Intrusion-detection start-up focuses on anomaliesStart-up System Detection this week will make its debut with software the company says stands apart through its use of analytics for defining and categorizing threats and attacks coming from the Internet and inside the corporate LAN.The company’s Antura product includes three components – the Recon Internet gateway, LAN-based Monitor sensor and Threat Management Center management console – that work together to give companies a feel for where threats and attacks originate and to help them prioritize their response.Antura, which customers install on Linux-based machines, relies on anomaly detection. With anomaly detection the devices can analyze suspicious behavior based on patterns and knowledge rather than signatures of known attacks. System Detection faces the hard task of distinguishing itself in what Synergy Research Group says is a $145 million market so far this year for intrusion-detection and intrusion-prevention systems (which use IDS intelligence to block attacks not just watch for them). The biggest player in this segmented market is Internet Security Systems, although Lancope is probably among System Detection’s closest competitors.“It’s a very crowded field and this type of anomaly based IDS is tough to test because you’re trying to prove you can find what may be a threat that’s unknown and not based on a signature,” says Pete Lindstrom, an analyst with Spire Security. But with false positives still a problem among many products, he says the door isn’t closed to newcomers with fresh ideas. Antura, which starts at $20,000, isn’t necessarily intended to replace signature-based IDS offerings that customers might already use, according to Dale Gardner, System Detection’s vice president of marketing.“[Existing IDS products] may do a good job of telling you about threats you already know, but Antura is detecting anomalies based on 68 different attributes, such as the man-in-the-middle attack, for instance – someone trying to insert themselves into an active session,” he says.The start-up was founded by Columbia University computer-science professor Salvatore Stolfo, who has a background in network anomaly detection research that was funded with a Defense Advanced Research Projects Agency (DARPA) grant, Columbia University owns the rights to the anomaly detection technology developed under the DARPA grant, but has licensed it exclusively to System Detection. The company has 24 employees and $7 million in funding from Metropolitan Ventures and Novak, Biddle Venture Partners.Analysts say the company, would do well to crack the government market. The company might have a shot, given the background of CEO and President Harvey Weiss, the former head of research and engineering company SAIC and a veteran in government sector-oriented divisions at Digital, Trusted Information Systems and Unisys” Lindstrom says. Related content opinion Is anything useful happening in network management? Enterprises see the potential for AI to benefit network management, but progress so far is limited by AI’s ability to work with company-specific network data and the range of devices that AI can see. By Tom Nolle Nov 28, 2023 7 mins Generative AI Network Management Software brandpost Sponsored by HPE Aruba Networking SASE, security, and the future of enterprise networks By Adam Foss, VicePresident Pre-sales Consulting, HPE Aruba Networking Nov 28, 2023 4 mins SASE news AWS launches Cost Optimization Hub to help curb cloud expenses At its ongoing re:Invent 2023 conference, the cloud service provider introduced several new and free updates that are expected to help enterprises optimize their AWS costs. By Anirban Ghoshal Nov 28, 2023 3 mins Amazon re:Invent how-to Getting started on the Linux (or Unix) command line, Part 4 Pipes, aliases and scripts make Linux so much easier to use. By Sandra Henry-Stocker Nov 27, 2023 4 mins Linux Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe