Platform Requirements
Hardware and performance specifications for ReversingLabs virtual appliances and deployment profiles.
Spectra Analyze
| Specification | Spectra Analyze E-1K | Spectra Analyze 5K | Spectra Analyze E-15K | Spectra Analyze 30K |
|---|---|---|---|---|
| Application | Any | Any | Any | Any |
| Included Modules | ReversingLabs Sample Analysis Application | ReversingLabs Sample Analysis Application | ReversingLabs Sample Analysis Application | ReversingLabs Sample Analysis Application |
| Spectra Core™ Pre-Execution / Static Analysis Engine | Spectra Core™ Pre-Execution / Static Analysis Engine | Spectra Core™ Pre-Execution / Static Analysis Engine | Spectra Core™ Pre-Execution / Static Analysis Engine | |
| Spectra Cloud™ File Reputation Web Services Interface | Spectra Cloud™ File Reputation Web Services Interface | Spectra Cloud™ File Reputation Web Services Interface | Spectra Cloud™ File Reputation Web Services Interface | |
| CPU | 8 cores | 16 cores | 24 cores | 32 cores |
| RAM | 64 GB | 96 GB | 128 GB | 256 GB |
| Storage Size | 1 TB | 2 TB | 3 TB | 4 TB |
| Storage Media | SSD-backed | SSD-backed | SSD-backed | SSD-backed |
| Min. IOPS | 2000 | 2000 | 2000 | 2000 |
| Min. Throughput (MBps) | 300 | 300 | 300 | 300 |
| Network Throughput (Mbps) | 100 | 100 | 100 | 100 |
| AWS Instance | r6a.2xlarge with 1 TB EBS gp3 | r6a.4xlarge with 2 TB EBS gp3 | r6a.8xlarge with 3 TB EBS gp3 | r7a.12xlarge with 4 TB EBS gp3 |
Spectra Analyze Platform Requirements are the minimum recommended specifications where file size must be under 400MB total and average size for all files under 250k for Spectra Analyze E-1K. Spectra Analyze 30K supports file sizes up to 10GB. For security hardening guidance applicable to deployment environments, refer to NIST SP 800-53 security controls.
For more deployment information, see Cloud Deployment Options and Firewall and Network Connections.
Spectra Detect
| Specification | Spectra Detect Manager | Spectra Detect Hub | Spectra Detect Worker |
|---|---|---|---|
| Application | Any | Large-sized organizations | Any |
| Included Modules | Central Management for Appliances | Load Balancer | Spectra Cloud™ File Reputation Web Services Interface |
| Central Status Overview for Appliances | Load Monitor | Spectra Core™ Pre-Execution / Static Analysis Engine | |
| Central Update Management for Appliances | Web Services API, Splunk Export | ||
| CPU | 8 cores | 8 cores | 32 cores |
| RAM | 64 GB | 64 GB | 128 GB |
| Storage Size | 2 TB | 1 TB | 2 TB |
| Storage Media | SSD-backed | SSD-backed | SSD-backed |
| Min. IOPS | 2000 | 2000 | 40,000 |
| Min. Throughput (MBps) | 90 | 90 | 600 |
| Network Throughput (Mbps) | 100 | 100 | 800 |
| AWS Instance | m6a.xlarge with 2 TB EBS gp3 | m6a.xlarge with 1 TB EBS gp3 | See Worker Profiles below |
Worker Profiles
The following table takes into account a single Worker. Varying specs imply different performance levels.
| Specification | Profile 1 | Profile 2 | Profile 3 |
|---|---|---|---|
| Core count | 8 | 16 | 32 |
| Memory (GB) | 32 | 64 | 128 |
| Disk (SSD) | 1TB | 1.5TB | 2TB |
| Performance (MB/sec) | 1.6 | 3.2 | 6.4 |
| Files / day | 150,000 | 300,000 | 600,000 |
| TB / day | 0.125 | 0.25 | 0.5 |
| Min Look-ups / day | 1,500,000 | 3,000,000 | 6,000,000 |
| Max Look-ups / day | 7,500,000 | 15,000,000 | 30,000,000 |
| Max file size | 1GB | 6GB | 200GB |
| AWS Instance | m6a.2xlarge with 1 TB EBS gp3 | m6a.4xlarge with 1.5 TB EBS gp3 | m6a.8xlarge with 2 TB EBS gp3 |
The maximum file size depends on the content of the file, not only its size. Spectra Detect unpacks a submitted file and analyzes what's inside it, so the limit is governed by how much content the file expands into during analysis. This applies to every profile. The figures below were measured on Profile 3; Profile 1 and Profile 2 behave the same way at lower thresholds, because both the working storage and the memory available for analysis are smaller.
Content that expands little can go higher. In testing on Profile 3 hardware, an archive of model weights processed successfully at 400 GB. A single model file processed successfully at 200 GB.
Content that expands a great deal must stay lower. Compressed data such as parquet or gzipped text can expand seven times or more, and analyzing it is bound by available memory rather than by file size. In testing on Profile 3 hardware, a 50 GB archive of parquet data processed successfully, while archives of 75 GB and larger did not complete.
As a sizing guide, allow roughly three times the submission size in working storage for model content, and seven times or more for compressed data.
T1000
| Specification | T1000 R1 | T1000 XG | T1000 Assure |
|---|---|---|---|
| Application | Any | Any | Any |
| Included Modules | File Reputation Database - R1 set plus additional file threat classification | File Reputation Database - XG set plus latest AV scan information | File Reputation Database - XG set plus latest AV scan information |
| Web Services API | Web Services API | Web Services API | |
| Database auto-update | Database auto-update | Database auto-update | |
| CPU | ≥16 cores | ≥16 cores | ≥16 cores |
| RAM | 64 GB | 64 GB | 64 GB |
| Storage Size | 21 TB | 36 TB | 20 TB |
| Storage Media | SSD-backed | SSD-backed | SSD-backed |
| Min. IOPS | 20,000 | 30,000 | 30,000 |
| Min. Throughput (MBps) | 250 | 320 | 320 |
| Network Throughput (Mbps) | 250 | 500 | 500 |
| VM Requirements |