Thursday, March 28, 2024

5 Homeland Security Technologies That Might Be Commercialized

The federal government spends an upwards of $1 billion each year on unclassified cybersecurity research.  This fuel a part of Homeland Security technology research and results in the development of new software programs that helps thwart new age cyberthreats.

These are not top-secret research projects that are too sensitive to declassify. In fact, the government is looking for ways to introduce these technologies to the marketplace. In hopes that private companies would show interest in licensing these technologies and package them as commercial security products, the government had made a list of 8 security techs back in 2016 that they are willing to release to the public. Following are 5 of them that has a high likelihood of getting commercialized.

REnigma: Malware can potentially do a lot of damage and some of them can even shutdown entire networks in a matter of seconds. REnigma is a Homeland Security technology that creates a virtual system that allows the malware to run.

This virtual system can be used to test different malware to see how they operate and thus develop security solutions to mitigate their threats. The virtual environment created by REnigma tricks the malware into thinking that it’s attacking an actual system. Once the malware does its thing, researchers can replay how it affected the virtual system without putting their actual computers at harm.

Pre-REnigma era required arduous efforts to analyze malware as it required days of reverse engineering to understand the workings of these malicious software programs.

PcapDB: This is a software that stores packets of data in a network. Almost like an airplane cockpit black box, this data can later be analyzed after a cyberattack has occurred. PcapDB is almost like a logbook that helps investigators understand a particular cyber attack and possibly deduce its origins.

FLOWER: This is a technology that’s already being used by many government offices and it’s aimed at detecting coordinated cyber-attack signatures and prevent them. A small hardware is installed in the network that captures IP Packets. It keeps a 24X7 vigil against network breaches and signatures for insider attacks.

SilentAlarm: This DHS technology analyzes network behaviors and flags them as either safe or abnormal. The type of network activities that can be deemed as abnormal includes failed SMTP attempts, external internet connections, and others. The software also helps determine whether a particular abnormal activity can pose a threat or has malicious intents. Once a malicious activity has been detected an alert or “Alarm” is sent to the authorized network administrator.

REDUCE: This software helps investigators to compare malware samples and compare them to previously collected malware samples and groups. This gives investigators an idea about who coded a particular malware and its threat level. Unlike other comparison technologies, which allows the comparison of two malware samples, REDUCE allows users to search a database of malware samples. Much like a search engine, the software displays malware samples and groups that have similar coding to the original sample after running it through the database.

Website

Latest articles

Wireshark 4.2.4 Released: What’s New!

Wireshark stands as the undisputed leader, offering unparalleled tools for troubleshooting, analysis, development, and...

Zoom Unveils AI-Powered All-In-One AI Work Workplace

Zoom has taken a monumental leap forward by introducing Zoom Workplace, an all-encompassing AI-powered...

iPhone Users Beware! Darcula Phishing Service Attacking Via iMessage

Phishing allows hackers to exploit human vulnerabilities and trick users into revealing sensitive information...

2 Chrome Zero-Days Exploited at Pwn2Own 2024: Patch Now

Google has announced a crucial update to its Chrome browser, addressing several vulnerabilities, including...

The Moon Malware Hacked 6,000 ASUS Routers in 72hours to Use for Proxy

Black Lotus Labs discovered a multi-year campaign by TheMoon malware targeting vulnerable routers and...

Hackers Actively Exploiting Ray AI Framework Flaw to Hack Thousands of Servers

A critical vulnerability in Ray, an open-source AI framework that is widely utilized across...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Mitigating Vulnerability Types & 0-day Threats

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

Related Articles