Script downloadedA Python payload from attacker.com was downloaded
Data exfiltratedData was archived then exfiltrated to 76.76.21.21
Engineer logged inAnomalous geolocation
‹First entry point
‹Persistence
‹Second entry point
Exfiltration›
What you see today.
What is actually happening.what is actually happening.
Bitbison sees
Bitbison Detectiondetection isnot a dead end.
Security you can verify.
The first Linux security platform built on a complete causal record of your systems, protecting everything from your most important assets to the servers they run on.
2 false positives. 1 real threat missed.1 real detection with evidence.
"Under peak loads, the best existing audit systems lose over 90% of the data, while slowing workloads by 2× to 8×."
Sekar et al., eAudit, IEEE Symposium on Security & Privacy, 2024
Event coverage vs. resource cost measured in production
coverage →
Alternatives
Bitbison
Orders of magnitude more coverage at a fraction of the cost
CPU + memory cost →
"The average breach took 194 days to identify, and 258 days to fully contain."
IBM, Cost of a Data Breach Report, 2024
"54% of intrusions were discovered by an external party - not the organization itself."
Mandiant, M-Trends, 2024
"SOC analysts report that as many as 99% of the alarms raised by signature- and rule-based tools are false positives."
Alahmadi et al., “99% False Positives”, USENIX Security, 2022
Causal policy
policy"managed-config":
scope$f:fspathwhere$f⇒_:exec⇒_:listen# every config a listening service loadsallowbastion.corp:conn⇒ansible:exec→[write] $fdeny_→[write] $f:
alert critical, evidence: full chain
“Only Ansible, driven from the bastion, may write a config that a network-facing service loads. Anything else alerts — with the complete chain as evidence.”
Everything here except the arrows exists in today's rule languages, where attributes can be spoofed. ⇒ asserts the write provably flowed from the bastion, a recorded fact rather than a claimed attribute. That one primitive is what no other platform can express.
What you see today.
Existing runtime security watches a few hundred coarse-grained events an hour and misses over 99% of what actually happens. You cannot detect or investigate what was never observed.
What is actually happening.
On the same host, over the same hour, tens of thousands of threads, processes, files, connections and other system objects interact with one another. Almost none of it is analyzed or recorded.
Bitbison sees what is actually happening.
The full causal graph of what actually happened, continuously, at production scale. No sampling and no blind spots.
Total observability used to be imis now possible.
Production build server
×13
Agent A56,587 events
Bitbison722,683 events
cpu2.4%0.72%
mem441 MB279 MB
Production web service
×10,537
Agent B32 events
Bitbison337,192 events
cpu0.53%0.32%
mem230 MB278 MB
Production control plane
×189
Agent C1,130 events
Bitbison213,657 events
cpu0.50%0.36%
mem1,191 MB275 MB
Attempted full capture
Agent D50% captured
Bitbison100% captured
cpu100%6%
disk9.2 GB80 MB
Bitbison against industry leaders on real production servers.
Total capture meant unbearable storage, runaway CPU and dropped events. The industry settled for architectures that capture less than 1% of what happens. We removed the bottleneck at production scale.
Detection is a dead end.
Without high-fidelity data, you are left reconstructing events from whatever data exists.
Bitbison logs everything, all the time.
The complete causal chain behind every alert is already recorded.
Detection was ineffective.
Signatures, rules and behavioral analysis are all pattern matching on discrete, disconnected events. A real threat is a chain of cause and effect. A pattern only approximates a chain. It misfires on benign activity and misses what it has not seen.
So we rebuilt policy around cause and effect.
A policy on the causal graph states the intention directly. It applies to the whole system. There are no allowlists or blocklists to maintain or evade.
The modern security platform.
Autonomous agents, supply chain attacks and commoditized 0-days do not follow patterns that can be enumerated in advance. The tooling built on those patterns has not kept up. Bitbison is a new foundation for runtime security.