Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

3/10/2015
03:05 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
100%
0%

Startup Focuses On Stopping Data Exfiltration

Former Akamai and Imperva exec heads up new security firm enSilo, launches an operating system-level endpoint security tool.

Now that most businesses are resigned to the fact that they can't stop the bad guys from getting in, the focus increasingly is on how to stop them from taking any data out. A new startup emerging from stealth today is rolling out a next-generation endpoint tool for catching malware and preventing the bad guys from stealing information.

Security firm enSilo, based in Israel, today officially launched and introduced a real-time endpoint security tool for preventing the exfiltration of data by attackers. In a nutshell, it looks for malicious connection attempts from the machine to the outside, and shuts them down so intruders can't take anything with them on the way out. enSilo's product virtually patches against the attack.

It sits in the operating system in the form of a small footprint agent, and uses a whitelisting-type approach to catching malicious activity, says enSilo CEO Roy Katmor, who previously headed up Akamai’s security strategy, and prior to that managed Imperva's data security products and architecture management. "If you're a targeted attack and trying to work on a corporate device, you're going to make a foul. We know" how to spot the fouls, Katmor says.

"The biggest advantage of sitting in the OS is we are agnostic to protocols," Katmor says. "enSilo is a 'black box.'"

What enSilo does not do is catch the actual successful infiltration or attack. It's all about tripping up the bad guys when they try to remove data.

[Determined cybercriminals and cyberspies will find their way to the data they want, but there are ways to trip them up as they try to make their way out. Read Operation Stop the Exfiltration.]

David Monahan, research director for security and risk management at Enterprise Management Associates, says what's unique about enSilo's approach is that it looks or the moment the malware attempts to communicate to its external systems. "They have identified that malware does not like to follow the standard conventions when it comes to making its communications.  It tries any number of things to bypass the normal channels to avoid being restricted or identified by the OS," Monahan says. "At that point it [enSilo] stops the communication attempt," Monahan says.

Because this process operates at the kernel level, he says, it's difficult for an attack to cheat it or bypass it. enSilo has both a cloud- and local server option that can be integrated with perimeter security tools to block the types of behaviors it catches, he notes.

With the days of stopping attacks at the door long gone for the most part--especially given increasingly advanced and persistent attacks--security strategies are shifting to making it harder for the bad guys to do damage once they've gotten inside. That means putting up hurdles for their exfiltration phase.

In addition to its platform for preventing exfiltration, enSilo also plans to add a next-generation firewall that monitors communications to all applications and stops any malicious ones.

The first generation of enSilo products include an agent gateway, a cloud gateway, a Windows 7/8/XP agent, endpoint distribution via LDAP, SIEM integration and a software management server. Next month, enSilo will add endpoint distribution with Symantec and McAfee software, out-of-line gateway support, next-gen firewall support, and a new management server.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
roy@enSilo
50%
50%
[email protected],
User Rank: Author
3/10/2015 | 6:21:06 PM
Re: enSilo vs Falcon
Hi Ryan,

Thanks for asking.

 To answer the first part of your question, enSilo vs. Falcon:

I wish not to refer to CrowdStrike's Falcon. However, I can quickly elaborate on enSilo's technology. enSilo's platform correlates the OS-related activity together with the respective actual outbound communication request. As such, enSilo prevents the consequences of the targeted attack – the data theft (exfiltration), and by design generates one alert for a single active communicating threat.

 

As for your second part, enSilo vs. NIPS –

NIPS employs packet filtering of incoming data packets. On the other hand, as mentioned, enSilo's platform correlates the OS-related activity together with the respective actual outbound communication request. As such, NIPS does not provide that intimate visibility.

 

If you want more information, feel free to PM me.
RyanSepe
100%
0%
RyanSepe,
User Rank: Ninja
3/10/2015 | 10:47:37 AM
enSilo vs Falcon
What are the differences between CrowdStrike's Falcon Endpoint and enSilo? I feel that they have a similar feel as to technique.

Also, can't this whitelisting approach be instantiated at the NIPS level as well? You are essentially stating that you will only accept traffic from the verified data transit feeds.
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-3154
PUBLISHED: 2020-01-27
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
CVE-2019-17190
PUBLISHED: 2020-01-27
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the...
CVE-2014-8161
PUBLISHED: 2020-01-27
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2014-9481
PUBLISHED: 2020-01-27
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
CVE-2015-0241
PUBLISHED: 2020-01-27
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric ...