Malware Intrinsic Analysis

Prev Next

The Intelligent Virtual Execution - Server appliance can identify malware based on intrinsic properties in known compromised systems. This feature, called malware intrinsic analysis, compares submitted traffic samples against known malware families. Objects that match are marked as malicious. Intrinsic analysis results are returned to the originating sensor, where the information can be viewed at the Alerts > Alerts page of the Network Security Web UI (or the Alerts > Web MPS > Alerts page of the Central Management System Web UI, if the sensor is under Central Management System management).

By default, the malware intrinsic analysis is enabled, and the Intelligent Virtual Execution - Server appliance performs intrinsic analysis in the Dynamic Threat Intelligence (DTI) cloud. The list of known malware is updated when the system checks for new security content from the DTI cloud. A two-way sharing CONTENT_UPDATES license is required.

You can disable and re-enable the feature, and you can configure the compute node to perform intrinsic analysis locally instead of in the DTI cloud:

Note

Malware intrinsic analysis supports EXE and DLL files only.