How Does Cyphort Detect and Mitigate Threats?

TL;DR
Cyphort detects advanced threats by actively interrogating suspicious objects, correlating their metadata, and determining an adversary's intent. Its distributed software sensors can cover on-premises, cloud, hybrid, and remote-user environments, while centralized analytics, continuous monitoring, machine learning, APIs, and risk-based mitigation help organizations act on relevant threats without relying on appliance-based deployment.
Transcript
Cyphort, with the tagline, "Protection from the threats that matter." Please welcome up Ali Golshan. Hi. I'm Ali Golshan. I'm the CTO and co-founder of Cyphort. At Cyphort, we've built the first truly distributed software platform for pro- protection against advanced threats. But not just advanced threats, threats that genuinely matter to you, the ... Read More
Key Insights
- Cyphort is a distributed software platform designed to protect organizations from advanced threats that create meaningful risk. It focuses on understanding whether observed activity is malicious, what the adversary intends to accomplish, and which threats deserve action within the monitored environment.
- Active interrogation is Cyphort's alternative to relying only on static or behavioral analysis. The platform proactively examines observed threats to distinguish malicious activity from false positives and to determine the adversary's intent, providing more context about what the attacker is seeking inside an environment.
- Actionable intelligence is integrated with the broader infrastructure so findings can support mitigation. Cyphort's API-driven design allows the platform to understand contextual data and push mitigation into the customer's environment instead of leaving threat information isolated within a separate security product.
- Coverage is provided through software sensors that can be deployed across traditional and emerging technologies. The platform supports on-premises, cloud, hybrid, distributed, and remote-user environments, addressing visibility limitations associated with relying exclusively on physical appliances or cloud-only security solutions.
- Cyphort scales through clustering, allowing organizations to expand or reduce the distributed software deployment as requirements change. Centralized analytics and inspection work with software collectors placed throughout the infrastructure, including collectors that can receive data from an organization's existing file-carving or instrumentation systems.
- Machine-learning analysis is seeded with both malicious and clean samples. Cyphort captures each unique object passing through an environment, processes millions of samples, correlates metadata among objects, and abstracts the intelligence so it can be shared with other infrastructure without transferring the full threat context.
- Second Order Detection correlates network anomalies with techniques previously discovered by Cyphort. This model is intended to reduce false positives and false negatives for mobile phones, tablets, and other devices without requiring organizations to install an agent directly on each supported device.
- Cyphort's pricing is based on aggregated bandwidth rather than the number of appliances. This model allows customers to place sensors wherever additional coverage is needed, while risk-based mitigation is presented as a way to lower resolution costs and reduce dependence on large on-premises professional-services engagements.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How does Cyphort detect advanced threats?
Cyphort detects advanced threats through active and proactive interrogation rather than relying only on traditional static or behavioral analysis. It examines suspicious activity to determine whether it is malicious or a false positive, then seeks to identify the adversary's true intent and objective. Continuous monitoring also helps the platform learn from threats relevant to the organization and anticipate related threats that may emerge.
Q: How does Cyphort determine which threats matter?
Cyphort focuses on threats that present the greatest risk to a particular environment. Its analysis attempts to move beyond a simple malicious-or-benign classification by identifying what an adversary is trying to achieve. That understanding supplies context for risk-based mitigation, helping the organization prioritize relevant threats and reduce the cost and effort associated with resolving security incidents.
Q: Where can Cyphort software sensors be deployed?
Cyphort's software sensors can be deployed in traditional infrastructure, cloud environments, distributed systems, and hybrid configurations. The collectors can also extend coverage to users when they are connected to the corporate network or operating outside it. Because deployment is software-based and can scale through clustering, organizations can place sensors wherever additional visibility is required rather than purchasing an appliance for every location.
Q: How is Cyphort different from an appliance-based security product?
Cyphort is a distributed software platform rather than a product tied to dedicated appliances. Its collectors can be placed across data centers, cloud infrastructure, hybrid environments, and other locations while using a centralized analytics and inspection environment. The company also charges according to aggregated bandwidth instead of appliance count, allowing customers to distribute sensors more broadly without connecting coverage directly to the number of purchased appliances.
Q: How does Cyphort build and share threat intelligence?
Cyphort captures every unique object that passes through the monitored environment and processes millions of malicious and clean samples through its machine-learning systems. It then identifies correlated metadata among those objects. By abstracting the resulting intelligence, Cyphort can share useful findings with other existing infrastructure that needs the intelligence without requiring that infrastructure to receive the complete context associated with each threat.
Q: How does Cyphort integrate with existing security infrastructure?
Cyphort uses an API-driven architecture to connect its intelligence and mitigation capabilities with existing infrastructure. Organizations that already perform file carving or maintain their own instrumentation can submit data to Cyphort through a REST API. After analyzing the context, the platform can push mitigation back into the environment, allowing its findings to participate in existing security operations instead of remaining confined to a separate console.
Q: How does Cyphort inspect encrypted SSL traffic?
Cyphort is not positioned as an inline security solution, so it works with partners to address encrypted traffic. Its approach is to embed Cyphort collectors within partner appliances that can perform SSL interception. For an encrypted session, such as traffic going to Dropbox, the partner technology provides access to the intercepted content so Cyphort's collectors can contribute their analysis without placing the core platform inline.
Q: Does Cyphort require agents on mobile devices?
Cyphort does not require an agent on each mobile phone or tablet for the approach described. Its Second Order Detection model translates anomalies observed on the network and correlates them with techniques the platform has discovered. Cyphort states that this correlation can reduce false positives and false negatives across devices while avoiding the need to deploy an agent-based security solution directly on each device.
Summary & Key Takeaways
-
Cyphort presents a distributed software platform designed to detect and mitigate the threats that create the greatest risk for a specific environment. Its approach combines active threat interrogation, intelligence about adversary intent, broad sensor coverage, continuous monitoring, and integration with existing infrastructure to produce context-sensitive and actionable findings.
-
The platform uses scalable clustering and supports deployment on-premises, in cloud infrastructure, or through a hybrid model. Software collectors can be placed wherever coverage is required, while centralized analytics and inspection process their data. Organizations with their own file-carving or instrumentation capabilities can submit data through a REST API.
-
Cyphort captures unique objects moving through an environment and analyzes malicious and clean samples through machine-learning systems. It correlates metadata among those objects and abstracts the resulting intelligence for sharing with other infrastructure. Second Order Detection also correlates network anomalies with identified techniques to reduce false positives and false negatives without device agents.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator