Security startup Blue Hexagon said it can inspect encrypted traffic, detecting and stopping threats in real time, using its deep-learning-based platform.

The 2-year-old company has been generating a lot of buzz since it disclosed a $31 million Series B funding round six months ago and launched its platform, which takes a unique approach to protecting enterprises from cyberattacks. It uses deep learning to provide security.

Blue Hexagon built its training infrastructure working with Amazon Web Services (in fact, the cloud-based platform runs on AWS infrastructure) and it uses neural networks to inspect web and network traffic. This approach enables it to block malware in sub-seconds, the company claims.

“The first place that threats enter the enterprise is through the connection to the internet, and we have a product that analyzes network traffic when it enters the enterprise,” said co-founder and CEO Nayeem Islam in an earlier interview. “We’re able to identify the network threat in less than one second — it’s the world’s first application of real-time deep learning to catch network threats."

Islam is the former head of Qualcomm research and development, and co-founder and CTO Saumitra Das is the former engineering leader at Qualcomm. The Blue Hexagon leadership team also includes threat researchers and deep learning experts from FireEye, Palo Alto Networks, Symantec, and Amazon.

The platform’s new capabilities announced today at Black Hat use deep learning for real-time inspection of encrypted traffic without hurting network speed and performance or requiring additional devices, the company says.

“Encryption is used to provide data privacy, but attackers can also use encryption to send malicious traffic,” said Balaji Prasad, vice president of products at Blue Hexagon. “Enterprises can get around this by putting up decryption tools and decrypting everything, but then there’s the issues of scale and noise.”

Traditional approaches — such as inspecting traffic on next-generation firewalls — usually requires additional decryption devices, and this can slow down network performance. Additionally, using signature profiling methods like JA3 or machine learning to identify anomalies over large volumes of data can result in lots of false positives.

“Benign communications look very different than malicious communications, and our neural network can make that differentiation,” Prasad said.

The company’s proprietary Deep Learning HexNet architecture detects suspicious patterns that can be observed in the SSL/TLS communications during different stages of the connection, he explained. The deep learning models are trained on thousands of observations and characteristics that are used to separate a malicious encrypted tunnel from a benign communications channel. These patterns are tightly bound to the core communication functionality of the client and server encryption process. As a result, deep learning can identify and stop threats in these communications channels, even when the channel is encrypted.

The models also observe how the connections change over time, which means they are continually learning from the threat patterns being used by attackers, according to the company.

With the plethora of products enterprises are already using to secure their networks and data, where does Blue Hexagon fit into a company’s security architecture? Right now, it’s a complementary product, Prasad said. “We are walking on new territory here, and for now we can make all the existing investments perform a lot better because they get a high-quality signal that something bad is happening. But down the line, imagine if you were able to do something very quickly at the perimeter itself?”

He’s referring to potential user and entity behavior analytics (UEBA), other anomaly detection tools, or even security information and event management (SIEM) products.

“We’re not there yet,” Prasad admits. “Given our size no one is going to rip out a firewall and replace it with us yet. But that is a possibility.”