Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

Darktrace Brings Threat Detection Platform to Third-Party Clouds

UK-based Darktrace, a cyber security startup that leverages machine learning and mathematics to detect threats, announced on Tuesday that it has extended its self-learning threat detection technology to virtualized environments.

UK-based Darktrace, a cyber security startup that leverages machine learning and mathematics to detect threats, announced on Tuesday that it has extended its self-learning threat detection technology to virtualized environments.

The company offers a so called “Enterprise Immune System” that detects previously unknown threats using machine learning and mathematics technology developed at the University of Cambridge.

Darktrace Logo

Deployed within an appliance installed inside an enterprise network, Darktrace says that its “self-learning” software can now gain visibility into virtualized environments, including third-party cloud environments.

The Darktrace platform leverages lightweight, host-based server agents (OS-Sensors) that complement its vSensors, virtual appliances configured to receive a SPAN for the virtual network switch.

The company explains that its OS-Sensors work by extracting copies of network traffic for analysis by the Darktrace appliance, giving the system a view of lateral information flow within the cloud, as well as within the physical network activity.

With complete visibility into cloud and on-premise network data, the solution creates only single copies of network traffic, avoiding data duplication. Additionally, the OS-Sensors can be easily installed onto virtual machines, without requiring access to the physical server, and can be configured to see all or selected cloud traffic, Darktrace said.

Darktrace’s OS-Sensors are compatible with popular cloud hosting services including Amazon Web Services, Google’s Cloud Platform, Rackspace and Microsoft Azure.

The company explains on its website that its platform “models patterns of life for each user and machine” to detect normal and abnormal behaviors as they emerge, without already knowing what it is looking for, and calculate the probability of threat based on the detection of behavioral anomalies.

Advertisement. Scroll to continue reading.

In April 2015, the company launched a solution designed to detect threats within Industrial Control Systems (ICS) environments. The company said that its “Industrial Immune System” leverages Darktrace’s machine learning and mathematics in both operational technology (OT) and corporate environments to detect advanced cyber attacks and “subtle” insider threats targeting Industrial Control Systems, including SCADA (supervisory control and data acquisition) devices.

Founded in 2013 by senior members of the UK’ GCHQ and other intelligence agencies, DarkTrace is headquartered in Cambridge, UK and San Francisco, with offices in London, Milan, New York, Auckland, Boston, Chicago, Dallas, Los Angeles, Mumbai, Paris, Seoul, Singapore, Sydney, Tokyo, Toronto and Washington D.C.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

CISO Conversations

SecurityWeek talks to Billy Spears, CISO at Teradata (a multi-cloud analytics provider), and Lea Kissner, CISO at cloud security firm Lacework.

Cloud Security

Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Cybersecurity Funding

Network security provider Corsa Security last week announced that it has raised $10 million from Roadmap Capital. To date, the company has raised $50...

Network Security

Attack surface management is nothing short of a complete methodology for providing effective cybersecurity. It doesn’t seek to protect everything, but concentrates on areas...

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...