Interview with Danijel Sokolović, NanoFirewall: Adaptive AI Protection for Web Applications

Danijel Sokolović, founder & CTO of the startup NanoFirewall, explains in an interview for Cybersecurity Summit ~ Cyberfy the concept behind their solution: a system that learns an application's normal behavior and responds to deviations in real time, instead of relying on static rules and known attack signatures.

The startup NanoFirewall has been increasingly attracting the attention of both the local and international tech community thanks to its innovative approach to cybersecurity based on adaptive learning and autonomous real-time system protection. Following the company’s success within the NINJA Accelerator program and presentations of its solution in Japan and Singapore, we spoke with Danijel Sokolović about building an “immune system” for web applications, why traditional protection models are no longer sufficient, and what comes after the AI revolution in cybersecurity.

 

NanoFirewall is often described as an immune system” for web applications. How would you explain that concept to someone outside the information security industry?

NanoFirewall learns the normal behavior of an application. It does not look at the application only through a list of known attacks. Instead, it tries to understand what is normal for that specific application, and what looks unfamiliar, suspicious, or potentially dangerous.

It is similar to the human immune system. The immune system does not always need to know the exact name of every threat, but it can recognize when something is not behaving in a known or expected way, and it reacts immediately.

For the user or the application owner, this means the protection is not static. The application changes, users change, attackers change, and the defense has to change together with them.

NanoFirewall is built to be that adaptive layer of protection: constantly listening, learning, and reacting before a problem becomes a serious incident.

That is why we describe it as an immune system. It is not just a wall standing in front of the application, but a living protection mechanism that understands context, recognizes unnatural behavior, and helps the system become more resilient over time.

 

How difficult is it today to protect modern web applications?

Defending web applications has always been a challenge. I would not say that it is necessarily harder or easier today than it was before, but it is definitely more complex. The reason is that the nature of applications has changed, as well as the context, or the environment, in which they operate.

Modern web applications are no longer just one system running on one server. Today, they include APIs, mobile applications, cloud infrastructure, third-party integrations, a large number of libraries, automated processes, and, of course, an increasing number of AI components. Each of these layers brings new opportunities, but also new risks.

For small and medium-sized companies, this can be especially difficult because they often do not have large security teams, continuous monitoring, or the same resources that large corporations have, while at the same time being exposed to the same types of attacks.

 

Your focus is not only on large enterprises, but also on the SME market. Why?

The SME market is important to us because small and medium-sized companies today are almost as digitally exposed as large corporations, but they usually do not have the same resources to protect themselves.

They have web applications, customer portals, online sales, cloud services, and various integrations, but often they do not have a large security team, continuous monitoring, or the budget for complex enterprise solutions.

That makes them especially vulnerable. Attackers do not choose targets only based on the size of the company, but also based on opportunity. If a system is exposed, misconfigured, or insufficiently protected, it becomes a target regardless of whether it belongs to a large corporation or a company with 30 employees.

That is why we believe advanced web protection must also be available to the SME sector. We are developing NanoFirewall with exactly that idea: to provide companies that do not have large security teams with adaptive, fast, and practical protection, without too much complexity and without putting a heavy load on their infrastructure.

 

NanoFirewall uses AI and machine learning. How challenging is it to balance accuracy and false positives?

That is one of the most difficult and most important balances when applying AI in cybersecurity. If the system is too sensitive, it will block legitimate users, create too many alerts, and very quickly lose the trust of the people who are supposed to use it. On the other hand, if it is too relaxed, there is a risk that it will miss an attack.

So, it is not enough to simply “detect as much as possible.” The system needs to detect intelligently.

With NanoFirewall, we approach this problem through the context of each specific application. Not every unusual activity is automatically an attack, and not every request that looks like a known pattern is necessarily dangerous.

That is why it is important for the system to learn what is normal for that particular application, its users, and the way it operates. The better it understands normal behavior, the more accurately it can recognize a real deviation.

Also, not every response should be the same. Sometimes a request needs to be blocked, sometimes it needs additional verification, and sometimes it should only be flagged for analysis. This layered approach is important because it reduces the number of false positives while maintaining a high level of protection.

 

Considering the latest AI models capable of autonomously discovering zero-day vulnerabilities, are we entering an era in which cybersecurity will become a fully AI vs AI domain, where humans will no longer be able to operationally keep up with the speed of attacks?

I think we are entering an era where a large part of cybersecurity will indeed become AI versus AI, but not in the sense that humans will disappear from the process. Rather, their role will change.

In a way, we have already had this situation for many years: software against software. Humans are only one part of that chain. I think that will remain true in the coming period as well, but humans will become a different link in the chain.

AI can already analyze code, search for vulnerabilities, generate variations of attacks, and adapt in real time. NanoFirewall is also proof of that. This means that humans can no longer manually follow the speed and scale of everything that is happening, alert by alert. In fact, that has not been realistic for many years.

However, humans remain essential at the strategic level. Their role will be to define the defense architecture, boundaries, rules, acceptable risk, and the way systems make decisions.

That is why adaptive protection is becoming critical. If attacks are becoming faster, smarter, and more automated, defense cannot remain static. It has to learn, recognize new behavior, and respond while the attack is still happening.

 

NanoFirewall was part of the NINJA Accelerator last year and was presented in Japan and Singapore. What were your impressions of the Asian market?

The NINJA Accelerator was very important for us because it helped us look at NanoFirewall not only as a technological solution, but as a product for the global market.

Presenting in Japan and Singapore was a valuable experience because these are highly demanding and technologically mature environments. Through conversations with mentors, investors, and potential partners, we received confirmation that the problem we are solving is not local, but global.

For us, that kind of feedback is extremely important. It shows us what people understand immediately, what needs to be explained better, and where the product has the greatest potential.

It also further confirmed that there is a real need for adaptive web protection that is powerful, but simple to integrate and use.

 

How difficult is it to build a global cybersecurity product from Serbia?

I believe it is becoming easier year by year. Of course, there are still challenges. Access to capital, markets, networks, and large enterprise clients is still more difficult than in some larger ecosystems, where these companies, investment firms, and funds have been present for decades.

At the same time, there are many companies and startups from Serbia that are receiving investment, developing products, and hiring new people. So it is possible, but the initial visibility is much lower because we come from a smaller ecosystem.

IT has probably done more than anything else in history to reduce the importance of borders, distance, and time. Cybersecurity, as part of the global IT scene, is global by nature. Attacks do not recognize borders, and the problems you solve in Serbia are often the same problems companies face all over the world.

On the other hand, Serbia has very strong engineering talent. People are used to working with limited resources, both technical and time-related, being resourceful, and solving complex problems in a practical way. In cybersecurity, that is a major advantage.

For us, the key is not to think of NanoFirewall as a local product trying to expand internationally, but as a global product being developed from Serbia. If you are solving an important enough problem, if you have technology that brings clear value, and if you are ready to learn from the market, geography may be a challenge, but it is not a barrier.

 

What would you highlight as NanoFirewall’s biggest advantage compared to other solutions on the market?

The biggest advantage of NanoFirewall is the combination of adaptability, speed, and simple deployment in real-world environments.

Unlike solutions that mainly rely on predefined rules or known attack signatures, NanoFirewall learns how a specific application normally works and reacts when behavior appears that deviates from that pattern.

One of the practical examples we often mention is zero-day attacks, which NanoFirewall can successfully detect, learn from, and prevent in real time. In some cases, information that a zero-day vulnerability even existed in the application or technology we were protecting was published only two or three weeks after our detection and protection. The critical Microsoft SharePoint vulnerability from last year is a good example of that.

At the same time, the system is designed to be fast and lightweight, so protection does not become a burden on the application or infrastructure. This is especially important for companies that want advanced protection but do not have a large security team or a complex enterprise environment.

So I would say that NanoFirewall’s main advantage is that it provides adaptive, AI-supported protection that naturally fits into the application and evolves together with it.

 

Finally — how do you see the future of cybersecurity over the next five years?

