gt;&lt;br&gt;http://...</title><content type='html'>VirusTotal *does* support Symantec.&lt;BR/&gt;&lt;BR/&gt;http://www.virustotal.com/en/virustotalf.html&lt;BR/&gt;&lt;BR/&gt;The missing heavyweight is Trend Micro. The VirusTotal folks say that they approached Trend Micro but Trend Micro refused to participate.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default/116171183796222634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/116161529741559178/comments/default/116171183796222634'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html?showComment=1161711780000#c116171183796222634' title=''/><author><name>snaikes</name><uri>http://www.blogger.com/profile/00291704397039941407</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2006/10/comparing-automated-malware-analysis.html' ref='tag:blogger.com,1999:blog-7652481.post-116161529741559178' source='http://www.blogger.com/feeds/7652481/posts/default/116161529741559178' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-982882918'/></entry></feed>
