Met outfits cyber crime unit with real-time malware analysis tools

FALCON will deploy Bromium's virtualisation tools to trace malware attacks

The London Metropolitan Police Service is set to provide its cybercrime taskforce with new real-time forensic analysis tools, the force announced today.

The Met has tapped cyber security firm Bromium to provide the new capabilities, and its FALCON (Fraud And Linked Crime Online) cybercrime division will soon be using the company's micro-virtualisation technology to analyse malware samples in a fast, secure manner.

"The Met is committed to fighting cybercrime and works hard every day to catch and convict cybercriminals and support victims," said detective superintendent Neil Ballard. "Speed is an advantage when investigating these kinds of crime."

Bromium provides an advantage in this regard, the company's EMEA CTO Fraser Kyne told IT Pro, because running malware samples within Bromium generates forensic reports in near-real time.

Advertisement
Advertisement - Article continues below

"When you detonate malware inside a micro-VM, as soon as the micro-VM is closed, those forensics are instantly available," he said. "It really just takes away that triage thing and it jumps you straight from the point of the malware executing to giving you a visibility of what actually happened in the micro-VM."

Another touted benefit is that, because Bromium's virtualised environments are built with just the minimum amount of code needed to run malware samples, the signal-to-noise ratio is much better than with general purpose hypervisors. This allows officers and investigators to identify anomalies much more quickly.

"Like biological evidence, cyber evidence degrades over time," said the Met's Ballard. "Websites are taken down and the trail goes cold. Bromium can be used to instantly analyse and gather evidence. The victim can then be immediately advised how to mitigate the threat. Evidence collected can then be used to track down the criminal and secure convictions."

Kyne also pointed out that the virtualisation element of Bromium's product also means that the Met can safely run malware without the risk of infecting the rest of its network - which still includes thousands of Windows XP machines.

"When you're interacting with things that are of this nature, they are by their very nature unsafe to use, so we give them that protective bubble to be able to safely analyse the malware and to very quickly extract useful forensic information out of it," he said.

The news demonstrates the Met's attempts to get to grips with cyber crime, which has hit one in 10 Britons, according to ONS data. Including 5.8 million cyber offences in ONS figures for the first time last year led to England and Wales' crime rate doubling for 2016.

FALCON, launched in 2014, comprises 500 officers tasked with tackling cyber crimes that lead to financial loss - so malware, DDoS attacks and network intrusion crimes.

Think tank Reform recommended that police forces should be able to sack officers who don't have the skills to tackle cyber crime, in a report released in August.

Picture: Bigstock

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/malware/33080/hackers-abuse-linkedin-dms-to-plant-malware
malware

Hackers abuse LinkedIn DMs to plant malware

25 Feb 2019
Visit/antivirus/28144/best-antivirus
antivirus

Best antivirus for Windows 10

3 Sep 2019
Visit/security/malware/28083/the-five-best-free-malware-removal-tools
Security

Best free malware removal tools 2019

8 Mar 2019

Most Popular

Visit/security/identity-and-access-management-iam/354289/44-million-microsoft-customers-found-using
identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019
Visit/business/business-strategy/354195/where-modernisation-and-sustainability-meet-a-tale-of-two
Sponsored

Where modernisation and sustainability meet: A tale of two benefits

25 Nov 2019