查看原文
其他

通过无代码区识别恶意代码 Solebit 获融$1100万

Kevin Townsend 网络安全投资 2021-08-07

- 网安创企融资/投资人合作 加微junshao -

【180316 securityweek】Tel Aviv-based cyber-attack prevention firm Solebit Labs, currently establishing new global headquarters in Silicon Valley, has announced completion of an $11 million Series A funding round led by ClearSky Security.


Solebit was founded in 2014 by Boris Vaynberg, Meni Farjon, and Yossi Sara -- all of whom graduated from Israel's IDF technology units. The funding announced today will be used to accelerate adoption and deployment of the SoleGATE Security Platform from the new headquarters in Silicon Valley.


SoleGATE is an attack prevention system that can be used as a replacement or alternative to traditional endpoint protection systems. Such systems typically rely on either malware signatures or malware behavioral analysis engines -- with or without benefit of machine learning AI algorithms-- to detect malware; and both of these approaches can be evaded by zero-day fileless attacks. 


SoleGATE is an attack prevention system that uses neither signatures nor behavioral analysis to detect malicious code before it enters the network. Instead, it creates a logical 'no code zone' that inspects every data stream for executable code, no matter how encrypted or hidden. By inspecting every data stream, malicious code has nowhere to hide, and cannot evade detection. Solebit claims that it has a false positive rate of less than 0.002%.


“Attackers still possess the edge, particularly in zero-day attacks, despite considerable security investment,” said Vaynberg, CEO of Solebit. “DvC (Solebit's patent-pending inspection engine) assumes that there is no legitimate reason for executable code to be present in any data file. DvC also accurately identifies and blocks malicious active content using advanced flow analysis, de-obfuscation techniques and deep content evaluation, to reveal threat intent within any data file covering machine, operating system and application levels, thereby rendering such sandbox-evading malware harmless to the enterprise.”


SoleGATE is a virtual appliance that can analyze data streams at high speed. For large companies, "SoleGATE supports both vertical and horizontal scaling," Vaynberg told SecurityWeek. "Each SoleGATE virtual appliance can scan many files concurrently (based on number of CPU cores dedicated to the virtual appliance) and customers can use multiple SoleGATE instances working in Active-Active mode." 


The technology is closer in concept to Content Disarm and Reconstruct (CDR) solutions than it is to standard malware detection products -- but still has fundamental differences. "The SoleGATE DvC engine analyzes the binary content of each scanned file and reaches a conclusive verdict regarding the file, whether it is malicious or not. It covers a wide range of file formats, does not change anything in the scanned file and, of course, there is no effect on user experience," explained Vaynberg. 


"CDR, however, is reconstructing the file, assuming that reconstruction will remove any malicious payload. This technology is generally limited in the number of supported file formats, and it can affect user experience since it is actually altering the file the user receives."


SoleGATE does not create signatures for files or malicious behavior -- all data streams are inspected as if never before seen. Nor does it share or export any data from the customer's environment -- eliminating, for example, the sequence of events that triggered Kaspersky Labs' issues with the US government. In that instance, it is thought that files exported from an NSA contractor's home computer for Kaspersky malware analysis somehow alerted Russian intelligence services to the presence and location of those sensitive files; which were later obtained by hacking the contractor's computer.


SoleGATE does, however, provide IoCs to the customer, "in order," said Vaynberg, "to leverage the customer's entire security stack based on SoleGATE's unique detection." He added, "SoleGATE also supports malicious links detection and prevention. It provides customers with prevention against links that lead to malicious web pages or malicious files to be downloaded from the web. A phishing web page that seeks to socially engineer user credentials will be supported later."


"Solebit provides the most effective, real-time, and accurate cyber-attack prevention platform that is incredibly simple to use, integrate and manage,” said Peter Kuper, Managing Director, ClearSky Security. “As organizations struggle to better manage risk against unknown threats, Solebit is ideally positioned to be a trusted partner to both enterprise and large-scale security vendors as they contend with ever increasingly sophisticated attackers."

