Beyond Firewalls: What Companies Are Doing to Outfox the Hackers

Advertisement
By Reuters | Updated: 27 January 2016 18:29 IST
With firewalls no longer seen as enough of a defence against security breaches, companies are looking at new tools to foil hackers trying to enter a computer network.

US and Israeli startups are leading the way, with new approaches such as "honeytraps" that lure a hacker to fake data or "polymorphic" technology that constantly changes the structure of applications running on a computer.

Some of the technology is still in the early stages and it remains to be seen whether it will be good enough to outfox the hackers.

Advertisement

But with corporate giants such as Sony and Twitter Inc facing high-profile hacks in recent years, companies are desperate for new ideas to make sure financial, personal and corporate data stays safe.

(Also see:  Sony Pictures Hit by Hackers | Pro-IS Hackers Take Over US Military Twitter Feed)

"We view this (deception technologies) as a $3 billion (roughly Rs. 20,396 crores) market over the next three years, with Israel and Silicon Valley being the epicentre of this innovation wave," said Daniel Ives, a senior technology analyst at FBR Capital Markets.

Advertisement

TopSpin Security, Illusive Networks, Cymmetria and GuardiCore in Israel, California-based TrapX and Attivo Networks are among a handful of start-ups forging ahead with deception technology. Israel's Morphisec and U.S. Shape Security are developing "polymorphic" systems.

Many of those companies use techniques partly developed in the US and Israeli military that were taken to startups by veterans such as Gadi Evron, the head of Cymmetria and of Israel's Computer Emergency Response Team.

Advertisement

TrapX Security offers DeceptionGrid, a technology using fake information that triggers a security alert.

TrapX clients include Israel's central bank, US hospital chain HCA, Bezeq, Israel's largest telecoms group, and Union Bank of Israel, according to Asaf Aviram, sales director for Israel and emergent markets at TrapX.

Advertisement

TopSpin Chief Executive Doron Kolton said his clients include one of Israel's top five banks, a large U.S. hospital and a mobility technology company. The product is resold by Optiv Security in the United States and Benefit in Israel.

Early days
While still a fraction of the overall cyber-security market, Gartner, a leading technology consultancy, sees 10 percent of businesses using deception tactics by 2018.

But Gartner analyst Laurence Pingree noted that they "have so far had only nascent adoption" as many of the companies don't yet understand the technology.

"Educating security buyers on its usefulness will be crucial," he said.

Some in the industry note that several companies including FireEye and CrowdStrike tried to launch similar products three or four years ago before pulling back although analysts say the technologies have improved greatly in the past two years.

"A lot of companies are looking at it but it's still early days," said a security executive with a Fortune 500 company.

He said deployments were quite limited, with most trials where business test the product on a limited basis at no cost.

Others said hackers may quickly be able to detect the traps.

"They will be challenged by the fact that (some) hackers are so sophisticated they might detect decoy servers or fake data," said Ziv Mador, head of research at Chicago-based cyber-security firm Trustwave.

The technology could offer a second layer of defence to firewalls, which cannot always block malicious attempts, he said, and did not rule out Trustwave offering deception tools in the future.

TopSpin's Kolton also noted that deception would be "part of a bigger solution" and to "be combined with other things".

Trail of breadcrumbs
The system developed by TopSpin, whose investors include Check Point Software Technologies co-founder Shlomo Kramer, engages attackers once they have penetrated the network. It leads hackers to decoys by sprinkling "breadcrumbs", such as fake credentials.

While the idea of a honeypot is not new, in the past they were used to alert IT administrators that there was a hacker in the system.

With more advanced technology they slow the hacker and set off tools to stop them getting further into the system. If they follow the trail to the trap, the company knows they are a hacker.

"When someone hits a honeypot it's malicious activity," Kolton said.

Attivo's website says their system lures attackers into revealing themselves when they start to look for "high-value assets". It also promises no false-alarms, a problem with traditional detection systems.

Other tools are being developed that would prevent hackers from penetrating a network entirely.

Morphisec, backed by Jerusalem Venture Partners, Deutsche Telekom and GE Ventures, has developed technology that randomly changes the structure of applications running on the computer.

"When an attack seeks its target it expects to find a certain memory structure. With Morphisec it finds something different," Morphisec CEO Ronen Yehoshua said.

Shape Security of California also uses such "polymorphic" technology.

While these new ideas have mainly been generated by start-up companies, investors say bigger, more established security players are interested.

"I'd say that many antivirus companies are already looking into building similar technologies on their own or buying them," JVP managing partner Gadi Tirosh said.

© Thomson Reuters 2016

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy M17e 5G Debuts With 6,000mAh Battery at This Price in India
  2. Poco X8 Series Arrives in India With 50-Megapixel Camera: See Price
  3. Best Mobiles Under Rs. 25,000 in India
  4. Apple Reportedly Increases Foldable iPhone Panel Orders to 20 Million
  5. Vivo T5x 5G Goes Official in India With 7,200mAh Battery
  6. Xiaomi 18 Pro May Feature Two 200-Megapixel Cameras and a 7,000mAh Battery
  7. Seetha Payanam OTT Release Date: When and Where to Watch it Online?
  8. iQOO 15R Review
  9. Realme P4 Lite 5G Roundup: Price in India, Specifications Expected
  1. Instagram Rolls Out New AI Voice Effects For Voice Notes With Eight Filters
  2. Apple Reportedly Boosts Foldable Panel Orders to 20 Million, Suggesting Strong Demand for Foldable iPhone
  3. Smriti Irani Backs Women Entrepreneurs With SPARK Collective Push and British Council Partnership
  4. Oppo Watch X3 With Snapdragon W5 Chipset, Over 100 Sports Modes Launched
  5. Oppo Find N6 Launched With Snapdragon 8 Elite Gen 5 SoC, 6,000mAh Battery: Price, Features
  6. Poco X8 Pro Series Launched in India With Up to 9,000mAh Battery, 50-Megapixel Camera: Price, Specifications
  7. OnePlus Pad 3 Tipped to Launch With 13.2-Inch Display, Snapdragon 8 Elite Gen 5 Chip
  8. Vivo X500 Series Chipsets Tipped Months Ahead of Launch; Vivo Pro Max Could Also Debut
  9. Argentina Bans Polymarket Over Unregulated Crypto Betting Concerns: Report
  10. Oura Ring 4 Launched in India With Smart Sensing Technology and HRV Tracking: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.