Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

AMTSO Releases Sandbox Evaluation Framework

AMTSO has developed a Sandbox Evaluation Framework to standardize the testing of malware analysis solutions. 

Developer security vulnerability

AMTSO, the cybersecurity industry’s testing standards community, on Wednesday announced the creation of a sandbox evaluation framework whose goal is to standardize the testing of sandbox-based malware analysis solutions. 

Sandbox systems are increasingly important in the analysis of malware and other potential threats, but it can be challenging to determine which solution is the best for a user’s specific requirements. 

AMTSO’s Sandbox Evaluation Framework aims to address this by providing a list of criteria and a scoring system to help researchers, vendors and other members of the cybersecurity industry with evaluating and comparing sandboxes. 

For instance, inline protection sandboxes have a very low latency and are good for real-time protection, which makes them ideal for products such as email gateways and web application firewalls. However, their analysis capabilities in terms of depth are limited.

On the other hand, full attack chain analysis sandboxes are much slower, but their depth capabilities are very high, enabling the analysis of sophisticated threats. 

AMTSO’s Sandbox Evaluation Framework looks at a sandbox’s detection capability, anti-evasion technology, analysis depth, speed and scale, deployment, reporting and threat intelligence, and automation and integration.

“Each of these indicators addresses a critical aspect of sandbox efficacy, allowing organizations to make informed decisions about which solution best fits their security needs,” the framework’s developers said. 

Advertisement. Scroll to continue reading.

“For example, an organization focusing on a prevention use case may favor detection capability, speed, and scalability. An email security gateway vendor that needs to process a massive amount of files may favor detection capability, compute cost, and ease of deployment/maintenance, or a research lab might be interested in deep-diving memory dumps and dissecting a file from an incident response perspective,” they explained. 

The documentation shared by AMTSO explains how scores can be assigned — for example, 0 is given if a feature is not available, 3 for limited support, and 10 for exceptional capability. It also explains the process of assigning weights depending on the importance of each performance indicator. 

Once scores and weights have been assigned, the user can calculate a total score and a weighted score that indicates which sandbox solution is the best for their needs.

Related: New AI Security Tool Helps Organizations Set Trust Zones for Gen-AI Models

Related: Free Diagram Tool Aids Management of Complex ICS/OT Cybersecurity Decisions

Related: Google Releases Major Update for Open Source Vulnerability Scanner

Related: OpenSSF Releases Security Baseline for Open Source Projects

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Chip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.