8 comments

[ 2.7 ms ] story [ 26.3 ms ] thread
Founder here; happy to answer questions about how this works. Reach out to ryan@traversalnetworks.com if you want to chat privately.
Hi Ryan, can you explain a little about what makes your service different from that offered by other companies in the industry? (Dell, Cisco etc).
We started out with the idea that companies don't want to manage these devices (fortinet, dell, etc), and designed a new IDS from the ground up with this is mind.

Its too hard to find good security people to do low end triage and analysis and the products mentioned above weren't designed to be cloud managed.

We employ good security people who review alerts across our entire infrastructure, so we get better as we grow.

Thanks for the reply!

I meant to ask specifically what differentiates your service from the "remote security/SOC/monitoring/etc" services offered by other companies?

I agree about finding good staff for sure. I work in the security industry and I don't know anyone that's NOT struggling to find even mediocre staff.

Edit: I guess the custom-developed SIEM is a differentiator actually.

So, is the primary model here to be an IDS / IPS vendor? It seems like that? http://traversalnetworks.com/product

What kinda tech are you using?

We're starting out with something that resembles a managed IDS/IPS but built with the things I wanted after building an IPS product @symantec. Better search, cloud managed, and tuned / triaged / and alayzed by our analysts.

Right now its built on-top of Bro and using tech from Gravitational (www.gravitational.com)

IMO this level of threat detection is not that useful anymore, detection needs to occur closer to the kernel level per machine
There are thousands of startups, large companies and product vendors doing this type of work, what is the specific differentiation that would make someone choose this over others?

Having worked in the managed security space, and both created products that did exactly what this is professing to do and working with others, I don't see how this is very different.