Browser Security in the Enterprise with Seraphic Security’s Ilan Yeshua and Avihay Cohen
Seraphic Security CEO Ilan Yeshua and CTO Avihay Cohen explain why a different approach to browser security in the enterprise is now required following picking up an additional $28 million investment.
Transcript
This is Textron tv. Hey guys, thanks for the drill. We're here with Lan, Yeshua, and Avi Hi Cohen, who are both the CEO and the CTO for terrific and security, adding the security to the back end of that, make sure, um, and they're just recently raised $29 million in funding.
They address this nagging problem we've always had around browser security. So we're gonna jump into this in a second. Gentlemen, welcome to show.
Thank you. Nice to be here. Thank you.
All right, let's start with lan. What exactly is the problem we're trying to solve? 'cause I think I've been hearing about we're gonna solve this browser security problem now for more years than I care to count, and it never seems to quite get solved.
Some people say, you know, well, I've got this perfect browser over here, but nobody uses that browser. And other people say, well, we're gonna secure the browser that everybody uses, but it doesn't seem to never actually quite work out. So walk me through how we're solving this problem.
So, uh, uh, that's correct. I mean, the browser gradually became in recent year, the most dominant application in, in CO is, and it was mostly secure from the outside, either from the operating system or from the cloud. And, um, uh, the recent, uh, uh, emergence of this new, new category of enterprise browser security is actually coming to secure the browser from, uh, from inside, uh, because the existing solution don't have the necessary visibility and, uh, control, uh, inside the browser.
And, um, the new approach is actually, uh, uh, providing this, this, uh, visibility and control, therefore taking it at completely different level. Of course, important thing is that while you are doing it, you don't impact performance, uh, or any performance impact on the browser level will be intolerable. The one is ready to wait even a millisecond until the website is uploaded.
Avi, hi. Um, how did you get inside the browser? Because I think, you know, what Alan just said makes perfect sense, but how do you get in there and actually do the thing he just described?
Yeah, so Zi said the browser is highly complex, especially today. Web applications are coming extremely complex. Looking at it at the network level, for instance, no longer works.
So, um, we bring the capabilities, Zi said, the visibility and controls into the browser, and either through deployment, like an extension, which is local to the browser, no, uh, network inspection or SSL script, not none of that, uh, legacy, uh, tech. And if it's for instance, uh, BYLD or other unmanaged devices, uh, we bring the browser itself. So we always add the browser, uh, local to the user, uh, without the, uh, necessary like other legacy solutions that may require either an OS agent or, uh, uh, some form of a proxy, which as I said, uh, no longer wants.
But I wanted just to add, uh, uh, uh, regarding your question, how do we get this visibility and control in the browser? If I can elaborate about it more. But the uniqueness of our solution is actually that we are intimately involved with the JavaScript engine, which is the kind of the cannel of, of the browser, and, uh, having full execution context, how can elaborate a lot.
This is the uniqueness of our solution. Raffic is a deep tech, uh, company. We have about five patents and additional 15 in filing.
So we developed our own solution for JavaScript engine, and therefore, by the way, it's extended beyond browser also to any JavaScript and enable application, like all the model application teams, slack, et cetera. Which, which is making it very important because when you look today on the desktop, the modern desktop of of, of your, uh, welcome either employee or contractor, it is actually composed of multiple browser and multiple, uh, model application Hai. Is that a standalone browser that you created, or did you get inside, say Google Chrome or any of the commercial browsers, or where, when do I have to exactly deploy?
So since we have a, a native, uh, JavaScript agent that is capable of executing in every JavaScript enabled application like browsers, but not limited to browsers, um, we have the ability to also, uh, provide the commercial consumer based browsers, uh, while we actually, uh, infuse our tech into it. Also, we do have a commune based, uh, browser that, again, it's plain old commune, but we, uh, the addition of our unique agent, uh, fused into it. So we, we have, we, we actually enjoy in pretty much, uh, both worlds.
