From: eSecurityPlanet.com

Former U.S. Defense Department official raises $26 million to fund a new type of cybersecurity technology.

By Sean Michael Kerner

Are there enterprise IT lessons to be learned from how the U.S. military approaches cybersecurity? Yes, according to a startup called Shape Security.

The co-founder of Shape Security, Sumit Agarwal, spent 14 years in the U.S. Air Force Reserve and was the deputy assistant secretary of Defense for the Obama administration in 2010. Agarwal’s military experience led him to help found Shape Security, a company that today is announcing a new $20 million round of funding. In total, Shape Security has raised $26 million to bankroll its military-inspired view of Web security.

“We’re taking major viewpoints of what the future will hold, from a Department of Defense, military perspective and recognizing that those are the same kinds of issues and challenges that regular businesses working on the Internet will face going forward,” Agarwal told eSecurity Planet. “It’s a much more sophisticated military-grade of security being made available to the business world.”

In describing what Shape Security is trying to achieve, Agarwal commented that the Department of Defense does not expect Americans to defend the airspace above their places of business. “Ironically enough, the same is not true in cyberspace,” he said. “On the Internet, you may be the target of organized crime or nation-state exploitation that is not reasonable for you as a business to defend against.”

Agarwal argued that it’s not reasonable to expect an average American business to defend itself against a nation-state attack. In his view, there is a need for more sophisticated cybersecurity with military levels of expertise.

New Attacks, New Cybersecurity Approach

Shape Security’s technology is going after a number of different types of challenging attack vectors. At the top of the list are attacks that appear to be coming from legitimate sources of traffic. These could be attacks that come from end-points or customers that are unwitting participants. It’s a type of attack where one moment the interaction is with the real customer and in the next moment it’s with a malicious agent on the customer’s machine.

“Distributed botnet-based attacks with large numbers of compromised end-points, many of which overlap with your current or future customers, are the most difficult types of attack to deal with, and that’s where we’re focused,” Agarwal said.

The traditional sentries of enterprise IT defense, including firewall and IPS devices, are still essential in Agarwal’s view. That said, he noted that both military and enterprise IT security experts have long preached the merits of an in-depth security strategy.

“We’re looking at a new segment of attacks that look like normal expected user behavior,” Agarwal said. “It’s not jimmying the lock, it’s walking in along with all of the other good traffic.”

Read Complete Article