{"id":5787,"date":"2023-01-26T16:26:09","date_gmt":"2023-01-26T15:26:09","guid":{"rendered":"https:\/\/partnernews.sophos.com\/en-us\/?p=5787"},"modified":"2023-01-30T07:22:35","modified_gmt":"2023-01-30T07:22:35","slug":"introducing-sophos-network-detection-and-response-ndr","status":"publish","type":"post","link":"https:\/\/partnernews.sophos.com\/es-es\/2023\/01\/products\/introducing-sophos-network-detection-and-response-ndr\/","title":{"rendered":"Introducing Sophos Network Detection and Response (NDR)"},"content":{"rendered":"<p>We recently launched\u00a0<a href=\"https:\/\/www.sophos.com\/en-us\/products\/managed-detection-and-response\/network-detection-and-response\" target=\"_blank\" rel=\"noopener\">Sophos Network Detection and Response<\/a>\u00a0(NDR) and it\u2019s already providing real-world value for organizations looking to elevate their defenses against sophisticated attackers and zero-day threats.<\/p>\n<p>Sophos NDR continuously monitors network traffic to detect suspicious activities that may be indicative of attacker activity, leveraging a combination of machine learning, advanced analytics, and rule-based matching techniques.<\/p>\n<p>It detects a wide range of security risks, including rogue devices (unauthorized, potentially malicious devices that are communicating across the network), unprotected devices (legitimate devices that could be used as an entry point), insider threats, zero-day attacks, and threats involving IoT and OT devices.<\/p>\n<p>Plus, when combined with other security telemetry, Sophos NDR enables threat analysts to paint a more complete, accurate picture of the entire attack path and progression, enabling a faster, more comprehensive response.<\/p>\n<p>Sophos NDR is an add-on integration for\u00a0<a href=\"https:\/\/www.sophos.com\/en-us\/products\/managed-detection-and-response\" target=\"_blank\" rel=\"noopener\">Sophos MDR<\/a>, our market-leading managed detection and response service that today serves over 14,000 organizations worldwide. Later this year, we\u2019ll also be making Sophos NDR available with\u00a0<a href=\"https:\/\/www.sophos.com\/en-us\/products\/endpoint-antivirus\/xdr\" target=\"_blank\" rel=\"noopener\">Sophos Extended Detection and Response<\/a>\u00a0(XDR) for those organizations that prefer to conduct their own threat hunting activities \u2013 more on this in a future post.<\/p>\n<h2>The importance of network detection and response<\/h2>\n<p>NDR is an essential part of an effective defense-in-depth strategy. Why? Because the network is the one place a stealthy, committed adversary cannot hide.<\/p>\n<p>Attackers go to great lengths to avoid being detected and Defense Evasion is well known\u00a0MITRE ATT&amp;CK Tactic at the system level. Exploits can hide out of sight of EDR solutions, and adversaries can disable and delete system logs.\u00a0<em>But they still have to traverse the network<\/em>.<\/p>\n<p>As adversaries continue to evolve their tactics, techniques, and procedures (TTPs) to bypass security controls, NDR is fast becoming a security imperative.<\/p>\n<h2>Sophos NDR: unparalleled network threat detection<\/h2>\n<p>Sophos NDR is powered by five real-time threat detection engines that use patented multi-layered technologies to detect even the stealthiest of attacks.<\/p>\n<figure id=\"attachment_89449\" class=\"wp-caption alignright\" aria-describedby=\"caption-attachment-89449\"><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/01\/NDR-engines.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-89449 size-large\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/01\/NDR-engines.png?w=460\" sizes=\"auto, (max-width: 460px) 100vw, 460px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/01\/NDR-engines.png 460w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/01\/NDR-engines.png?resize=300,207 300w\" alt=\"\" width=\"460\" height=\"317\" \/><\/a><figcaption id=\"caption-attachment-89449\" class=\"wp-caption-text\">Sophos NDR detection engines. Click to enlarge.<\/figcaption><\/figure>\n<p>The<strong>\u00a0Data Detection Engine<\/strong>\u00a0is an extensible query engine that uses a deep learning prediction model to analyze encrypted traffic and identify patterns across unrelated network flows.<\/p>\n<p><strong>Deep Packet Inspection\u00a0<\/strong>uses known indicators of compromise to identify threat actors and malicious tactics, techniques, and procedures across encrypted and unencrypted network traffic.<\/p>\n<p><strong>Encrypted Payload Analytics\u00a0<\/strong>detects zero-day C2 servers and new variants of malware families based on patterns found in the session size, direction, and interarrival times.<\/p>\n<p><strong>Domain Generation Algorithm\u00a0<\/strong>identifies dynamic domain generation technology used by malware to avoid detection.<\/p>\n<p><strong>Session Risk Analytics\u00a0<\/strong>is a powerful logic engine that utilizes rules that send alerts based on session-based risk factors.<\/p>\n<p>These five engines monitor east-west (internal) traffic and north-south (outgoing\/incoming) traffic to detect and flag anomalies indicative of threat activity. Alerts generated by Sophos NDR include:<\/p>\n<ul>\n<li>Network scanning activity<\/li>\n<li>Unexpected SSH sessions to never-before accessed systems<\/li>\n<li>Suspected beaconing activity<\/li>\n<li>Suspected C2 connections<\/li>\n<li>Communication on non-standard ports<\/li>\n<li>Malware present in encrypted traffic<\/li>\n<li>Encoded PowerShell execution<\/li>\n<li>Abnormal volumes of data sent<\/li>\n<\/ul>\n<h2>Leveraging Sophos NDR telemetry to stop advanced threats<\/h2>\n<p>Network security telemetry is a powerful threat hunting resource on its own, and especially useful when combined with signals from across the full security ecosystem.<\/p>\n<figure id=\"attachment_89450\" class=\"wp-caption alignright\" aria-describedby=\"caption-attachment-89450\"><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/01\/NDR-pipeline.