Q1. AJ, what do organizations need to understand about identity deception and how to protect against it?
Identity deception is at the root of advanced email attacks, including account takeover, spear-phishing and business email compromise. The most common attack vectors are spoofing the email address, look-alike domains and display name deception. All of these attacks target the vulnerability of human perception by incorporating social engineering and publically discoverable information to craft convincingly authoritative messages, such as a fake request from a CEO impersonator to wire money to a fraudulent bank account. Traditional email security solutions, such as legacy secure email gateways are typically unable to detect these attacks because are no malicious content, such as malicious attachments or malicious URLs.
Artificial Intelligence is the solution. As a next-generation secure email cloud, Agari has global telemetry data of more than two trillion emails each year, which generate more than 300 million machine learning signals on a daily basis to create trusted identity graphs. Instead of trying to detect the bad, Agari first models the good and then detects deviations from it.
Q2. Mark, what do you see as some of the trends driving demand for email security technologies? What are some of the questions enterprises need to be asking when shopping for such tools?
As businesses navigate through their own digital transformation and embrace cloud and SaaS services, their attackable surface radius increases. Despite decades of technical development and billions of dollars of investment, cybercriminals are bypassing traditional defense systems by simply attacking the human part of your network and tricking people into trusting an email they shouldn't. It's a vicious Catch-22 in which a systemic lack of trust throttles growth.
The stats are shocking. Companies are three times more likely to get breached by identity-based attacks than actual vulnerabilities or malicious content. Phishing alone represents 98% of all identity-oriented attacks, and email is still the entry point 96% of the time. According to the FBI, BEC victim dollar losses are 50+ times more than malware and ransomware combined. Legacy security systems simply aren't working, because there's no malware or malicious content to detect. In short, we're facing an epidemic of identity deception—and it's costing us more than we know.
The impact is an erosion of our ability to rely on the very digital business processes that are meant to fuel our growth, revitalize our economy, and transform our industries. The real cost is a loss of trust in business, period.
It doesn't have to be this way. Agari's ingenious use of predictive AI to automatically detect and block these kinds of identity-based attacks is changing the game for individuals, businesses and government agencies of all kinds. No longer do we have to fall victim to impostors preying on our trust in each other.
Q3. AJ, how can behavioral analysis approaches help address existing and emerging email, and endpoint security threats in general?
Agari Identity Intelligence applies artificial intelligence in a unique way. Historically, the cybersecurity industry has spent decades and billions of dollars trying to anticipate, defend against and to recover quickly from what cybercriminals are doing. But the problem is it's nearly impossible to model what cybercriminals are doing in any meaningful way. And as soon as we figure out how to defend against one kind of attack, they adapt and change their approach. The malicious actors literally have a near infinite number of ways they can craft exploits to target any number of vulnerabilities. But Agari innovated a solution that instead uses predictive AI and machine learning to zero in on what known, trusted communications look and act like. In short, by modeling the good instead of modeling the bad, organizations and individuals can finally stop fighting a defensive, reactive battle and get one step ahead of cybercriminals.
Agari Identity Intelligence first engages in Identity Mapping, answering the question, "Who do we believe is sending this message?" Using machine learning, we examine a number of known "identity markers" such as the underlying email account, the display name and even the subject line. Second, we look at behavioral analytics, answering the question, "Does this message itself act like it came from this person?" The system analyzes 100+ aspects of an email's behavior, including its origin, destination, routing, time it was sent, etc., to detect signals of fraud. Third, the system conducts Trust Modeling to look at historical interactions between the real sender and recipient, and identify tell-tell signs that somebody is impersonating a trusted contact. All this is conducted in a fully automated, AI-driven solution that gets smarter every time it analyzes an email. Agari now analyzes more than 2 trillion messages each year and more than 50,000 new domains each day, and derives more than 300 million signals for our models daily.
Q4. Mark, what is Agari's main messaging focus at Black Hat Europe 2018?
Agari is on a mission to secure digital communications that ensure humanity prevails over evil. We fulfill this mission through the Agari Secure Email CloudTM -- a next-generation cloud that uses predictive AI to detect, defend, and deter costly attacks driven by social engineering, phishing, and Business Email Compromise. Legacy Secure Email Gateway (SEG) solutions have not adapted to the mass migration to cloud-native communications and new attack types based on identity deception. The next generation of email security controls requires context inspection for impostor defense, behavioral anomaly detection, automated post-delivery remediation, and AI-driven machine learning models.
The Agari Secure Email Cloud fulfills these requirements and also includes capabilities found in legacy SEGs, including URL analysis and attachment analysis. The remaining legacy SEG capabilities have been consolidated and commoditized into features of cloud email providers, including Office 365 and Google Suite. Agari provides the first, and only, advanced email security controls to protect the cloud inbox from advanced email attacks. In a cloud-first world, all you need is Agari Plus Office 365 or Google Suite.