Confident Technologies Adds New Capabilities to Its Network Security Software

turn that business away.

Yudkin, Confident’s chief technology officer, says the company’s new KillSwitch technology now offers a way for network managers to tell the difference between the log-in failures of an authorized user and an automated system repeatedly trying randomly generated passwords.

“With this technology, we’re trying to change the paradigm for brute force attacks,” Yudkin says.

The KillSwitch technology really just adds a new twist to the company’s core image-based verification system. When a user logs onto a secure website using Confident’s technology, he chooses a sequence of encrypted images to log on with. The images vary with each login, but the user logs in by selecting the images that fit previously selected categories. For example, using the car, airplane, fruit categories mentioned above, the user might choose a Porsche, Boeing 747, and apple for a login sequence.

With the KillSwitch feature enabled, the user is asked during the initial registration process to choose an additional couple of image categories that he will never use—for example, a flower and dog. So if a hacker or automated program chooses a dog or some other “no pass” category in a login attempt, the KillSwitch system can automatically alert the authorized user or the website’s network administrator.

It’s possible that an account user might mistakenly try one of the “no pass” images to log on, “but the likelihood of you selecting two KillSwitch images is quite low,” Yudkin says. It becomes even more obvious when “no pass” images are repeatedly selected in multiple login attempts.

The company says its technology can lock all access to the online account, or keep the would-be attacker online to collect information about his IP address, geographical location, and behavioral characteristics.

“If a company has good security, it gives them more time to respond to an attack,” Yudkin says.

Confident, however, faces a pretty stiff headwind in a crowded market for network security, according to Gene Schultz, a well-known network and computer security expert who is chief technology officer for Emagined Security, a consulting firm in San Carlos, CA.

“Despite the apparent goodness of Confident’s technology, I worry that organizations will not use it because they are (lamentably) so password-dependent,” Schultz told me by e-mail last night. “Many great authentication solutions have in the past fallen by the wayside because of widespread acceptance of and dependence on passwords. Additionally, I worry that have extra steps involving user tasks may be necessary if legitimate access is to be allowed, but illegitimate access is to be denied. Finally, I worry that if this technology were to be widely deployed, the black hat community would soon find a way to defeat it, as historically has been true.”

Author: Bruce V. Bigelow

In Memoriam: Our dear friend Bruce V. Bigelow passed away on June 29, 2018. He was the editor of Xconomy San Diego from 2008 to 2018. Read more about his life and work here. Bruce Bigelow joined Xconomy from the business desk of the San Diego Union-Tribune. He was a member of the team of reporters who were awarded the 2006 Pulitzer Prize in National Reporting for uncovering bribes paid to San Diego Republican Rep. Randy “Duke” Cunningham in exchange for special legislation earmarks. He also shared a 2006 award for enterprise reporting from the Society of Business Editors and Writers for “In Harm’s Way,” an article about the extraordinary casualty rate among employees working in Iraq for San Diego’s Titan Corp. He has written extensively about the 2002 corporate accounting scandal at software goliath Peregrine Systems. He also was a Gerald Loeb Award finalist and National Headline Award winner for “The Toymaker,” a 14-part chronicle of a San Diego start-up company. He takes special satisfaction, though, that the series was included in the library for nonfiction narrative journalism at the Nieman Foundation for Journalism at Harvard University. Bigelow graduated from U.C. Berkeley in 1977 with a degree in English Literature and from the Columbia University Graduate School of Journalism in 1979. Before joining the Union-Tribune in 1990, he worked for the Associated Press in Los Angeles and The Kansas City Times.