Static analysis consists of individually configured analysis components. Within an MVX cluster, Intelligent Virtual Execution - Server appliances that function as compute nodes perform static analysis on the malware samples submitted by the Network Security sensors enrolled in the cluster. For information about malware submission, see the Distributed Network Security Cloud MVX Guide.
Static analysis results are returned to the Network Security sensors that submitted the samples. You can view analysis results for a single sensor or for all sensors at the Alerts > Alerts page of the sensor Web UI (or the Alerts > Web MPS > Alerts page of the Central Management System Web UI, if the sensor is under Central Management System management).
The components of static analysis are enabled by default. You can disable and re-enable individual components by using CLI commands only.
AV-Suite Integration—A DTI cloud solution that provides intelligent analysis of complete, incomplete, or corrupted files.
AV-Check—The use of integrated antivirus tools, such as ClamWin and signer checking, to scan submitted malware samples. If the AV_ENGINE_SOPHOS license is installed on the Intelligent Virtual Execution - Server appliance, the integrated Sophos AV engine is also used.
Python-Based Static Analysis—A Python-based analysis engine that uses a combination of generic and file type-specific YARA rules and other file type-specific analysis techniques.
Dropper Detection—Uses a list of MD5 checksums to detect dropper files.
Malware Intrinsic Analysis—Objects that match known malware families are marked as malicious.
If the static analysis feature is enabled, all of the enabled components of static analysis components are applied to the submitted traffic. Conversely, if the static analysis feature is disabled, none of the static analysis components—even analysis components that are enabled—are applied to submitted traffic.
Note
Because the VX Series appliance performs static analysis on submitted malware samples, the output fields for each static analysis tool are not displayed for the
show static-analysis configcommand on the sensor.
The static analysis feature is enabled by default. You can disable or re-enable the feature using CLI commands only.