Damballa (company)

For the Vodou spirit, see Damballa.
Damballa
Corporation
Industry Computer security
Founded 2006
Founder Merrick Furst, Wenke Lee, David Dagon, Richard Lipton
Headquarters Atlanta, GA, United States of America
Key people
David Scholtz; Tom Savini; Stephen Newman; Paul Rolfe; Ron Wilson; David Fortune; Julie Preiss
Products Advanced Threat Protection
Website https://www.damballa.com

Damballa is an American computer security company focused on advanced cyber threats such as zero-day attacks and advanced persistent threats (APT).[1][2] The company’s system uses massive data sets and machine learning to identify malicious activity based on network behavior, content analysis and threat intelligence. The system constantly “trains” on new data, which enables it to detect previously unknown threats.

Damballa was acquired by Core Security Technologies in July 2016 for $US 9 million, a significant loss on the $US 60 million in funding it had received.[3]

Origins

Damballa was founded in 2006 in Atlanta, Georgia by Merrick Furst, an associate dean in the Georgia Institute of Technology (Georgia Tech) College of Computing;[4] he was joined by two Georgia Tech colleagues, Wenke Lee, and David Dagon.[5] The company is named after Damballa, a Vodou snake god[6] that protects against zombies, with the implication that Damballa protects against “zombie” computers operating as part of botnets. According to its site, Damballa now seeks primarily corporate clients and ISP.

Funding

In April 2014, Damballa secured $US 13 million from its existing investors to grow sales and marketing efforts along with global expansion.[7] Since the company was founded in 2006, Damballa has raised a total of $US 57.5 million in venture capital funding led by the following firms: Sigma Prime Ventures; InterWest Partners; Palomar Ventures; Paladin Capital Group; and, Adams Street Partners. Additional investors include: GRA Venture Fund; Noro-Moseley Partners; and, Imlay Investments.[4][8][9]

Offerings

Damballa’s current product offerings are:

Advanced Threat Protection

Damballa's advanced threat protection solution for enterprises, Damballa Failsafe detects successful infections with certainty, terminates their threat activity, and gives incident response the intelligence needed to rapidly prevent data breaches. Damballa Failsafe is able to detection malicious files (malware) and track suspicious behavior over time in the network, delivering actionable information about known and unknown threats regardless of the infection’s source, entry vector or OS of the device. It provides incident responders with definitive evidence so they can rapidly prevent loss on high-risk devices while blocking activity on the rest.[10] It was recommended on the Advanced Threat Protection shortlist buyer's guide for 2015. [11]

ISP Subscriber Protection

Damballa CSP, which is designed for service providers and ISPs, identifies malicious activity originating from subscriber’s devices, whether PC, tablet or mobile. Damballa CSP sits out-of-band inside the service provider’s network and monitors DNS requests (non-PII traffic) from the subscriber’s IP address, which enables it to identify subscriber devices infected with advanced malware.[12]

Patents

In 2013, Damballa was granted its first two patents,[13] related to detecting advanced threats. Patent 8,566,928[14] describes methods for detecting a first network of compromised computers in a second network of computers, while patent 8,578,497[15] describes methods for analyzing domain names that are not registered that are collected from an asset in a real network.

In February 2014, the company was granted a third patent, # US20120198549, for its "Method and system for detecting malicious domain names at an upper DNS hierarchy", which describes a methodology for identifying potential malicious domain names used to propagate threats.[16]

See also

References

  1. Markoff, John (2007-01-07). "Attack of the Zombie Computers Is Growing Threat". The New York Times. Retrieved 2007-01-07.
  2. "Enterprise Botnet and Malware Detection". Damballa, Inc. Retrieved 2007-01-07.
  3. "Atlanta's Damballa sold for nearly $9 million - Atlanta Business Chronicle". Retrieved 30 September 2016.
  4. 1 2 "Startup Aims to Detect and Thwart Botnets". Nerd Twilight. 2006-08-17. Retrieved 2007-01-07.
  5. Wilson, Tim (2006-08-15). "Startup to Challenge Botnets". Dark Reading. Retrieved 2007-01-07.
  6. Rubner, Justin (April 7, 2006). "Tech spinoff gets $2.5M to go after 'zombies'". Atlanta Business Chronicle. Retrieved 2007-01-07.
  7. "Atlanta Internet security firm Damballa raises $13M". The Atlanta Business Chronicle. 2014-06-02. Retrieved 2014-06-01.
  8. "Internet Security Firm Lands $6M in New Financing". WRAL.com. 2007-08-29. Retrieved 2007-09-01.
  9. "The Daily Start-Up: Damballa Locks Down $15M Series E to Fight Cyberattacks". The Wall Street Journal. 2012-09-17. Retrieved 2013-09-05.
  10. "Advanced Threat Detection and APT Detection". Retrieved 30 September 2016.
  11. "Advanced Threat Detection Buying Guide". eSecurity Planet. 2015-09-03. Retrieved 2016-09-30.
  12. "Advanced Protection for Service Providers and their Subscribers - Damballa". Retrieved 30 September 2016.
  13. Jacques, Couret (2014-01-07). "Damballa adds two patents". Atlanta Business Chronicle. Retrieved 2 June 2014.
  14. Google, Patents. "Patent Search". Google. Retrieved 2 June 2014.
  15. Google, Patents. "Method and system for detecting malware". Google. Retrieved 2 June 2014.
  16. "Damballa Granted Third New Patent For Detecting Advanced Threats". Dark Reading. 2014-02-04. Retrieved 2014-06-02.
This article is issued from Wikipedia - version of the 10/8/2016. The text is available under the Creative Commons Attribution/Share Alike but additional terms may apply for the media files.