I think the next five years in cybersecurity will be defined mostly by speed, just like the past several years have been. Attacks will become increasingly automated, more personalized, and more often supported by artificial intelligence.

That is why defense will no longer be able to rely only on static rules. We will need systems that learn, adapt, and respond in real time, such as NanoFirewall.


 

Intervju sa Danijelom Sokolovićem, NanoFirewall: Adaptivna AI zaštita za veb aplikacije

 

Startap NanoFirewall sve češće privlači pažnju domaće i međunarodne tech zajednice zahvaljujući inovativnom pristupu sajber bezbednosti zasnovanom na adaptivnom učenju i autonomnoj zaštiti sistema u realnom vremenu. Razgovarali smo sa Danijelom o tome kako izgleda razvoj „imunog sistema” za veb aplikacije, zašto tradicionalni modeli zaštite više nisu dovoljni i šta dolazi posle AI revolucije u sajber svetu.

 

NanoFirewall se često opisuje kao „imuni sistem” za veb aplikacije. Kako biste objasnili taj koncept nekome ko nije iz sfere informacione bezbednosti?

NanoFirewall uči normalno ponašanje aplikacije. Ne posmatra je samo kroz listu poznatih napada, već pokušava da razume šta je za tu konkretnu aplikaciju uobičajeno, a šta deluje strano, sumnjivo ili potencijalno opasno. Slično kao imuni sistem kod čoveka. On ne mora uvek da zna ime svake pretnje, ali prepoznaje kada se nešto ne ponaša u skladu sa poznatim ili već viđenim, i reaguje odmah.

Za korisnika ili vlasnika aplikacije to znači da zaštita nije statična. Aplikacija se menja, korisnici se menjaju, napadači se menjaju – i odbrana mora da se menja zajedno sa njima. Kao i do sada. NanoFirewall je napravljen da bude taj adaptivni sloj zaštite koji stalno osluškuje, uči i reaguje pre nego što problem preraste u ozbiljan incident.

Zato ga opisujemo kao imuni sistem. Ne samo kao zid koji stoji ispred aplikacije, već kao živi zaštitni mehanizam koji razume kontekst, prepoznaje neprirodno ponašanje i pomaže sistemu da postane otporniji tokom vremena.

 

Koliko je danas zapravo teško zaštititi moderne veb aplikacije?

Braniti veb aplikacije je oduvek bio izazov. Ne bih rekao da je danas nužno teže ili lakše nego pre, ali je definitivno kompleksnije. Razlog je što se promenila priroda samih aplikacija kao i njihov kontekst, odnosno, okruženje u kojem rade.

Moderne veb aplikacije više nisu jedan sistem na jednom serveru. One danas uključuju API-je, mobilne aplikacije, cloud infrastrukturu, integracije sa trećim stranama, veliki broj biblioteka, automatizovane procese, i naravno, sve više AI komponenata. Svaki od tih slojeva donosi nove mogućnosti, ali i nove rizike.

Za male i srednje kompanije može biti teže, jer one često nemaju velike bezbednosne timove, stalni nadzor i resurse kakve imaju velike korporacije, a istovremeno su izložene istim vrstama napada.

 

Vaš fokus nije samo na velikim kompanijama, već i MSP tržište. Zašto?

MSP tržište nam je važno zato što su male i srednje kompanije danas digitalno izložene gotovo u istoj meri kao velike korporacije, ali najčešće nemaju iste resurse da se zaštite. Imaju veb aplikacije, korisničke portale, online prodaju, cloud servise i razne integracije, ali često nemaju veliki bezbednosni tim, stalni nadzor ili budžet za kompleksna enterprise rešenja.

To ih čini posebno ranjivim. Napadači ne biraju mete samo po veličini kompanije, već (uz to) i po prilici. Ako je sistem otvoren, pogrešno podešen ili nedovoljno zaštićen, on postaje meta bez obzira na to da li iza njega stoji velika korporacija ili firma od 30 ljudi.

