ATLANTA & WALTHAM, Mass—Oct. 21, 2014—Damballa, the experts in advanced threat protection and containment, and Bit9® + Carbon Black®, the leader in endpoint threat prevention, detection and response, today announced a partnership and technology integration that enables Damballa Failsafe infection notifications to be correlated with the recorded history of endpoint activity from Carbon Black, to aid and improve response times in investigation, remediation, and response. Damballa also has joined the “Bit9 + Carbon Black Connect” Alliance Partner Program.
Damballa Failsafe is an automated breach defense system that leverages multiple techniques to detect true positive infections, terminate their activity and give responders the ammunition needed to rapidly prevent loss. Failsafe delivers actionable information about known and unknown threats regardless of the infection’s source, entry vector or OS of the device. It arms responders with definitive evidence so they can rapidly prevent loss on high-risk devices while blocking activity on the rest.
Built by leveraging Carbon Black’s open API, the Damballa Failsafe Connector for Carbon Black enables responders to rapidly determine additional attributes of the malicious activity, speeding up infection discovery on other devices, including those not on the enterprise network. Utilizing threat intelligence from both Failsafe and Carbon Black, risk and prioritization can quickly be established, dramatically reducing the time needed to positively identify infected devices, reducing the infection’s dwell time, and improving overall incident response time and security posture.
“To correlate seemingly disparate security events and catch attacks that span both of these layers, security and risk pros must integrate the network and endpoint layers wherever possible, focusing on integrated data analysis and coordinated blocking/remediation,” wrote Rick Holland, Chris Sherman and John Kindervag, in a March 2014 Forrester Research, Inc. report (Holland, Sherman, Kindervag, March 2014).
“Network and endpoint security solutions are typically purchased by different teams within the enterprise, but are increasingly being asked to work together to enhance the value from each, and share intelligence for the greater good,” said Paul Rolfe, VP of Global Alliances and Channels for Damballa. “By integrating with Carbon Black, Damballa is enabling enterprises to truly choose the best-of-breed network and endpoint protection, for organizations looking to improve their security posture and enhance the value received from both technologies.”
“The Failsafe and Carbon Black integration is a force multiplier, bringing together network discovery and investigation with our recorded history of endpoint activity,” said Tom Barsi, vice president of business development for Bit9 + Carbon Black. “Enterprises benefit from a checks and balances system by purchasing from different vendors, but can now also receive shared intelligence across our products, enabling them to coordinate remediation across the enterprise.”
To learn more:
Damballa and Bit9 + Carbon Black will present a joint webinar on October 30th for Breach Week 2014. With Halloween the next day, there’s no better time to protect against the Goblins that seek to infiltrate enterprise networks. Together Failsafe and Carbon Black offer a robust Detect and Respond solution. Discovering hidden infections on the network, and using Carbon Black to offer the highest fidelity and confidence in your response. The combined threat intelligence and attributes allow proactive improvements to prevention controls, such as new IOCs for IDS/IPS, new rules for NGFW and WSG to improve prevention against future attacks.
About Damballa
As the experts in advanced threat protection and containment, Damballa discovers active threats that bypass all security prevention layers. Damballa identifies evidence of malicious network traffic in real time, rapidly pinpointing the compromised devices that represent the highest risk to a business. Our patented solutions leverage Big Data from the industry’s broadest data set of consumer and enterprise network traffic, combined with machine learning, to automatically discover and terminate criminal activity, stopping data theft, minimizing business disruption, and reducing the time to response and remediation. Damballa protects any device or OS including PCs, Macs, Unix, iOS, Android, and embedded systems. Damballa protects more than 400 million endpoints globally at enterprises in every major market and for the world’s largest ISP and telecommunications providers. For more information, visit www.damballa.com, or follow us on Twitter @DamballaInc.
About Bit9 + Carbon Black®
Bit9 + Carbon Black offers the most complete solution against the advanced threats that target your organization’s endpoints and servers. This makes it easier for you to see—and immediately stop—those threats. Carbon Black’s lightweight endpoint sensor, which can be rapidly deployed with no configuration to enable detection and response in seconds, combined with Bit9’s industry-leading prevention technology, delivers four key benefits:
Thousands of organizations worldwide—from 25 Fortune 100 companies to small businesses—use Bit9 + Carbon Black to increase security, reduce operational costs and improve compliance. Leading managed security service providers (MSSP) and incident response (IR) companies have made Bit9 + Carbon Black a core component of their detection and response services. With Bit9 + Carbon Black, you can arm your endpoints against advanced threats. For more information, visit www.bit9.com.
Bit9 and Carbon Black are registered trademarks of Bit9, Inc. All other company or product names may be the trademarks of their respective owners.