Menu
Security startup finds stolen data on the 'Dark Web'

Security startup finds stolen data on the 'Dark Web'

Terbium uses data fingerprinting techniques to find stolen information on the Web

Security startup Terbium says it can find stolen data in the dark corners of the Internet by using data fingerprinting techniques.

Security startup Terbium says it can find stolen data in the dark corners of the Internet by using data fingerprinting techniques.

Finding stolen data on the Internet is often the first sign of a breach, and a Baltimore-based startup says it has developed a way to find that data faster and more securely.

The company is called Terbium Labs, named after a malleable, silver-gray element. CEO Danny Rogers and CTO Michael Moore say they're taking a large scale, computational approach to finding pilfered data.

Terbium's product, Matchlight, uses data fingerprinting techniques to create hashes of an organization's data in fragments as small as 14 bytes. Only those hashes -- which can't be transformed back into the original data -- are stored by Terbium.

The other major component of Terbium's service is a massive private index of the so-called Dark and Deep Web, both terms for hard-to-find websites and crevices of the Internet where cybercriminals trade and sell data.

The hashes collected from companies by Terbium are then compared with data shared on the Web, "which is a way for us to automatically search for an element of the company's data without actually knowing what that data is," Rogers said.

"The number one concern for information security folks at these large enterprises is control and protection of the data, even from their own vendors," he said. "So this allows them to search for things without having to reveal what those things are."

Because the hashing and comparing is done in real time, the company said it can shorten the breach discovery time -- which in some studies ranges up to six to eight months -- down to minutes.

Companies can choose what applications or data stores they want Terbium to monitor. If Matchlight finds something similar on the Dark Web, it can score it, which gives an idea of how similar it may be to the company's data.

Terbium spiders and indexes obscure parts of the Web, such as Tor hidden services, which are websites using the anonymity system to obscure the sites' real IP addresses. Hidden sites are increasingly favored by hackers, as it makes it harder for law enforcement to track.

The indexing system naturally follows links posted within the Dark Web. "Where we're looking at are places where people are leaking or are trying to monetize data," Rogers said.

The company also monitors some mainstream sites at 30-second intervals such as Reddit, Pastebin and Twitter, which are also used by hackers.

Companies using Matchlight can get alerts when a piece of data is found. A fingerprint ID number can then be looked up to see what original data it corresponds to. Companies can then potentially start the breach mediation process, Rogers said.

Rogers said the first day Terbium turned Matchlight on, it found in a single 24-hour period 20,000 to 30,000 credit card numbers and 600 leaked email addresses and passwords. Both sets of data were detected minutes after being posted, Rogers said.

Several Fortune 500 companies, including health insurers, manufacturers and financial services ones, are beta testing Matchlight now.

Terbium hasn't determined pricing yet, but it is considering a flat rate based on data volumes or the number of records monitored, Rogers said.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Terbium Labs

Events

Featured

Slideshows

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

This year’s Reseller News 30 Under 30 Tech Awards were held as an integral part of the first entirely virtual Emerging Leaders​ forum, an annual event dedicated to identifying, educating and showcasing the New Zealand technology market’s rising stars. The 30 Under 30 Tech Awards 2020 recognised the outstanding achievements and business excellence of 30 talented individuals​, across both young leaders and those just starting out. In this slideshow, Reseller News honours this year's winners and captures their thoughts about how their ideas of leadership have changed over time.​

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners
Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

This exclusive Reseller News Exchange event in Auckland explored the challenges facing the partner community on the cloud security frontier, as well as market trends, customer priorities and how the channel can capitalise on the opportunities available. In association with Arrow, Bitdefender, Exclusive Networks, Fortinet and Palo Alto Networks. Photos by Gino Demeer.

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security
Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomed 2019 inductees - Leanne Buer, Ross Jenkins and Terry Dunn - to the fourth running of the Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed the changing face of the IT channel ecosystem in New Zealand and what it means to be a Reseller News Hall of Fame inductee. Photos by Gino Demeer.

Reseller News welcomes industry figures at 2020 Hall of Fame lunch
Show Comments