Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Darktrace adds early warning system to Antigena Email

Security

Darktrace adds early warning system to Antigena Email

Cambridge based Darktrace has added an early warning system to its Antigena Email product, allowing members of the Darktrace community to contribute and benefit from insights gleaned from across the fleet.

Above: Jack Stockdale OBE, Darktrace CTO.
Courtesy Darktrace

This new capability is now available to Antigena Email users and includes the extension of anonymised, learned domain behavioral profiles across Darktrace’s expansive and diverse group of global customers.

“Darktrace stops all kinds of cyber-attacks against organizations in every sector in over 110 countries globally. That represents a huge bank of knowledge about how malicious payloads behave in the very earliest stage of a cyber-attack,” commented Jack Stockdale OBE, Darktrace CTO. “Antigena Email has now realised the vision of leveraging collaborative, anonymised insights to leave attackers with nowhere to hide.”

Advertisement
Marshall RT 2

Ninety-four per cent of cyber-attacks begin in the inbox. As organisations continue to rely on email as a primary workplace collaboration tool and attacks become increasingly novel and sophisticated, email security technologies that rely on behaviour rather than threat intelligence become more imperative.

Darktrace’s Self-Learning AI observes emails to build bespoke behavioral profiles for each customer and leverages these behavioural profiles, rather than a ledger of binary ‘good’ or ‘bad,’ to accurately determine whether each email belongs in a recipient’s inbox. Antigena Email uniquely analyses domains within email addresses and links in email bodies and attachments to evaluate their popularity and typical presence in the inbox.

Now, when Antigena detects unusual domain behavior in a customer environment, a supplementary interpretation can be made by comparison with this new fleet-wide version of the behavioural profiles. This new functionality can lead to increased suspicion, for example, of a potential account compromise when a fleet-wide popular domain suddenly strays from its usual behavioural patterns – even in a trusted supplier or vendor.

This update recently allowed Darktrace to stop a phishing campaign sent from a compromised government account in South America that was soliciting fake philanthropic donations. Although the government domain was legitimate, the attacker had inserted their own 'reply-to' address into the email headers. This address had zero domain precedent locally or globally and, in combination with other indicators, led Antigena Email to flag this email as suspicious.
 

 

Advertisement
ODU RT

 

 

 

Advertisement
L3Harris L3Harris
BSI updates SAPIENT standard

Defence Security

BSI updates SAPIENT standard

26 April 2024

Sensing for Asset Protection with Integrated Electronic Networked Technology (SAPIENT) was developed by the Defence Science and Technology Laboratory (Dstl) and first published as a British Standards Institute (BSI) standard in July 2023.

New powers to seize criminal cryptoassets go live

Security

New powers to seize criminal cryptoassets go live

26 April 2024

Greater powers for the National Crime Agency (NCA) and police to seize, freeze and destroy cryptoassets used by criminals have come into force today.

NCA and European Police Chiefs call for public protection across tech platforms

Security Events

NCA and European Police Chiefs call for public protection across tech platforms

26 April 2024

The Director General of the National Crime Agency (NCA) General Graeme Biggar and European Police Chiefs, are calling for industry and governments to take urgent action to ensure public safety across technology platforms.

Most dangerous electronic items passengers take on planes revealed

Aerospace Security

Most dangerous electronic items passengers take on planes revealed

26 April 2024

The number of lithium battery fires on planes continues to rise but the personal electronic items which cause the most problems can now be revealed.

Advertisement
ODU RT 2
AST Networks acquires Reygar

Security

AST Networks acquires Reygar

25 April 2024

AST Networks has expanded its ecosystem further through the acquisition of Reygar Ltd, an award-winning provider of fully integrated performance monitoring and control solutions for crewed and uncrewed vessels, to form AST Reygar.

PPM Systems enables 5x increase in detection range

Defence Security Events

PPM Systems enables 5x increase in detection range

25 April 2024

Swindon based PPM Systems are increasing observational antenna radius by solving signal distribution limitations.

Advertisement
Marshall RT