更多网安创投资讯                                   

【安全检测】开源软件安全 Snyk获融$700万

【企业并购】PhishMe被$4亿收购并更名Cofense

【企业并购】Splunk以$3.5亿收购Phantom

【Web安全】Netsparker获$4000万融资

【网安众测】 Bugcrowd 获得$2600万C轮融资

【数据安全】顶象宣布获过亿融资 嘉实投资领投

【产业并购】Google宣布计划收购IoT创企Xively

【产业并购】甲骨文收购云安全创企Zenedge

【网络安全】实时未知威胁防御 Vectra获融$3600万

【云安全】以插件代位WAF Templarbit获融$300万

【IoT】SAM获$350万种子轮融资

【反欺诈】Proofpoint$2.25亿并购反钓鱼创企Wombat

【数据安全】基础设施安全创企 Aperio获融$450万

【数据安全】帮助企业应对GDPR BigID获$1400万融资

【IoT】轨道交通网安 Cylus获$470万融资

【智能安防】车载安全摄像头Owl获$1800万融资

【数据安全】隐私保护 D-ID获$400万种子轮融资

【云安全】应用层安全 Tigera获$1000万融资

【端点安全】混合架构协调效率与安全 Hysolate获$800万融资

【数据安全】DLP创企Allure获$530万种子轮融资

【智能安防】巡逻机器人Knightscope获$2500万融资

【身份认证】芯盾时代获¥1.2亿B2轮融资

【区块链】硬件钱包 Ledger获$7500万B轮融资

【数据安全】Baffle获$600万A轮融资

【智能安防】印度智能门禁myGate获$250万首轮融资

【IoT】以色列创企VDOO获83North $1300万投资

【威胁情报】SaaS平台Anomali获$4000万D轮融资

【安全管理】外包SOC服务 Arctic Wolf获$1600万融资

【IoT】AI工控安全 Nozomi获$1500万B轮融资

【威胁检测】四叶草宣布获¥6700万A轮融资

【IoT】韩企Security Platform获软银$278万投资

【智能安防】小兔开门宣布获¥500万Pre-A轮融资

【漏洞扫描】安赛科技宣布获腾讯¥1亿投资

【安全管理】AlgoSec获$3600万融资

【威胁情报】亚马逊欲收购威胁防护平台Sprrl

【数据安全】泰雷兹以$57亿收购SIM卡厂商金雅拓

【网络安全】四维创智获华耀资本¥千万级融资

【区块链】虚拟币安全 BitGo获$4250万B轮融资

【IoT】云车联网安全 Upstream获$900万A轮融资

【云安全】软件定义安全 ShieldX获$2500万B轮融资

【IoT】防护80亿个IoT终端 Cog获$350万A轮融资

【云安全】反恶意威胁云平台 Menlo获$4000万C轮融资

【区块链】代理二次认证 NuCypher获$430万融资

【网络安全】蝎子网络获数千万元A+轮融资

【工控安全】SCADAfence获$1000万A轮融资

【反欺诈】反钓鱼 IRONSCALES获$650万A轮融资

【移动安全】实时APP防护 Prevoty获$1300万B轮融资

【二级市场】银基安全拟通过新三板融资¥1200万

【威胁情报】暗网情报创企Terbium获投$600万

【智能安防】家庭安防创企Minut获投$250万

【物联网】基础支撑平台Ayla获投$6000万

【物联网】Tortuga Logic获融$200万打造芯片级安全

【日志分析】AI驱动Logz.io获$2300万C轮融资

【威胁情报】ThreatQuotient获$3000万C轮融资

【智能安防】AI视频监控平台 博思廷获融¥3000万A+轮融资

【容器安全】NeuVector获$700万A轮融资

【邮件安全】Proofpoint以$1.10亿收购Cloudmark

【工控安全】Enview通过AI及3D技术监控老旧管线获$600万A轮融资

【威胁情报】EclecticIQ获€1400万B轮融资

【二级市场】360拟以¥504亿借壳江南嘉捷回归A股

【智能安防】Face++获$4.6亿C轮融资

【暗网监控】Recorded Future获$2500万E轮融资

【数据安全】Trilio获$500万A轮融资

【物联网】ForeScout通过IPO融资$1.16亿

【反钓鱼】KnowBe4获$3000万B轮融资

【风控】攻击可视化分析创企Skybox获$1.5亿融资

【NAC】网络访问控制创企ForeScout上市融资$1.16亿

【物联网】AI助力摄像头安全 Flare获融€340万

【身份认证】双重认证创企Duo获$7000万D轮融资

【网安测评】SecurityScorecard获诺基亚$2750万C轮融资

【风控】同盾科技获$7280万C轮融资

【终端安全】火绒获天融信¥1500万Pre-A轮融资

【身份认证】人工智能创企Onfido获$3000万融资

【身份认证】谷歌收购统一身份管理创企Bitium

【身份认证】区块链生物认证创企HYPR获$800万A轮融资

【威胁防护】实时防护创企Capsule8获$600万A轮融资

【容器安全】Aqua Security获$2500万B轮融资

【移动安全】指掌易获¥1.5亿A+轮融资

【暗网防护】Digital Shadows获$2600万C轮融资

【反病毒】在初始阶段阻止病毒,AppGuard获3000万美元B轮融资

【云安全】炼石网络获¥3000万Pre-A轮融资

【数据安全】观安信息获¥5000万A轮融资

【每周五为您同步全球网安投融大事】

    您可能也对以下帖子感兴趣

    文章有问题?点此查看未经处理的缓存