Live data from Hacker News

Cymmetria (YC S15) Uses Virtual Machines to Decoy and Detect Hackers

techcrunch.com

1–10 of 31 posts

Re: Cymmetria (YC S15) Uses Virtual Machines to Decoy and Detect Hackers

#2
Gadi Evron has been in the security industry for a long, long time. He's a malware/botnet/honeynets guy. Mile-long resume.

This is kind of a surprising pick for YC: a down-the-middle enterprise security play, the kind of company that usually gets funded by Battery because one of the cofounders successfully sold a portfolio company a couple iterations ago.

It's interesting to see what seems to be a pretty conventional bit of security technology (sandboxing malware and exploit code into virtual machines is the kernel of several 9-figure security products) get extra attention because of the YC pedigree. Or maybe TechCrunch just got this wrong? Either way: not complaining!

Re: Cymmetria (YC S15) Uses Virtual Machines to Decoy and Detect Hackers

#3
This is a solid idea with a great team behind it. The challenge with this kind of product is to make it easy to deploy while delivering actual value to users, and looks like they've figured that out.

(It was great meeting Gadi in the speakers lounge at a conference in Hamburg and doing the YC sales pitch last year.)

Re: Cymmetria (YC S15) Uses Virtual Machines to Decoy and Detect Hackers

#4
post #2

Gadi Evron has been in the security industry for a long, long time. He's a malware/botnet/honeynets guy. Mile-long resume. This is kind of a surprising pick for YC: a down-the-middle enterprise security play, the kind of company that usually gets funded by Battery because one of the cofounders successfully sold a portfolio company a couple iterations ago. It's interesting to see what seems to be a pretty conventional…

It's a fun twist on that conventional bit of security technology, though* . What I'm unsure of is whether these decoy-type products really provide much value beyond alert triage. Even if we're charitable and assume they don't introduce new false positives into the system, all the old false positives remain.

* Disclaimer: I manage one of those nine-figure security products you mention.

Re: Cymmetria (YC S15) Uses Virtual Machines to Decoy and Detect Hackers

#5
Mass market IT tech has been hacker heaven so far but better stuff isn't making many inroads. All these desktop, cloud, etc offerings don't have a hope of stopping determined attackers. Knowing this, industry mostly focuses on reducing risk, detection, recovery, etc. Honeynets are another great tool that's under-utilized in mainstream industry. They make the right assumption (they'll get in), the right goal (let's spot it), and add extra benefit (real damage maybe averted).

With that in mind, I'm liking what I see in the article. A true pro building on honeynet tech while maxing out ease of use and knocking out false positives. That last part is huge if he gets it right: too many just make people ignore the alarms. I look forward to seeing what it achieves in the field.

Like the names, too: Deception Stack, Maze Runner... good stuff haha.

Re: Cymmetria (YC S15) Uses Virtual Machines to Decoy and Detect Hackers

#6

Mass market IT tech has been hacker heaven so far but better stuff isn't making many inroads. All these desktop, cloud, etc offerings don't have a hope of stopping determined attackers. Knowing this, industry mostly focuses on reducing risk, detection, recovery, etc. Honeynets are another great tool that's under-utilized in mainstream industry. They make the right assumption (they'll get in), the right goal (let's sp…

No, honeynetwork research actually dominates academic security programs. It's problematic how much of it there is. Almost all of honeypot innovation comes from schools now. They're also the ones doing large-scale longitudinal studies done from honeynetwork and "network telescopes", in which universities like UCSD are enlisting BGP peering relationships to capture malware.

Re: Cymmetria (YC S15) Uses Virtual Machines to Decoy and Detect Hackers

#8
post #6

Mass market IT tech has been hacker heaven so far but better stuff isn't making many inroads. All these desktop, cloud, etc offerings don't have a hope of stopping determined attackers. Knowing this, industry mostly focuses on reducing risk, detection, recovery, etc. Honeynets are another great tool that's under-utilized in mainstream industry. They make the right assumption (they'll get in), the right goal (let's sp…

No, honeynetwork research actually dominates academic security programs. It's problematic how much of it there is. Almost all of honeypot innovation comes from schools now. They're also the ones doing large-scale longitudinal studies done from honeynetwork and "network telescopes", in which universities like UCSD are enlisting BGP peering relationships to capture malware.

I appreciate the correction. Edited the comment to reflect that. Weird how the field is fragmented enough that I can go through hundreds of INFOSEC papers (ACM, IEEE, conferences) without seeing hardly anything on honeynets then you see a flood of them in the sources you read. I expect a certain amount of this due to specialization but I think INFOSEC innovation is way too scattered compared to some fields. People end up missing key findings.

It's why I keep toying with the idea of a unified resource for INFOSEC professionals of all these fields. Collection of papers by category, tools, wikis, forum, and so on. Free or cheap to avoid exclusion the way ACM/IEEE/Springer end up causing. The wisdom of our field would be passed down more easily, all stuff in one category would be there with authors maybe discussing it, and different types of researchers would have higher chance of bumping into each other for cross-disciplinary advances. Pretty idealist, I know, but would be great if pulled off.

Epstein at NSF liked the idea but thought you'd need a ton of buy-in from Universities & private parties ahead of time. Haven't solved that one yet...

Re: Cymmetria (YC S15) Uses Virtual Machines to Decoy and Detect Hackers

#10
post #7

Hi all, Gadi here (CEO of Cymmetria). We are here on Hacker News and would be happy to answer any questions, technical or otherwise, and discuss.

How does it work, really? Do you provide a plausible-looking virtualized fake enterprise network that will look like a real thing to outsiders? Or do you put honeypot servers alongside other production servers, running whatever applications are really being used by the company? Do you intend to protect against inside threats as well?
Post reply on HN