Zato verujemo da napredna veb zaštita mora biti dostupna i MSP sektoru. NanoFirewall razvijamo upravo sa tom idejom: da kompanijama koje nemaju velike bezbednosne timove pruži adaptivnu, brzu i praktičnu zaštitu, bez prevelike kompleksnosti i bez velikog opterećenja po infrastrukturu.

 

NanoFirewall koristi AI i mašinsko učenje. Koliko je teško balansirati između preciznosti i lažnih uzbuna?

To je jedan od najtežih i najvažnijih balansa u primeni AI-ja u sajber bezbednosti. Ako je sistem previše osetljiv, on će zaustavljati i legitimne korisnike, stvarati previše alarma i vrlo brzo izgubiti poverenje ljudi koji treba da ga koriste. Ako je, sa druge strane, previše opušten, postoji rizik da propusti napad. Dakle, nije dovoljno samo „detektovati što više” – potrebno je detektovati pametno.

Kod NanoFirewall-a na taj problem gledamo kroz kontekst konkretne aplikacije. Nije svaka neobična aktivnost automatski napad, niti je svaki zahtev koji liči na poznati obrazac nužno opasan. Zato je važno da sistem uči šta je normalno za baš tu aplikaciju, njene korisnike i njen način rada. Što bolje razume normalno ponašanje, to preciznije može da prepozna stvarno odstupanje.

Takođe, nije svaka reakcija ista. Nekada je potrebno zahtev blokirati, nekada ga dodatno proveriti, nekada samo označiti za analizu. Upravo taj slojeviti pristup je važan, jer smanjuje broj lažnih uzbuna, a zadržava visok nivo zaštite.

 

Imajući u vidu najnovije AI modele koji autonomno pronalaze „zero-day” ranjivosti, da li ulazimo u eru u kojoj će sajber bezbednost postati potpuno AI vs AI domen, gde čovek više neće moći operativno da prati brzinu napada?

Mislim da ulazimo u eru u kojoj će veliki deo sajber bezbednosti zaista postati AI vs AI, ali ne u smislu da čovek nestaje iz procesa. Pre će se promeniti njegova uloga.

Na kraju, takvu situaciju imamo mnogo godina unazad. Softver protiv softvera. Ljudi su samo jedan deo tog lanca. Mislim da će tako ostati i u narednom periodu, samo će biti u ulozi neke druge karike.

AI već sada može da analizira kod, traži ranjivosti, generiše varijacije napada i prilagođava se u hodu. NanoFirewall je takođe dokaz za to. To znači da čovek više ne može ručno, alarm po alarm, da prati brzinu i obim svega što se dešava. To već dugi niz godina nije tako.

Čovek ostaje ključan na strateškom nivou. Njegova uloga biće da definiše arhitekturu odbrane, granice, pravila, prihvatljiv rizik i način na koji sistemi donose odluke.

Zato adaptivna zaštita postaje presudna. Ako napadi postaju brži, pametniji i automatizovaniji, odbrana ne može ostati statična. Mora da uči, prepoznaje novo ponašanje i reaguje dok se napad još dešava.

 

NanoFirewall je prosle godine bio deo NINJA akceleratora i predstavljen u Japanu i Singapuru. Kakvi su utisci sa azijskog tržišta?

NINJA akcelerator nam je bio veoma važan jer nam je pomogao da NanoFirewall sagledamo ne samo kao tehnološko rešenje, već kao proizvod za globalno tržište.

Predstavljanje u Japanu i Singapuru bilo je dragoceno iskustvo, jer su to veoma zahtevna i tehnološki zrela okruženja. Kroz razgovore sa mentorima, investitorima i potencijalnim partnerima dobili smo potvrdu da problem koji rešavamo nije lokalni, već globalni.

Za nas je takva povratna informacija izuzetno važna. Ona pokazuje šta ljudi odmah razumeju, šta treba bolje objasniti i gde proizvod ima najveći potencijal. Nama je to dodatno potvrdilo da postoji stvarna potreba za adaptivnom web zaštitom koja je snažna, ali jednostavna za integraciju i korišćenje.

