Company profile / Network security

The Alarm Was the Problem

Arista Security began with a blunt confession from an enterprise security chief: the alarms were ringing, but the investigators could not see the intruder. Awake built a way to turn network traffic into a case file; Arista bought it and put that view inside the network itself.

Michael Callahan was listening to security executives at a large financial institution when one of them delivered a remarkably candid forecast. An attacker could probably enter their network, the executive said, and the team would never find them. The company had money, staff and a stream of alarms. What it lacked was a dependable way to work out which alarm described a real intrusion and what the intruder had done.

Callahan, then an entrepreneur in residence at Greylock Partners, described that meeting as the start of Awake Security. A second chief security officer soon told him much the same thing: they did not know what was happening on their own network. It is a peculiar failure of modern defense. The machines produce endless evidence; the investigators still need a map.

The short version
  • Awake Security was founded in 2014 to turn network activity into usable threat investigations.
  • Its sensors identify devices and behavior across campus, data center, cloud and IoT environments; AVA correlates the clues into an attack story.
  • Arista Networks acquired Awake in October 2020 for $180.5 million in cash and now sells the technology as Arista NDR, alongside expert services from Awake Labs.

The first failure was the handoff

The usual security stack divides labor. A firewall guards an entrance. Endpoint software watches a laptop. A log platform collects what the tools report. The analyst is asked to join those fragments and decide whether a strange connection means anything. Awake's founding thesis was that the expensive part of the job was often that joining: finding the device, the user, the destination, the sequence and the likely intent before the trail went cold.

Callahan recruited three cofounders whose skills matched the problem. Gary Golomb brought experience in network defense and forensics. Debabrata Dash worked in large-scale analytics. Keith Amidon knew high-speed network processing and protocol analysis. The combination says something about the product. This was not a prettier alarm bell. It required packet-level observation, an evolving picture of the environment and a workflow an investigator could actually use.

“If you want to get into our network, you probably will. And we’ll never find you.”An enterprise security executive, recalled by Michael Callahan

Awake's answer was to watch the network itself. A sensor observes communications; the platform identifies and profiles devices, users and applications; analytics look for suspicious behavior over time. It then connects related events into what the product calls a Situation. The distinction is small in vocabulary and large in practice. “Unknown device contacted a new domain” is an alert. “This device contacted that domain, reached a server it had never used, and then touched three other machines” is the beginning of a case.

The useful unit of security work is a sequence, not a solitary ping.

The witness no one installed

The product earns its place most clearly where an endpoint agent cannot go. A camera, medical device, industrial controller or guest machine may still communicate even when no security software runs on it. Arista NDR uses network sensors to observe that traffic and build a profile. Arista says its AVA Sensors can run in switches, standalone appliances, virtual environments and cloud deployments. Their output flows to AVA Nucleus, hosted on premises or as a cloud service.

That makes the network a witness, though a witness with a limited view: a sensor can only interpret traffic it receives. Placement matters. So do the analyst's questions. A large enterprise with sprawling campus networks, data centers and cloud workloads has more to gain from a joined-up account than a tiny office with a handful of well managed devices. The company's customers are security operations and network teams; Arista does not publish a reliable count for NDR users alone.

Arista NDR risk dashboard with device, severity and suspicious-domain views
Figure 01The dashboard's many boxes have one assignment: save the analyst from opening another dozen tabs.

The comparison with endpoint tools is instructive. Arista's integration with CrowdStrike Falcon Insight puts endpoint evidence in the NDR view and lets an analyst move from network clues toward containment. Arista's own example describes an externally accessible IoT device that was compromised and then used to move across managed endpoints. The unmanaged device showed why a network perspective mattered; the endpoint integration helped explain and stop what followed. The two kinds of evidence are stronger together.

What $180.5 million bought

Awake announced a $36 million Series C in April 2020, led by Evolution Equity Partners. Six months later, Arista closed the acquisition. Its annual filing puts cash purchase consideration at $180.5 million. The sequence is more interesting than the conventional “startup exits” caption. Arista already made the switches and monitoring fabric that carry enterprise traffic. Awake supplied software to read that traffic as security evidence. Earlier in 2020, Arista had also bought Big Switch Networks, adding monitoring capabilities that fit the same picture.

2014Awake founded
$36mSeries C / April 2020
$180.5mArista's cash purchase

The business model now has several doors. An analyst report describes annual NDR licensing based on average network throughput. Arista offers hardware, virtual and cloud sensor choices, while the analysis console can be hosted locally or as a service. Awake Labs adds assessments, managed 24-hour monitoring, threat hunting and incident response. Arista does not publish a standard price list, so a buyer must scope coverage, traffic volume and service needs with the company.

Arista is competing in network detection and response against vendors including Cisco, Darktrace and ExtraHop, which it named in its 2020 filing. Its particular advantage is architectural proximity. The vendor can provide the network infrastructure, the sensor and the investigation software, then link findings to identity and segmentation tools such as AGNI and MSS. That may reduce the distance between noticing suspicious movement and containing it. It also makes a fair buying question obvious: how well does the system work on the network gear and security tools already in place?

Arista NDR Situation view showing an attack sequence and connected devices
Figure 02A Situation is the platform's attempt to give every clue a place at the same table.

A practical lesson in asking better questions

There is a useful idea here even for teams that never buy Arista NDR. Start an investigation by asking what the network can prove: which device communicated, what changed in its behavior, where it went next and which evidence is missing. Look for the handoffs that make analysts retype an address or guess which alert belongs to which machine. The cost of an alert is not merely the minute it takes to read. It is the hours spent assembling the scene after someone has already left it.

Awake's founders noticed a market full of detectors and a room full of people still unable to answer a simple question. Arista bought the machinery they built to answer it. The point of the product is visible in its least glamorous promise: give the investigator enough context to say what happened, and enough time to do something about it.