Skip to content
JBRichardson.comIT Cloud Solutions

Cyber Threat Assessment

In computers, the term sandboxing has long been used to represent a safe, isolated environment in which to run malicious code so researchers can analyze it. Network security appliances now use this concept: they execute and inspect network traffic and uncover malicious code that would previously slip past traditional security measures.

A sandbox can emulate entire end-user operating environments and safely execute suspicious code so its activity can be observed: file operations, network connections, registry or system configuration changes and more. Early sandboxes could only scan executable files. Advanced platforms now scan many more file types, including JavaScript, Adobe Flash and Microsoft Office files, and integrate tightly into the rest of your security infrastructure.

Fighting today's advanced threats takes a multilayered approach. Fortinet FortiSandbox combines proactive mitigation, visibility and rich reporting with award-winning antivirus and threat-scanning technology and dual-level sandboxing.

Why sandboxing matters

  • Cybercriminals keep developing new tools and techniques, so new threats must be found and contained quickly.
  • Sandboxing is resource intensive; pairing it with proactive signature detection filters traffic before it reaches the full sandbox.
  • A single proactive signature can catch 50,000 or more variants of a malware family.

Advanced evasion techniques to defend against

  • APTs and AETs: custom-developed, targeted attacks that use zero-day malware and social engineering
  • Logic bombs: dormant code that runs only when a time or user action triggers it
  • Rootkits and bootkits that take control of the system before a sandbox can observe them
  • Sandbox detection: code that behaves normally when it knows it is being watched
  • Botnet command and control through clean droppers that connect out later
  • Network fast flux and domain generation algorithms
  • Encrypted archives and binary packers that hide malware from inspection

Integration

  • FortiSandbox integrates with FortiGate, FortiMail, FortiWeb and FortiClient devices with minimal configuration.
  • Ratings and signatures flow back to your inspection points for policy-based response and protection against lateral movement.
  • Default connectors and an open, standards-based API share intelligence with third-party security products.