Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    ShapeShifter Offers Polymorphic Defense for Web Attacks

    Written by

    Sean Michael Kerner
    Published January 24, 2014
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      After more than a year of operating in stealth and more than $20 million invested in research and development, Shape Security emerged out of the shadows this week to debut its ShapeShifter technology. The basic idea behind ShapeShifter is to constantly shift the attack landscape that is available to an attacker in a bid to minimize risk.

      Shape Security first hinted at its efforts in January of 2013, when the company announced a $20 million round of funding.

      Company co-founder Sumit Agarwal, who was the Deputy Assistant Secretary of Defense for the Obama administration in 2010 and served for 14 years in the U.S. Air Force Reserve, told eWEEK that Shape Security’s thesis is that there is a whole new class of attacks that have emerged that abuse the front door of Websites through automated attacks. It’s a class of attack that rides along with legitimate traffic, making it difficult for current forms of Web security to defend against.

      “We have created something that changes Websites into a constantly changing target, which breaks the vast majority of attempts of automated scripted attacks,” he said.

      Attackers have used similar approaches by constantly adjusting malware to evade signature-based detection methods, according to Agarwal. Now the tables have turned, and Websites can constantly adjust to avoid attack. Shape Security refers to its approach as real-time polymorphism.

      How It Works

      From a practical use-case perspective, the Shape Shifter technology does not actually block specific attacks—for example, a SQL Injection action. Rather, it makes it more difficult for an attacker to find code to exploit.

      In a typical large-scale SQL Injection attack, an automated attack tool is first used to spider or index a target for all input fields and try a number of known SQL exploits, Agarwal explained. Once the automated attack tool gets some form of response from the tool to the SQL query, a manual attack needs to happen. With the Shape Shifter technology, since the Website code is constantly shifting, when the attacker comes back, the same code injection route is likely not going to be available.

      “When all of the attacker’s reconnaissance gathering information is useless, cause you can’t go back to a page and find the same form, we have not directly prevented the SQL Injection from going through, but we have destroyed in practice how the attack would be perpetrated,” he said.

      The ability to customize and change a given Website for user preferences, for example, is not a new thing, and it is typically achieved with the use of Cascading Style Sheets (CSS) to adjust the look of a Website. Agarwal stressed that simple CSS modification is not what ShapeShifter does.

      “This is very involved technology. It’s technology that involves all of the HTML/JavaScript and CSS that has to be modified and changed in unison,” he said. “So everything is adjusted and modified in ways that are specifically designed to foil every measure and counter-measure that an adversary might try, while still preserving the functional aspects of the site.”

      From a network deployment perspective, ShapeShifter technology is deployed in line with the data flow and is designed to work with load balancer technologies. The goal is to limit any performance impact on a live Website to something that is undetectable to most humans, which Agarwal said is in the range of 20 to 40 microseconds.

      There are multiple other approaches in the security market today that try to deceive attackers from finding their targets. One of them is Juniper’s Web App Secure technology, formerly known as Mykonos, which aims to deceive attackers with a variety of techniques. Agarwal said that Shape Security is similar to other approaches in that it wants to reduce the risk of Web attacks, though he stressed that how Shape Shifter works, with its approach of rewriting Websites to deflect attackers, is fundamentally different from other approaches.

      The initial Shape Shifter technology release is being made available as a hardware platform from Shape Security. Agarwal declined to comment on the specific components included in the box, other than that its commodity gear from leading vendors. Moving forward through 2014, the plan is to make the technology available for use as a virtual appliance that can be used in virtualization deployments.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.