So we can provide a lightweight solution like an extension, uh, a, a hybrid one like, uh, commercial browsers fused with our tech or a full blown commune based, uh, enterprise browser, Alan, so if I upgrade my browser, do I have to upgrade your engine? Or how does that work? Or how do you keep that in a way that, um, makes it all feel seamless?
You don't have to upgrade and, and to add to whatever you high said, we, with us, you don't need to change the browser. You keep your native browser, your, your mainstream browser. We bring the security to the browser.
The browser is updated automatically by the vendors, and you don't need to update our solution. Aha. If you want to update here, uh, to, to, to, Yeah, I, I will just add that in order to add more context.
And when we look at the problem, we need to look at it in two, uh, different use cases. There is the managed, and there is the unmanaged managed, meaning corporate devices, managed devices. Uh, so you do want to protect the device, the endpoint.
In order to do so, you need to protect all browsers, right? On the unmanaged devices, it's a different story. There is, uh, uh, the device may be compromised, uh, um, and you just want to isolate the user interaction with the enterprise, uh, data in a way that is secure, even if the device is compromised.
Um, so our tech plays in both, uh, uh, walls allowing us to actually, uh, provide the feature parity in the same level of, uh, capabilities, uh, in both ways, including security, which are highly important to the, uh, managed devices. And, uh, using our unique tech and exploit prevention, we can actually, um, uh, prevent, uh, browser exploitation even from zero days and end days. So you don't necessarily need to update your browser, or it's not signature based.
It's based on a, um, tech called MTD moving target defense, meaning using randomization just like a SLR, uh, uh, without any detection. So just by randomizing and making the environment non-deterministic, we're actually able to prevent exploitation, meaning that even if your browser is outdated, which is pretty much a common practice among, uh, enterprises, they, they need to test new releases before they update, uh, their employees. So, um, we provide, uh, uh, prevention capabilities, uh, uh, a strong and robust protection for that gap, no matter wide, it is, uh, for the enterprise until, uh, the enterprise decides to update, uh, the browsers.
Uh, but it's not signature based. So there is no, uh, need for constant updates from our side, uh, for that specific engine. So, Alan, what's next from here?
What's the plan? I mean, you know, $29 million is still a big number, and I'm sure everybody, you know, applauded and maybe everybody got a couple of beers, but where are we going from here? More than a couple of beers, actually.
So, uh, you are right. I mean, I mean, the main effort, I mean, we have a material product, uh, now, uh, with, uh, about 70 customers already, large enterprises. There is a, a demand in the market.
The main, uh, um, uh, most of the proceeds will go first and foremost to, to increase, uh, and build our sales organization, sales and market organization in North America. We do have a sales team here that will realize in 24, otherwise we wouldn't have, uh, this, uh, uh, uh, round, obviously. Uh, so sales and marketing team in the us, uh, we already more than tripled the, the team in the last, uh, 45 days, but also to continue and support the r and d of the product.
As I indicated before, the, the, the main fault of raffic is the technology depth, and we have a very aggressive innovation roadmap for, for the product specifically. Now we are, we are, uh, releasing, uh, a new version that will, uh, obviously leverage on ai, uh, all the capabilities of AI on, on three aspects, and, and provide also enablement for, for organization as the browser is becoming, uh, actually also a gateway for ai, uh, users. So, so, so it's r and d enhancement and the go-to market.
These are the two main things. Hai, why didn't somebody else think about this approach before? What was kind of the aha moment for you?
So I think, um, enterprises look at the browser as a part of, mainly a feature of, uh, ssi, right? Uh, SW supposed to take, uh, uh, uh, and handle all traffic, including web-based browsers. So browsers until just a few years ago was not that widespread, and some applications, at least not the majority of ones, was native applications.
Now, the browser, the trend is always web-based. So many native applications become web-based, the application themself, um, become more and more complex. So looking at it, as I said, at the network level, is no longer enough, no context.
Um, traditional file uploads or file downloads are no longer the same. Um, so you need to be at the access point, at the access tool, the, the browser, um, in order to be in the browser. Now you have two approaches, either to be the browser or in some form, some, uh, uh, uh, agent on top of it.
