2007.02.07

Sandbox Online Analyzer

Norman Online Analyzer is a web-based analysis service which allows the customer to upload suspicious executable files to Norman’s dedicated servers and then quickly supplies a comprehensive analysis of the file action. Reports, logs, and other outputs can immediately be viewed online or emailed to the user.  This new online tool offers the same powerful options and outputs as Norman SandBox Analyzer.

This more affordable version of Norman SandBox Analyzer is  made available to customers who have more limited needs but still require powerful forensic tools to stop malware instantly.
The service is targeted to customers who do not require the unlimited analysis capabilities of the Analyzer, are frequently away from designated malware analysis lab locations, or do not have a dedicated virus analysis lab and wish to let Norman supply the processing power.

At the core of SandBox Analyzer is Norman’s SandBox Technology - a fully simulated computer and network within the application. Any file loaded into this simulated environment is deceived into behaving normally (e.g., infecting and deleting files, sending e-mails, setting up listening ports, copying itself over networks or connecting to an IRC server). As the file does this, each action is being recorded. Unlike other virtual environments, all simulation is securely contained within the emulator. No code is ever executed on the real CPU, and no other real system hardware components are accessed.

More details in the product information.