Security App Modeled After Immune System

Security App Modeled After Immune System

Written By
Dennis Fisher
Dennis Fisher
Feb 3, 2003
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The security industry has always looked to the field of medicine for metaphors and ways of thinking about network protection. Now, Sana Security Inc., a San Mateo, Calif., start-up, is extending that relationship to another level with the introduction Monday of its Primary Response application security platform.

The software works by observing application-operating system interactions and learning the code paths that each application uses during its normal operations. The system develops a profile of each applications behavior and then blocks anything that falls outside that profile.

As a result, the system produces a remarkably low number of false positives—as few as two or three per month in some customer environments.

The concept was taken from the human immune systems ability to recognize potential infections and begin defending against them before they reach their intended targets. The software is the brainchild of Steven Hofmeyr, Sanas founder and chief scientist, who came up with the idea while doing research for his doctoral thesis.

Although the concept is somewhat similar to several other systems on the market—notably those sold by Okena Inc.—there is one key difference, Hofmeyr says: Sana does not rely on a human to define the acceptable behavior for each application.

“They assume that theres some human out there with sufficient knowledge to recognize the attacks and know what to do,” Hofmeyr said. “Weve assumed the human wont understand.”

Primary Response relies on a server-agent architecture and is meant mainly for servers handling Web, FTP and Domain Name System traffic. However, it can also protect custom applications.

Once an attack is detected and blocked, the system functions much like other security applications. It sends an e-mail alert to the administrator and logs the event in a central management console. The system also includes a set of analytics to help identify trends and dig deeper into each event.

Primary Response is due to ship in mid-March on the Windows and Solaris platforms; Linux and AIX versions are in the works. One server license costs $6,500 and each agent is $1,750.

  • Read more articles by Dennis Fisher
  • Read more security stories
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.