Clicky

Explore Joe Security Cloud Basic Accounts Subscribe to our Newsletters Contact Us
top title background image

Joe Sandbox Class

Scalable Malware Similarity Analysis and Clustering!

Joe Sandbox Class Joe Sandbox Class enables to cluster malware into groups that share common behavior. Given a malware sample, Joe Sandbox Class identifies all similar samples.

Class reports that contain key information about the common functionality within a malware group enable cyber-security professionals to find and classify new malware variants and to understand the evolution of modern threats.

Joe Sandbox Class is a plugin for Joe Sandbox Desktop, Joe Sandbox Complete and Joe Sandbox Light.

Joe Sandbox Class Explained

Joe Sandbox Class Explained

Joe Sandbox Class is directly added as an output processor to Joe Sandbox Desktop, Complete or Light.
Features from the analysis report are extracted in the first step of the process. Joe Sandbox Class mainly uses Hybrid Code Analysis in this step. Next, the features are generalized and noise is reduced. A similarity search over all stored features is then executed.
Joe Sandbox Class generates a classification report in HTML, XML and JSON outlining similar samples as well as the shared Hybrid Code Analysis results. In addition, it compiles a detailed graph for a complete malware set.

Joe Sandbox Class output is very useful for finding similarities shared within different malware variants or groups. It can also be used to identify new, never-before-seen samples.

Explore Joe Sandbox Class

Have a look at the behavior analysis reports generated by Joe Sandbox Class or contact Joe Security to schedule a technical presentation.

Hybrid Code Analysis Data

Joe Sandbox Class classification algorithm is based on Hybrid Code Analysis (HCA) results. HCA combines dynamic and static program analysis while retaining such benefits as code completion. Joe Sandbox Class uses the complete view, including non-executed codes of the malware behavior for similarity analysis.

Hybrid Code Analysis Data

Scalable

Joe Sandbox Class's classification algorithm is scalable (O(n*m), n = number of features per sample, m = number of stored features in the database) and can be mutlithreaded to process enormous amounts of data in a short period of time.

Scalable

Quick Installation and Setup

Joe Sandbox Class is a plugin for Joe Sandbox Desktop, Complete or Light. Its installation and setup is quick and simple.

Quick Installation and Setup

Supplementary Analysis Data

In addition to classification reports in HTML, XML and JSON formats, Joe Sandbox Class generates a detailed cluster map in GraphML format.

Supplementary Analysis Data

Flexibility and Customization

Joe Sandbox Class is built as a modular and scalable system with many settings for advanced tuning. With its open SDK, behavior signatures and cookbooks, it enables performing advanced use cases to serve organizations' specific needs. Joe Sandbox Class supports multiple analysis machines with different applications/versions installed.

Flexibility and Customization

Additional Support, Maintenance and Consulting

Joe Security provides excellent services, such as system installations, training, maintenance, customization and expert knowledge as an supplemental package to Joe Sandbox Class.

Additional Support, Maintenance and Consulting

Explore Joe Sandbox Class

Find similar malware samples at http://www.class-analyzer.net and contact [javascript protected email address] to schedule a technical presentation.