Startup Agari debuts security services to stop fake email, phishing attacks

AOL, Google, Microsoft, and Yahoo are on board to support the security technology, and Facebook is an early adopter

Startup Agari debuts today with cloud-based email security services aimed at allowing enterprises and e-commerce companies to identify and block fake and spoofed email exploiting their legitimate business domain names to conduct scams and phishing attacks.

Facebook and YouSendIt are among the early adopters of the Agari technology, according to Patrick Peterson, founder and CEO of the company, which is based in Palo Alto.

[ In the data center today, the action is in the private cloud. InfoWorld's experts take you through what you need to know to do it right in our "Private Cloud Deep Dive" PDF special report. | Also check out our "Cloud Security Deep Dive," our "Cloud Storage Deep Dive," and our "Cloud Services Deep Dive." ]

Facebook community forum swamped by spam during Thanksgiving

"They understood how email identity is being abused," says Peterson, who adds the Agari service allows Facebook, for example, to set policy controls and automatically block fake email attempting to exploit Facebook's legitimate domain names used for email.

Agari's protective filtering relies on the big email providers to make it work, and Agari so far has gotten AOL, Google, Microsoft, and Yahoo on board to integrate the Agari technology directly into their email systems to be able to detect fake email. Today, Google product manager Adam Dawes, AOL mail engineering lead Charlie Biegel, Microsoft general manager, safety services, John Scarrow and Yahoo Mail senior director of product management David McDowell each voiced support for the Agari platform to stop illegitimate sources of email.

This accounts for about 1 billion email boxes, says Peterson, noting that there's no financial arrangement with the four big email providers regarding supporting the Agari platform. Already, about 1.5 billion messages each day are now being securely filtered using Agari technology to weed out email attack traffic for customers. While this is a big step, Peterson is the first to admit more is needed.

The Agari service is intended for businesses to be able to set email security policies from the Agari portal that AOL, Google, Microsoft and Yahoo will automatically implement on their behalf to block email detected to be fake and abusing the legitimate domain name of the business, with what Peterson says is a "one in one million false positive rate." Customers using Agari can also show a stream of any blocked email determined to be spoofed or fraudulent.

Agari's technology is called the Agari Email Trust Fabric, and it makes use of established Internet protocols DomainKeys Identified Mail (DKIM) and Sender Policy Framework (SPF). Peterson says about half of all Internet mail today is SPF and DKIM-signed already, and customers using the Agari service must support it, too.

But the Agari service at this point doesn't provide this security filtering for email destined for the typical corporate email server, and thus is more consumer-focused in that regard for now. "This is not for [Microsoft] Exchange," says Peterson but adds Agari is working on finding a way for its technology to apply to various corporate email servers as well.

Also, as of yet, the Agari system wouldn't stop attackers that could evade the Agari email filtering process by using, for instance, European telecom or ISPs which don't yet support Agari filtering.

Because there's such a mammoth stream of spam each day, AT&T and other ISPs already make great efforts to block it, which "is a great and important technology," Peterson says. What Agari adds to this effort, he says, is a way to detect and notify an enterprise about any attempt to steal their specific business email identity in order to trick people into opening fake email that might be loaded with malware or is a phishing attack designed to look like email from a company or someone they know. Agari has some competition in this segment, with company Return Path also seeking to win in the email assurance arena.

"Agari means to win in Japanese," Peterson says. The company, formed in October 2009 and now with 13 employees, has received about $2.5 million in venture capital backing from Alloy Ventures, Battery Ventures, First Round Capital and Greylock Partners.

The history of Agari has roots at Cisco, where Peterson, a Cisco Fellow involved in research, convinced Cisco to let him go off and establish the company based on technology Peterson was developing before joining Cisco as part of the IronPort acquisition. But Peterson still retains his position as Cisco Fellow, though cutting back on hours to spend most of his time at Agari. Cisco, while it's said not to be an investor at Agari, does gain benefits such as access to security information of interest, and a chance to co-market Agari services to Cisco customers.

Read more about wide area network in Network World's Wide Area Network section.

This story, "Startup Agari debuts security services to stop fake email, phishing attacks" was originally published by Network World.

Copyright © 2011 IDG Communications, Inc.

How to choose a low-code development platform