Lastline Emulating its Way to Security Breach Detection Success | Internet News

Lastline Emulating its Way to Security Breach Detection Success

Jan 28, 2015
1 minute read

The Lastline platform provides a full-system emulation approach to detecting malware and potential breach risks. At the core of the platform, Lastline leverages the open-source QEMU (Quick EMUlator) emulator, which, according to Kirda, Lastline has heavily modified and extended.

“Malware has become very evasive, so when you attempt to analyze it, the behavior can change,” Engin Kirda, Lastline’s co-founder and chief architect said. “So our technology has full-system emulation that allows us to look deeper into malware execution and extract behaviors.”

Lastline’s system also has a correlation engine that can provide context, pulling different security events together to provide a complete picture. For example, the system would understand that something was downloaded, which in turn led to an infection and then some kind of connection out to a botnet for command and control.

Lastline’s “secret sauce” isn’t just the emulation technology, but rather the detection mechanisms that are used, according to Kirda.

Read the full story at eWEEK:
Lastline Extends Breach Protection via Dell SecureWorks Service

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.