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-89450\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/01\/NDR-pipeline.png?w=300\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/01\/NDR-pipeline.png 602w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/01\/NDR-pipeline.png?resize=300,96 300w\" alt=\"\" width=\"350\" height=\"112\" \/><\/a><figcaption id=\"caption-attachment-89450\" class=\"wp-caption-text\">Sophos MDR Detection Pipeline. Click to enlarge.<\/figcaption><\/figure>\n<p>Sophos MDR leverages alerts from Sophos and third-party network, endpoint, firewall, email, identity, and cloud solutions to accelerate threat detection and response.<\/p>\n<p>Alerts are processed through the Sophos MDR Detection Pipeline where they are transformed into normalized schema, mapped to the MITRE ATT&amp;CK\u00ae framework, and enriched with third-party intelligence. Related alerts are grouped in clusters which are then prioritized and escalated to detection specialists for investigation and response.<\/p>\n<p>Let me walk you through a couple of example scenarios where Sophos MDR leverages telemetry from Sophos NDR in conjunction with insights from other technologies.<\/p>\n<p><strong>Scenario 1<\/strong><\/p>\n<ol>\n<li>Email solution detects a message containing a malicious attachment<\/li>\n<li>Endpoint protection detects a suspicious file download<\/li>\n<li>Endpoint protection detects that an unknown process launched an interactive shell<\/li>\n<li>Sophos NDR detects a suspected Command and Control (C2) connection<\/li>\n<li>Endpoint protection detects suspected credential harvesting<\/li>\n<li>Sophos NDR detects suspected lateral movement using SSH<\/li>\n<\/ol>\n<p>By correlating the email, endpoint, and NDR alerts, Sophos MDR can quickly ascertain that there has likely been a successful phishing attack that has resulted in credential theft and lateral movement. Armed with this insight, we can step in to swiftly contain, neutralize, and remediate the attack, minimizing impact.<\/p>\n<p><strong>Scenario 2<\/strong><\/p>\n<ol>\n<li>Sophos NDR detects a device communicating on the internal network<\/li>\n<li>Endpoint protection has no known device under management<\/li>\n<\/ol>\n<p>Combining data points from these two separate technologies enables us to identify that there is an unmanaged device communicating on the network. At this point, we investigate further to determine whether it\u2019s the result of an internal user policy violation or an adversary-managed system, and then take appropriate action.<\/p>\n<h2>Already using an alternative NDR solution? No problem.<\/h2>\n<p>We understand that organizations already have security solutions in place. The challenge for many companies is how to manage, interpret, and respond to the information they provide. All too often, we speak with IT teams that are drowning in alerts or unable to digest the complex telemetry.<\/p>\n<p>With the Sophos MDR add-on integration packs, our analysts can leverage telemetry from the third-party security tools your customers are already using (including NDR solutions from Darktrace and Thinkst Canary) to detect and respond to advanced, human-led attacks. With our experts managing their security operations, they can elevate their defenses and increase return on their existing investments.<\/p>\n<h2>Learn more<\/h2>\n<p>Check out the Sophos Partner Portal to access the <a href=\"https:\/\/partners.sophos.com\/prm\/English\/s\/assets?collectionId=48255\" target=\"_blank\" rel=\"noopener\">Sophos NDR service brief and a sales deskaid<\/a> and all the service, sales, and marketing resources available for <a href=\"https:\/\/partners.sophos.com\/prm\/English\/c\/selling-sophos-mdr\" target=\"_blank\" rel=\"noopener\">Sophos MDR<\/a>.<\/p>\n<p>We&#8217;ve also created <a href=\"https:\/\/partners.sophos.com\/prm\/English\/s\/assets?collectionId=50170\" target=\"_blank\" rel=\"noopener\">promotional emails<\/a> that you can send to your customers and prospects to introduce the new offering.<\/p>\n<p>If you\u2019d like to hear what customers have to say about Sophos MDR, take a look at the independent reviews on <a href=\"https:\/\/www.gartner.com\/reviews\/market\/managed-detection-and-response-services\/vendor\/sophos\/product\/sophos-managed-detection-and-response-services\/review\/view\/4273080\" target=\"_blank\" rel=\"noopener\">Gartner Peer Insights<\/a>\u00a0and check out why we\u2019re the\u00a0<a href=\"https:\/\/news.sophos.com\/en-us\/2023\/01\/12\/sophos-mdr-is-the-1-rated-mdr-service-by-g2-peer-reviews\/\" target=\"_blank\" rel=\"noopener\">#1 rated MDR service by G2 Peer Reviews<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sophos NDR identifies rogue assets, unprotected devices, insider threats, and novel attacks to accelerate threat detection and response.<\/p>\n","protected":false},"author":11,"featured_media":3000005788,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[72],"tags":[184,202],"coauthors":[198],"class_list":["post-5787","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-products","tag-managed-detection-and-response-mdr","tag-sophos-ndr"],"jetpack_featured_media_url":"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2023\/01\/featured-image-ndr.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/posts\/5787","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/comments?post=5787"}],"version-history":[{"count":1,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/posts\/5787\/revisions"}],"predecessor-version":[{"id":5788,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/posts\/5787\/revisions\/5788"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/media?parent=5787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/categories?post=5787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/tags?post=5787"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/coauthors?post=5787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}