Wednesday, January 8, 2025
HomeComputer Security5 Homeland Security Technologies That Might Be Commercialized

5 Homeland Security Technologies That Might Be Commercialized

Published on

The federal government spends an upwards of $1 billion each year on unclassified cybersecurity research.  This fuel a part of Homeland Security technology research and results in the development of new software programs that helps thwart new age cyberthreats.

These are not top-secret research projects that are too sensitive to declassify. In fact, the government is looking for ways to introduce these technologies to the marketplace. In hopes that private companies would show interest in licensing these technologies and package them as commercial security products, the government had made a list of 8 security techs back in 2016 that they are willing to release to the public. Following are 5 of them that has a high likelihood of getting commercialized.

REnigma: Malware can potentially do a lot of damage and some of them can even shutdown entire networks in a matter of seconds. REnigma is a Homeland Security technology that creates a virtual system that allows the malware to run.

This virtual system can be used to test different malware to see how they operate and thus develop security solutions to mitigate their threats. The virtual environment created by REnigma tricks the malware into thinking that it’s attacking an actual system. Once the malware does its thing, researchers can replay how it affected the virtual system without putting their actual computers at harm.

Pre-REnigma era required arduous efforts to analyze malware as it required days of reverse engineering to understand the workings of these malicious software programs.

PcapDB: This is a software that stores packets of data in a network. Almost like an airplane cockpit black box, this data can later be analyzed after a cyberattack has occurred. PcapDB is almost like a logbook that helps investigators understand a particular cyber attack and possibly deduce its origins.

FLOWER: This is a technology that’s already being used by many government offices and it’s aimed at detecting coordinated cyber-attack signatures and prevent them. A small hardware is installed in the network that captures IP Packets. It keeps a 24X7 vigil against network breaches and signatures for insider attacks.

SilentAlarm: This DHS technology analyzes network behaviors and flags them as either safe or abnormal. The type of network activities that can be deemed as abnormal includes failed SMTP attempts, external internet connections, and others. The software also helps determine whether a particular abnormal activity can pose a threat or has malicious intents. Once a malicious activity has been detected an alert or “Alarm” is sent to the authorized network administrator.

REDUCE: This software helps investigators to compare malware samples and compare them to previously collected malware samples and groups. This gives investigators an idea about who coded a particular malware and its threat level. Unlike other comparison technologies, which allows the comparison of two malware samples, REDUCE allows users to search a database of malware samples. Much like a search engine, the software displays malware samples and groups that have similar coding to the original sample after running it through the database.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Gravy Analytics Hit by Cyberattack, Hackers Allegedly Stole data

Gravy Analytics, a prominent player in location intelligence, has reportedly fallen victim to a...

Chrome Security Update – Patch for Multiple Security Vulnerabilities

Google has released an update for its Chrome web browser, advancing to version 131.0.6778.264/.265...

How Nation-State Actors and Organised Hackers Involving in Their Ways of Cyber Attacks

The distinction between nation-state actors and organized cybercriminals is becoming increasingly blurred.Both groups...

Washington State Filed Lawsuit Against T-Mobile Massive Data Breach

Washington State Attorney General Bob Ferguson filed a consumer protection lawsuit against T-Mobile for...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Gravy Analytics Hit by Cyberattack, Hackers Allegedly Stole data

Gravy Analytics, a prominent player in location intelligence, has reportedly fallen victim to a...

How Nation-State Actors and Organised Hackers Involving in Their Ways of Cyber Attacks

The distinction between nation-state actors and organized cybercriminals is becoming increasingly blurred.Both groups...

Malicious npm Packages Stealing Developers’ Sensitive Data

Attackers published 20 malicious npm packages impersonating legitimate Nomic Foundation and Hardhat plugins, where...