 

Koliko je teško iz Srbije graditi globalni cybersecurity proizvod?

Smatram da je iz godine u godinu sve lakše. Naravno, postoje izazovi – pristup kapitalu, tržištu, mreži kontakata i velikim enterprise klijentima je i dalje teže nego u nekim većim ekosistemima gde se te firme ili investitorske kuće i fondovi nalaze decenijama. Dokaz za to su brojne firme ili startup-i koje dobijaju investicije, razvijaju proizvode, zapošljavaju nove ljude, a odavde su. Dakle, moguće je, ali je početna vidljivost dosta manja jer dolazimo iz „manjih” sredina.

IT je verovatno u najvećoj meri u istoriji sveta uticao na brisanje granica, distance ili vremena. Sajber bezbednost, kao deo globane IT scene, je globalno tržište po svojoj prirodi – napadi ne poznaju granice, a problemi koje rešavate u Srbiji često su isti problemi koje imaju kompanije u na svim meridijanima.

Sa druge strane, Srbija ima veoma jak inženjerski talenat. Ljudi su navikli da rade sa ograničenim resursima (tehnološkim i vremenskim), da budu snalažljivi i da rešavaju kompleksne probleme praktično. U sajber bezbednosti je to velika prednost.

Za nas je ključno da ne razmišljamo kao lokalni proizvod koji pokušava da izađe napolje, već kao globalni proizvod koji se razvija iz Srbije. Ako rešavate dovoljno važan problem, ako imate tehnologiju koja donosi jasnu vrednost i ako ste spremni da učite od tržišta, geografija je tu kao izazov (možda), ali ne i prepreka.

 

Šta biste izdvojili kao najveću prednost NanoFirewall-a u odnosu na ostale?

Najveća prednost NanoFirewall-a je kombinacija adaptivnosti, brzine i jednostavne primene u realnom okruženju.

Za razliku od rešenja koja se uglavnom oslanjaju na unapred definisana pravila ili poznate potpise napada, NanoFirewall uči kako konkretna aplikacija normalno funkcioniše i reaguje kada se pojavi ponašanje koje odstupa od tog obrasca.

Posebne primere koje uvek navodimo iz prakse su zero-day napadi koje uspešno detektujemo, učimo i sprečavamo u realnom vremenu. U nekim slučajevima, čak 2-3 nedelje nakon naše detekcije i zaštite, dolazi do objavljivanja informacija da je uopšte postojao zero-day napad vezan za tu aplikaciju ili tehnologije koje branimo. Microsoft Sharepoint kritična ranjivost od prošle godine je dobar primer za to.

Istovremeno, sistem je projektovan da bude brz i lagan, tako da zaštita ne postane opterećenje za aplikaciju ili infrastrukturu. To je posebno važno za kompanije koje žele naprednu zaštitu, ali nemaju veliki sajber bezbednosni tim ili kompleksno enterprise okruženje.

Zato bih rekao da je glavna prednost NanoFirewall-a u tome što donosi adaptivnu, AI-podržanu zaštitu koja se prirodno uklapa u aplikaciju i razvija zajedno sa njom.

 

Za kraj — kako vi vidite budućnost sajber bezbednosti u narednih pet godina?

Mislim da će narednih pet godina u sajber bezbednosti najviše obeležiti brzina. Kao i proteklih godina. Napadi će biti sve automatizovaniji, personalizovaniji i sve češće potpomognuti veštačkom inteligencijom.

Zato odbrana više neće moći da se oslanja samo na statična pravila. Biće potrebni sistemi koji uče, prilagođavaju se i reaguju u realnom vremenu, poput NanoFirewall-a.

Cyber Security Summit, Belgrade 2024
Contact us today to be a part of the future of cyber security.

Put your brand and expertise in the spotlight with one of our carefully crafted sponsorship packages. Whether it be a speaking role, a delegate package for your team, logo exposure, or the opportunity to bring your current and potential clients along to the event, we have got you covered with something that will genuinely help you get deals done at our events.

Join us in uniting for a safer tomorrow!

Cyber Security Summit, Belgrade 2024