Now, extensions will not, uh, uh, uh, something abnormal, right? They're quite common. It's not something new.
Uh, our approach is unique because the extension is just the delivery vector for us. It's injecting our agent. Um, and extensions are by itself highly limited in terms of APIs.
They don't have always level visibility. That's why no one, uh, pushed forward on extension only solutions. We have a unique tech that allows us to leverage the extension framework, although, uh, we are pretty much, uh, resilience against changes and stuff like that because our, uh, capabilities are not at the extension.
And, and since it's quite, uh, uh, unique and, uh, uh, generic approach, we can use the same agent in different, uh, methods and delivery mechanism. Extension is one of those, but it can happen in different ways. But in order to gain context and in order to handle the more complex web applications that other legacy solutions can't, you need to be at the browser in some way or form.
Uh, and we have that capability, including os level visibility. So we can provide feature parity and across, uh, different deployment methods. Ellan, last word on this, but the bad guys, you know, they, they're at work on all this stuff.
I mean, are they squarely focused on the browser? Is this their point of entry or how big a, a, a hole is This particular part of our extended attack service, Obviously what we see is, uh, uh, in enterprises that we made, we see a great demand. And usually, you know, the driver of the demand is breaches.
The breaches are, are the best friends of, of, uh, security vendors. And the breaches are, uh, on the rise in spite of the, uh, significant amount, uh, that, that, uh, enterprise are investing. And, and some of them have something between 50 to even 100 vendors, the type of security vendors providing to them their, their solution.
So obviously we don't have a big problem sitting with enterprises and, uh, uh, exploring with them, um, uh, gaps in browsers. So the statistic is talking for itself. Uh, uh, uh, 76% of ransomware is actually happening because of, uh, web browsing and, and the, uh, the semi tool regarding, uh, exploit about 40% of zero days are in browsers.
So the browser is a very sophisticated piece of code. You can't have such a sophisticated code, and you want it, it's a wonderful piece of code. See, it's driving the productivity of all of us in the world, but there is no way to do it without bugs, and there is no way.
And bugs means vulnerabilities. And vulnerabilities are the first step for, for, for, for breaches and for for attacks. This fact of the sophistication of the browser, uh, and the facts that the vendors are investing so much and so many line, uh, code lines are written every day, plus the fact that here is an application that the only one that is used by employees, both at work, but also to render external code from, for untrusted side.
And let's assume that almost any site should be untrusted, even the most trusted one that are used by, by, by, uh, bad, by bad actors. So this combination of sophisticated of the code plus sophistication of the code, plus the fact that it's s rendering, external code is creating, uh, uh, this fantastic opportunity for adversaries. But I want to say just one thing.
The fact that today, all of us, most of us are spending most of the time in the browser, is at the same time creating a, uh, an amazing opportunity for adversaries that it's also an opportunity to consolidate the security requirement into the browser. And this is the big sh uh, uh, shift in earthquake in the industry because suddenly the things that you could have done only by very sophisticated, uh, SSIS solution with all these moving parts in the cloud and pops and reverse boxes, all of this, you don't need it. If 99 or sometimes 100% of your traffic is web-based, why should you do all of your analysis in, in the, in the cloud where things are, uh, uh, encrypted today, sometimes end to head, you have self pinning and all of this where actually you can bring the security to the, let's call it to the, uh, uh, crime scene.
This is the crime scene. And, and this is, I think what is creating a shift. And this is the reason that you see that, uh, um, um, technology leaders, both Sass e company and EDR are looking, uh, uh, quite closely, uh, watching quite closely on this category and saying, okay, we need visibility in controlling the browser.
I verify a DR or Sass E and if I have the gaps, so I need to get this visibility. And this is what is creating the momentum in the market. It's disrupting quite big categories.
All right? You heard in here, ultimately it is all about, well, the crime scene. And if the crime is occurring on the web browser, well then that's where we need to fight the crime.
Gentlemen, thanks for being on the show. Thanks you so much, Mike. Bye-bye.
And, and back to you guys in the.