Friday, April 4, 2025
HomeComputer Security5 Homeland Security Technologies That Might Be Commercialized

5 Homeland Security Technologies That Might Be Commercialized

Published on

SIEM as a Service

Follow Us on Google News

The federal government spends an upwards of $1 billion each year on unclassified cybersecurity research.  This fuel a part of Homeland Security technology research and results in the development of new software programs that helps thwart new age cyberthreats.

These are not top-secret research projects that are too sensitive to declassify. In fact, the government is looking for ways to introduce these technologies to the marketplace. In hopes that private companies would show interest in licensing these technologies and package them as commercial security products, the government had made a list of 8 security techs back in 2016 that they are willing to release to the public. Following are 5 of them that has a high likelihood of getting commercialized.

REnigma: Malware can potentially do a lot of damage and some of them can even shutdown entire networks in a matter of seconds. REnigma is a Homeland Security technology that creates a virtual system that allows the malware to run.

This virtual system can be used to test different malware to see how they operate and thus develop security solutions to mitigate their threats. The virtual environment created by REnigma tricks the malware into thinking that it’s attacking an actual system. Once the malware does its thing, researchers can replay how it affected the virtual system without putting their actual computers at harm.

Pre-REnigma era required arduous efforts to analyze malware as it required days of reverse engineering to understand the workings of these malicious software programs.

PcapDB: This is a software that stores packets of data in a network. Almost like an airplane cockpit black box, this data can later be analyzed after a cyberattack has occurred. PcapDB is almost like a logbook that helps investigators understand a particular cyber attack and possibly deduce its origins.

FLOWER: This is a technology that’s already being used by many government offices and it’s aimed at detecting coordinated cyber-attack signatures and prevent them. A small hardware is installed in the network that captures IP Packets. It keeps a 24X7 vigil against network breaches and signatures for insider attacks.

SilentAlarm: This DHS technology analyzes network behaviors and flags them as either safe or abnormal. The type of network activities that can be deemed as abnormal includes failed SMTP attempts, external internet connections, and others. The software also helps determine whether a particular abnormal activity can pose a threat or has malicious intents. Once a malicious activity has been detected an alert or “Alarm” is sent to the authorized network administrator.

REDUCE: This software helps investigators to compare malware samples and compare them to previously collected malware samples and groups. This gives investigators an idea about who coded a particular malware and its threat level. Unlike other comparison technologies, which allows the comparison of two malware samples, REDUCE allows users to search a database of malware samples. Much like a search engine, the software displays malware samples and groups that have similar coding to the original sample after running it through the database.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

OpenVPN Flaw Allows Attackers Crash Servers and Run Remote Code

OpenVPN, a widely-used open-source virtual private network (VPN) software, has recently patched a security...

Apache Traffic Server Flaw Allows Request Smuggling Attacks

A critical vulnerability has been discovered in Apache Traffic Server (ATS), an open-source caching...

Secure Ideas Achieves CREST Accreditation and CMMC Level 1 Compliance

Secure Ideas, a premier provider of penetration testing and security consulting services, proudly announces...

New Phishing Campaign Targets Investors to Steal Login Credentials

Symantec has recently identified a sophisticated phishing campaign targeting users of Monex Securities (マネックス証券),...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

DarkCloud Stealer Uses Weaponized .TAR Archives to Target Organizations and Steal Passwords

A recent cyberattack campaign leveraging the DarkCloud stealer has been identified, targeting Spanish companies...

EvilCorp and RansomHub Collaborate to Launch Worldwide Attacks on Organizations

EvilCorp, a sanctioned Russia-based cybercriminal enterprise, has been observed collaborating with RansomHub, one of...

Hackers Exploit Cloudflare for Advanced Phishing Attacks

A sophisticated phishing campaign orchestrated by a Russian-speaking threat actor has been uncovered, revealing...