Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

AMTSO Releases Sandbox Evaluation Framework

AMTSO has developed a Sandbox Evaluation Framework to standardize the testing of malware analysis solutions. 

Developer security vulnerability

AMTSO, the cybersecurity industry’s testing standards community, on Wednesday announced the creation of a sandbox evaluation framework whose goal is to standardize the testing of sandbox-based malware analysis solutions. 

Sandbox systems are increasingly important in the analysis of malware and other potential threats, but it can be challenging to determine which solution is the best for a user’s specific requirements. 

AMTSO’s Sandbox Evaluation Framework aims to address this by providing a list of criteria and a scoring system to help researchers, vendors and other members of the cybersecurity industry with evaluating and comparing sandboxes. 

For instance, inline protection sandboxes have a very low latency and are good for real-time protection, which makes them ideal for products such as email gateways and web application firewalls. However, their analysis capabilities in terms of depth are limited.

On the other hand, full attack chain analysis sandboxes are much slower, but their depth capabilities are very high, enabling the analysis of sophisticated threats. 

AMTSO’s Sandbox Evaluation Framework looks at a sandbox’s detection capability, anti-evasion technology, analysis depth, speed and scale, deployment, reporting and threat intelligence, and automation and integration.

“Each of these indicators addresses a critical aspect of sandbox efficacy, allowing organizations to make informed decisions about which solution best fits their security needs,” the framework’s developers said. 

Advertisement. Scroll to continue reading.

“For example, an organization focusing on a prevention use case may favor detection capability, speed, and scalability. An email security gateway vendor that needs to process a massive amount of files may favor detection capability, compute cost, and ease of deployment/maintenance, or a research lab might be interested in deep-diving memory dumps and dissecting a file from an incident response perspective,” they explained. 

The documentation shared by AMTSO explains how scores can be assigned — for example, 0 is given if a feature is not available, 3 for limited support, and 10 for exceptional capability. It also explains the process of assigning weights depending on the importance of each performance indicator. 

Once scores and weights have been assigned, the user can calculate a total score and a weighted score that indicates which sandbox solution is the best for their needs.

Related: New AI Security Tool Helps Organizations Set Trust Zones for Gen-AI Models

Related: Free Diagram Tool Aids Management of Complex ICS/OT Cybersecurity Decisions

Related: Google Releases Major Update for Open Source Vulnerability Scanner

Related: OpenSSF Releases Security Baseline for Open Source Projects

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.