Damballa Failsafe 5.0 Now Performs Cloud-based Analysis of Zero-day and Targeted Malware as part of a Comprehensive Approach to Advanced Threat Protection
ATLANTA – November 15, 2011 – Damballa Inc., the company transforming the fight against cyber threats, today announced Damballa Failsafe 5.0, the most comprehensive, purpose-built solution for detecting and terminating hidden cyber threats in corporate networks. Damballa Failsafe hunts for undetected threats by correlating a variety of observed network behaviors that indicate malware-infected devices (PCs, Macs, servers, smartphones, iPads, etc.) are communicating with criminals. Damballa Failsafe 5.0 now includes automated malware analysis in its advanced threat detection capabilities. The new features inspect unknown, zero-day and targeted malware, identifying changes the malware makes to the targeted device and the malware's intended communication behaviors.
Hunting for Hidden Infections – Detecting the Undetectable
Today's persistent threats and network breaches are driven by modern malware infections that easily evade detection by traditional signature-based endpoint solutions. The malware-infected device then communicates with criminal operators using techniques that imitate a legitimate user to evade detection by traditional network security solutions designed to prevent obvious illegitimate traffic. Damballa Failsafe is the only solution specifically designed to automatically detect criminal network communication behavior, analyze zero-day and targeted malware, correlate the forensic evidence to pinpoint live infections, identify the nature of the threat and the criminal operator, and terminate the communication to stop data theft.
"Damballa Failsafe has never failed to detect unknown threats and hidden infections in corporate networks," said Stephen Newman, vice president of product management for Damballa. "Our ability to correlate multiple behavioral indicators to rapidly and accurately pinpoint hidden infections is unequaled in the market. We now offer real-time malware analysis as additional forensic evidence that contributes to the threat conviction scores for threats identified on infected devices."
"There are products available today that analyze 'malware in motion,' but they do so by analyzing the malware in a sandbox within the customer's network," added Newman. "There are obvious limitations inherent with running captured malware samples live within a targeted organization. Damballa Failsafe overcomes these limitations by performing the malware analysis in the cloud, outside of the targeted company's network."
The Power of Cloud-based Malware Analysis
The malware analysis feature in Damballa Failsafe 5.0 utilizes cloud-based dynamic malware analysis, which occurs at Damballa Labs in real-time. Customers can opt to automatically submit all suspicious files for analysis, or selectively submit files as desired. A cloud-based approach offers many advantages over in-network malware analysis technologies:
"Malware analysis and malware reverse engineering has been a staple of Damballa Labs since our inception in 2006," said Gunter Ollmann, vice president of research for Damballa. "It is fundamental to our research as we profile criminal command-and-control and for threat attribution to criminal operators. We are now applying this capability, in real-time, to our customer implementations of Damballa Failsafe. Malware analysis is now one more piece of evidence we automatically harvest and correlate to hunt for infected devices and detect zero-day or targeted attacks. It also provides our customers with additional insight into how infections occur when the device is within their corporate network, which can assist them with improving their security posture and improving user behavior."
The new malware analysis capability is included in Damballa Failsafe 5.0 at no additional fee and is a simple upgrade for existing customers. For a demonstration of Damballa Failsafe 5.0, visit http://www.damballa.com/solutions/demo_load.php.
About Damballa
Damballa is a pioneer in the fight against cybercrime. Damballa provides the only network security
solution that detects the remote control communication that criminals use to breach networks to steal
personal and intellectual information, and conduct espionage or other fraudulent transactions.
Patent-pending solutions from Damballa are platform and system-agnostic, protecting networks with
any type of device including PCs, Macs, smartphones, as well as mobile and embedded systems. Damballa
customers include Fortune 1000 companies, Internet and telecommunications service providers, government
agencies and educational organizations. Privately held, Damballa is headquartered in Atlanta.
http://www.damballa.com
Media Contacts:
Ann Conrad, 404-961-7402
Damballa Inc.
press@damballa.com
Bill Keeler/Tiffany Darmetko, 781-684-0770
Schwartz Communications
damballa@schwartzcomm.com