Z Archive: Product – MalWeb

MalWeb: A System to Harness Intelligence from Malware

[cols]
[col class=”1/1 last”]

Cythereal’s MalWeb is a cloud-based, automated malware analysis platform that, using advances made in the DARPA Cybergenome program, discovers deep and hidden connections between malware to construct a malware web. The web of malware it extracts may be used for detecting targeted attacks before they succeed, reconstructing attacks for incidence response, and connecting actors for forensic investigation.
[/col]
[/cols]

[cols]
[col class=”1/3″]

Anti-malware systems are optimized to identify malware whose traits are known to the AV company. The point data information about a specific malware they provide is not rich enough to draw connections between malware, and thus has little actionable intelligence.

[/col]
[col class=”2/3 last”]

AV technologies provide only information for individual malware, not their interconnections.

Anti-malware technologies provide point information for individual malware. They do not discover their interconnections and hence have limited value for intelligence. MalWeb fills this gap. It uses malware DNA, derived from malware code, to discover the missing links.

[/col]
[/cols]

[cols]
[col class=”2/3″]

Figure 1. Interesting malware clusters discovered by <span class=

[/col]
[col class=”1/3 last”]

MalWeb connects cyberattacks separated by time and space to provide network defenders:

  • Situational awareness of the threat environment.
  • Early warning of a targeted attack in progress.
  • Ability to reconstruct an attack upon a breach.

To ensure confidentiality of an organization’s data, MalWeb may be deployed within an organization’s data center. Its RESTful API makes it easy to integrate it in an organization’s workflow and and customize it.

[/col]
[/cols]

[cols]
[col class=”1/3″]

MalWeb installations may be interlinked to create cybersecurity information sharing networks. Such a network may be company specific, industry-wide, geographically limited, or public.

Cythereal is establishing a MalWeb Hub for global intelligence. This hub will receive daily malware feed from a variety of sources around the world and distribute situational awareness reports on the global threat environment.

[/col]
[col class=”2/3 last”]

Cybersecurity Information Sharing network using Cythereal's MalWeb.

Cybersecurity Information Sharing network using Cythereal’s MalWeb.

[/col]
[/cols]

[cols]
[col class=”1/1 last”]

Cyber-attackers have for long enjoyed an asymmetric advantage by weaving a web of deception. MalWeb levels the playing field by using their web to help the defenders.
[/col]
[/cols]