About the Malware Analysis appliance

Prev Next

The Malware Analysis appliance provides security analysts a secure environment to test, replay, characterize, and document advanced malicious activities. After one or more suspicious files such as PDF documents, and Web objects requested by a URL) are loaded into the Malware Analysis appliance, the analysis engine analyzes the files. The Malware Analysis appliance reports a full view of the attack, from the initial exploit and malware execution path to the callback destinations and follow-on binary download attempts.

Malware Analysis modes

The Malware Analysis appliance can be deployed in the following modes:

  • Live Mode—The live mode is an open analysis environment in which the appliance is connected with the outside world for tracking callbacks and analyzing malicious URLs. The appliance can accept binaries, PDFs, Microsoft Office documents, malicious URLs with embedded scripts, and other objects for analysis. The malware infects the virtual machine and has access to the Internet so it can call home and engage in malicious activities that may not be possible in sandbox mode.

  • Sandbox Mode—The sandbox mode is a closed environment in which malware is submitted and its effects on virtual machines are analyzed and reported. In sandbox mode, security analysts can witness the behavior of any supported object they wish to analyze.

In an integrated Central Management System environment, the Central Management System appliance shares the results of the Malware Analysis malware analysis with the Network Security, Email Security — Server, and File Protect appliances for real-time protection against emerging attacks.

Note

For information about configuring and performing live and sandbox malware analysis, see the Hardware Administration Guide for your appliance model and the Malware Analysis User Guide.