Tuesday, November 26, 2024
HomeComputer Security5 Homeland Security Technologies That Might Be Commercialized

5 Homeland Security Technologies That Might Be Commercialized

Published on

The federal government spends an upwards of $1 billion each year on unclassified cybersecurity research.  This fuel a part of Homeland Security technology research and results in the development of new software programs that helps thwart new age cyberthreats.

These are not top-secret research projects that are too sensitive to declassify. In fact, the government is looking for ways to introduce these technologies to the marketplace. In hopes that private companies would show interest in licensing these technologies and package them as commercial security products, the government had made a list of 8 security techs back in 2016 that they are willing to release to the public. Following are 5 of them that has a high likelihood of getting commercialized.

REnigma: Malware can potentially do a lot of damage and some of them can even shutdown entire networks in a matter of seconds. REnigma is a Homeland Security technology that creates a virtual system that allows the malware to run.

- Advertisement - SIEM as a Service

This virtual system can be used to test different malware to see how they operate and thus develop security solutions to mitigate their threats. The virtual environment created by REnigma tricks the malware into thinking that it’s attacking an actual system. Once the malware does its thing, researchers can replay how it affected the virtual system without putting their actual computers at harm.

Pre-REnigma era required arduous efforts to analyze malware as it required days of reverse engineering to understand the workings of these malicious software programs.

PcapDB: This is a software that stores packets of data in a network. Almost like an airplane cockpit black box, this data can later be analyzed after a cyberattack has occurred. PcapDB is almost like a logbook that helps investigators understand a particular cyber attack and possibly deduce its origins.

FLOWER: This is a technology that’s already being used by many government offices and it’s aimed at detecting coordinated cyber-attack signatures and prevent them. A small hardware is installed in the network that captures IP Packets. It keeps a 24X7 vigil against network breaches and signatures for insider attacks.

SilentAlarm: This DHS technology analyzes network behaviors and flags them as either safe or abnormal. The type of network activities that can be deemed as abnormal includes failed SMTP attempts, external internet connections, and others. The software also helps determine whether a particular abnormal activity can pose a threat or has malicious intents. Once a malicious activity has been detected an alert or “Alarm” is sent to the authorized network administrator.

REDUCE: This software helps investigators to compare malware samples and compare them to previously collected malware samples and groups. This gives investigators an idea about who coded a particular malware and its threat level. Unlike other comparison technologies, which allows the comparison of two malware samples, REDUCE allows users to search a database of malware samples. Much like a search engine, the software displays malware samples and groups that have similar coding to the original sample after running it through the database.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Beware Of SpyLoan Apps Exploits Social Engineering To Steal User Data

SpyLoan apps, a type of PUP, are rapidly increasing, exploiting social engineering to deceive...

Researchers Detailed Tools Used By Hacktivists Fueling Ransomware Attacks

CyberVolk, a politically motivated hacktivist group, has leveraged readily available ransomware builders like AzzaSec,...

Blue Yonder Ransomware Attack Impacts Starbucks & Multiple Supermarkets

A ransomware attack on Blue Yonder, a leading supply chain management software provider, has...

Dell Wyse Management Suite Vulnerabilities Let Attackers Exploit Affected Systems Remotely

Dell Technologies has released a security update for its Wyse Management Suite (WMS) to...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

IBM Workload Scheduler Vulnerability Stores User Credentials in Plain Text

IBM has issued a security bulletin warning customers about a vulnerability in its Workload...

Nearest Neighbor Attacks: Russian APT Hack The Target By Exploiting Nearby Wi-Fi Networks

Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as...

Earth Kasha Upgraded Their Arsenal With New Tactics To Attack Organizations

Earth Kasha, a threat actor linked to APT10, has expanded its targeting scope to...