XDR

What is XDR?

XDR is an abbreviation for eXtended Detection and Response, and is a concept that improves visibility and detection by cross-sectionally analyzing information from various sensors to protect organizations and companies.

Recently, it has rapidly become a topic of discussion as a keyword for cyber security measures, but in fact, it is not a completely new concept, but a concept that includes existing security technologies such as "EDR" and "SIEM". As a result of accumulating countermeasures against threats and introducing various products, have you fallen into a situation where operations cannot keep up? In the future, companies will be required to utilize this XDR concept, combine the security products necessary for each customer, and equip them with optimal capabilities (organizational capabilities).

Definition of XDR

Definition by Macnica

By cross-sectionally analyzing information from various sensors
A concept that improves visibility and detection to protect organizations and companies
Definition by Macnica

Why is XDR attracting attention now?

Emergence of EDR/NDR

  • Due to the sophistication of attack methods, it has become difficult to detect with conventional products.
  • Need to take countermeasures assuming intrusion
  • With the advent of EDR/NDR, detection capabilities have dramatically improved
Emergence of EDR/NDR

Challenges of EDR/NDR

Although EDR and NDR have dramatically improved their detection capabilities, there are still issues. Addressing these issues requires personnel with advanced knowledge and experience, and the operational load is also high. As a result, there will be a shortage of personnel, and it will be impossible to allocate resources to the review and planning of the overall picture of security that should be done.

high volume ofalerts
It is difficult to judgeover-detection and correct detection
Need to matchmultiple sourcesto understand the whole attack
Telework and cloud utilization make the IT environmentmorecomplex
Advancedknowledge and experiencerequired
Highoperational load
understaffed_
Challenges of EDR/NDR

Introducing XDR

  • XDR solves these problems.
  • It has the following three characteristics.
Extended inspection range of EDR and NDR
Correlation analysis of information from multiple sensors
Improvedetection capabilities andreduceoperational load

Building blocks of XDR

  • XDR is roughly divided into a data source part and a data store and analysis engine part.
  • The data source part refers to security products that exist in the internal network such as EDR, NDR, SWG and IDaaS.
  • XDR collects logs from these multiple security products and analyzes them on a single platform.

Definition by Macnica

Definition by Macnica

Benefits of XDR

6 Benefits of Improving Detection Capability and Reducing Operational Burden

Detect breaches thatsensors alone cannot detect
Visibilityacross breaches
Reducefalse positives
Management on asingle platform
Incidentprioritization
Responseautomation

Inquiry/Document request

In charge of Macnica XDR Co., Ltd.

Mon-Fri 8:45-17:30