Press release
Oslo, Norway, March 30 2007

Sandbox Online Analyzer

Norman ASA, the data security company, releases today Norman Online Analyzer, a new web based security analysis service for analysis of suspicious data programs and files.  The online service will be beneficial for organizations that needs quickly and cost-effectively analyze to reveal malware (virus, worms, trojans, bots, spyware etc.) and needs insight in the methods used by malware developers.

Norman Online Analyzer is a web-based analysis-, report-, and trend tool developed to provide information on data programs and data files’ intentions and activity pattern. The analysis gives a classification of the file (malware, Trojan, spyware etc.) and if the file already has a signature name. Further analysis provides information on changes to the file system and Windows registry, networking services attempting started, eventually program additions downloaded from the internet, affected system processes etc.

SandBox Statistics is a graphical statistics- and trend module with analysis of the attacking methods used, and the methods popularity over time. The data is based on Normans own malware database, where malware has been collected for over a decade.

SandBox Report is a powerful analysis report extracted from the large amount of data daily added to Normans databases, and provides information of suspicious web URL’s and IRC (Internet Relay Chat) activities. The report includes location information, port numbers, communication channels, call signs, passwords etc.

- We are proud to announce a web based service of the Norman SandBox Analyzer and providing access to our malware database. The online service will be beneficial for organizations that need a quick and cost-effective analysis to reveal and identify malware, says Audun Lødemel, VP Marketing & Business Development in Norman ASA. Organizations subscribing to this service will receive results from the comprehensive analysis in seconds, presented in a easily understood way, ready to be used to establish protective mechanisms into the IT infrastructure in a quick and cost-effective way. The Norman Online Analyzer is designed for customers who wants this service available through the web, and needs a mobile analysis laboratory with statistics, in depth analysis and reports. This is a tool to uncover the techniques used by hackers and other criminals are using, and to follow the development of these techniques over time.

At the core of SandBox Analyzer is Norman’s SandBox Technology - a fully simulated computer and network within the application. Any file loaded into this simulated environment is deceived into behaving normally (e.g., infecting and deleting files, sending e-mails, setting up listening ports, copying itself over networks or connecting to an IRC server). As the file does this, each action is being recorded. Unlike other virtual environments, all simulation is securely contained within the emulator.

- So far we have provided our popular free of charge web based analysis service, The SandBox Information Centre, used by a lot of users all around the world. The extension of this service with Norman Online Analyzer will introduce our customers to a new dimension in protecting their information systems. The new service will have a great impact on the methods used to explore the techniques used by malware developers over time, enabling a better understanding of the security threat. Norman has experienced a great interest in our Analyzer products launched last fall, and expect the Norman Online Analyzer to be a popular service. Payment for the service is established as a ticketing system, where every uploaded file counts one ticket, says Audun Lødemel.

Norman’s portfolio of analyzer products covers the SandBox Analyzer, SandBox Analyzer PRO, SandBox Online Analyzer and SandBox Reporter.

 


 

For information:

www.malwareanalyzer.com

- Audun Lødemel, VP Marketing, Norman ASA; Tel.: + 47 6710 97 79 Mobile: +47 93 44 65 31