So what does a typical work day look like nowadays? Before the day has even properly begun, many of us have already logged into a service sitting on the public Internet several times. We connect to the company VPN on the commute to work or from home, order lunch through an app, check our bank account, pay a bill and – for those getting away from a screen for a stint – sync a smartwatch before heading out for a run. Each interaction feels routine, even smart. A username, a password, perhaps a two-factor authentication: and we are in. Check.
But there is something we tend not to think about: every service reachable from anywhere on the Internet can be discovered, targeted and attacked.
Cybercriminals scan the Internet constantly (now leveraging AI tools), hunting for exactly this kind of exposed service: VPN gateways, banking backends, IoT endpoints, anything reachable that might also be breakable.
Anapaya PathGuard makes services and applications reachable only by approved users – protecting them so that customers and employees can access safely, while hackers cannot even see them. Today, with Anapaya PathGuard, digital applications and web services don't have to be Internet-facing anymore.
For decades, the answer against Internet-wide scanning of applications and web services has been to build security around them, otherwise known as damage control. As cyberattacks become increasingly automated and scalable, the default reachability on the public Internet of critical applications creates unnecessary risk. Organizations face several challenges at once:
Overlay security solutions can control who is allowed into an application, but their Internet-facing gateways and infrastructure can themselves become part of the attack surface. For critical services, the safest attack surface is one unauthorized users cannot reach.
Think of an e-banking application that customers can access normally, but which an unauthorized user cannot discover or reach. Or better still: a corporate VPN that employees can connect to from home, while an attacker scanning the Internet cannot even find, much less target. This is the main intent behind developing Anapaya PathGuard operating on the SCION Internet: making services and applications reachable only by approved users and invisible to anyone else.
SCION (Scalability, Control, and Isolation on Next-generation Networks) is a network technology that enables enterprises to create trusted networks with selected, approved participants, built on clear governance.
Anapaya PathGuard changes from default public reachability to controlled reachability: from your application being visible to billions of users on the public Internet, to millions with Anapaya GATE, to only pre-selected, authorized users with Anapaya PathGuard on the SCION Internet.
This is made possible by the fact that Anapaya PathGuard extends SCION natively to the end user's browser, app, and device, and hides the enterprise service behind paths that are inaccessible to unauthorized users. The service is de facto invisible on both the public Internet and the SCION Internet (unless you are allowed to see it).
Together with our CTO, Sam, I will explain the mechanics behind it in our webinar, "Every exposed service is a target: A new approach to protecting critical access with Anapaya PathGuard," on November 10 and 12.
Enterprises can deploy Anapaya PathGuard by following three steps:
The biggest difference with Anapaya PathGuard happens before the traffic reaches the application: unauthorized users do not receive the routing information needed to establish a path to the protected service.
The idea is simple: No authorization. No path. No access.
That means an attacker cannot simply discover the application's IP address and start scanning or sending traffic to it. For unauthorized users, there is simply no route to the application.
Most security solutions start working once traffic is already able to reach your infrastructure. Firewalls filter it. DDoS protection identifies and mitigates malicious traffic. Intrusion detection systems analyze it. Authentication systems determine whether a user should ultimately receive access.
Anapaya PathGuard operates one layer beneath all that: it decides whether traffic can reach the protected service in the first place. For services that have a known user base, this means that they can’t be subject to Internet-wide scanning.
Rather than seeing who can detect and respond to malicious traffic faster, organizations can remove an important part of the attacker's opportunity: the ability to reach the target from the get-go.
Anapaya PathGuard adds to the existing security stack. Nothing gets replaced.
With Anapaya PathGuard, enterprises can:
For organizations operating critical applications, that means security, resilience, and sovereignty can be addressed at the network layer rather than treated as separate problems.
Any application or service with a known user base is a potential use case for Anapaya PathGuard. Here are the top three:
A public website with unknown users, on the other hand, is a use case for Anapaya GATE.
The Internet was designed around reachability, which is – in itself – a good thing. But, in a beautiful example of a catch 22, if a service is on the Internet, it can be scanned, targeted and attacked.
Cybersecurity has spent decades building increasingly sophisticated and reactive defenses around that model. Anapaya PathGuard introduces another possibility by shifting the paradigm.
Don't make every critical service reachable by everyone and then decide who gets in. Decide who should be able to reach the service in the first place.
For employees, customers, partners, applications, and devices that are authorized, the service remains digital, remote, and accessible. For everyone else, there is simply no path.
That is what we mean by invisibility to unauthorized users.
Ok, so for the final task of the day – smart watch on, let’s go check our sleep patterns and make sure we’re getting a good night’s rest.