Trend No. 1: Extended Detection and Response Capabilities Are Emerging toImprove Detection Accuracy and Security ProductivityXDR describes a security incident detection and response platform that automatically collects andcorelates data from multiple security products. It is an expansion of the concept driving endpointdetection and response (EDR) solutions (see “Market Guide for Endpoint Detection and ResponseSolutions”). Pioneering XDR tools are delivered by security solution providers that have a broadportfolio of products and select partners’ products unified by the XDR console. Current XDR focusis primarily on protecting end users and the apps and data they consume, Early candidates includeCisco, Fortinet, McAfee, Microsoft, Palo Alto Networks, Trend Micro and Symantec. Although XDRtools are similar in function to SIEM and security orchestration, automation and response (SOAR)tools, they are primarily differentiated by the level of integration at deployment and the focus onincident response. The two primary requirements of an XDR system are centralization of normalizeddata and a centralized incident response capability that can change the state of individual securityproducts as part of the remediation process (see Figure 1). The primary goals of an XDR solution areto increase detection accuracy by corelating threat intelligence and signals across multiple securitysolutions, and improved security operations efficiency and productivity.
Trend No. 1: Extended Detection and Response Capabilities Are Emerging to<br>Improve Detection Accuracy and Security Productivity<br>XDR describes a security incident detection and response platform that automatically collects and<br>corelates data from multiple security products. It is an expansion of the concept driving endpoint<br>detection and response (EDR) solutions (see “Market Guide for Endpoint Detection and Response<br>Solutions”). Pioneering XDR tools are delivered by security solution providers that have a broad<br>portfolio of products and select partners’ products unified by the XDR console. Current XDR focus<br>is primarily on protecting end users and the apps and data they consume, Early candidates include<br>Cisco, Fortinet, McAfee, Microsoft, Palo Alto Networks, Trend Micro and Symantec. Although XDR<br>tools are similar in function to SIEM and security orchestration, automation and response (SOAR)<br>tools, they are primarily differentiated by the level of integration at deployment and the focus on<br>incident response. The two primary requirements of an XDR system are centralization of normalized<br>data and a centralized incident response capability that can change the state of individual security<br>products as part of the remediation process (see Figure 1). The primary goals of an XDR solution are<br>to increase detection accuracy by corelating threat intelligence and signals across multiple security<br>solutions, and improved security operations efficiency and productivity.
正在翻译中..