Improving Incident Response via Extended and Managed Detection and Response
CIOREVIEW >> Identity Governance and Administration >> NEWS

SWAROVSKI

Matthias Gander, Senior Manager Information Security

Improving Incident Response via Extended and Managed Detection and Response

Matthias Gander, Senior Manager Information Security
Matthias Gander, Senior Manager Information Security, SWAROVSKI

The response is necessary when everything before already has failed. What is a good metric to measure the improvement thereof? Likely, dwell time. This includes mean time to detect (MTD) and mean time to recover (MTR). On average, an advanced adversary resides in the network about 60 days (Fireye) before it is fully eradicated, and systems are recovered. The good news is that it is getting better, because, among other things, detective and responsive technology such as extended detection and response (XDR). From an industry outlook perspective, the size of the extended detection and response market in the world was estimated at $ 754.8 million in 2022, and according to Grand View Research, it is anticipated to grow at 20.7 percent annually from 2023 to 2030. It is, therefore, high time to discuss it.

Before we discuss XDR we should talk about precursor technologies, endpoint detection and response (EDR), and endpoint protection platforms (EPP).

Endpoint Detection and Response (EDR) and Endpoint Protection Platform (EPP)

The terms were coined in 2013 by Gartner. Both are solutions for endpoint security that have different roles and functions. EPP operates independently of supervision, passively preventing known and often unknown threats. EPP is a first line of defense that can protect against various attacks, it often entails technology such as AV, data encryption, loss prevention, device control (USB and more), and data integrity mechanisms. EDR, on the other hand, is an actively used incidence response solution for security teams. EDR enables detection and response for (advanced) threats on an endpoint, especially those that EPP cannot detect, which, unfortunately, is common. Their focus is breach-centered and they shine when it comes to investigating potential adversary behavior (usually MITRE Att&ck centered) allowing analysts to investigate all devices at once. Corporations leveraging EDR technology mostly have an assumed breach mindset at heart. In recent years, security vendors have developed hybrid EPP and EDR systems that combine elements of both solutions. Those technologies drastically shorten MTD and MTR, hence, our dwell time. But as it turns out, for advanced persistent threats (APTs) focusing solely on endpoints is not enough and our MDR and MTD are still too high.

 If XDR is on the roadmap but a dedicated response team seems daunting, a managed detection and response (MDR) service is an option 

 

Fusing Detection and Response Capabilities: From EDR to XDR

Every attack, even an advanced one, leaves traces but often in silos. Furthermore, responses manual or automated necessitate additional tooling and increases complexity for analysts (which translates to delays in our dwell time metric). Extended detection and response (XDR) solutions are a rather recent development (2018) promising to remedy the situation. These solutions collect and correlate data from multiple security products, such as network detection and response (NDR), intrusion detection systems, identity and access management, mail-gateway, cloud access security brokers, and more, not unlike SIEM, to improve threat detection and additionally provide incident response capability, the R in XDR, for instance, through APIs. What does a response look like? Block a port, quarantine files, block a domain on the mail gateway, delete mails in affected inboxes, disable a user, and so on, all to contain, eradicate, and recover faster (yes, improve MTD and MTR).

XDRs come in various flavors, the most prominent ones are, Native XDR and Open (Hybrid) XDR. In short, when using a Native XDR solution, security technologies from a single vendor are integrated to gather data and carry out threat detection and response tasks. On the other hand, an Open (Hybrid) XDR solution makes use of the security architecture already in place within a company. Open XDR solutions can link with existing infrastructure rather than pulling out and replacing present security technologies. Which variant is the right choice is dependent on the corporation, both have merits. Open XDR solutions are less of a vendor lock-in, parts can be exchanged from different (compatible) vendors, and one can still stick to solutions that have proven themselves in the company. Native solutions provide an even better inclusion of the existing toolset, albeit from the same vendor, likely with less management overhead.

Understanding If XDR is Suitable for the Corporation

XDR is the logical continuation of (hybrid) EDR. As we have seen above, it allows to fuse sensors to allow faster detection through correlation or artificial intelligence, yet also provides responsive capabilities. But its suitability for your corporation depends. It boils down to your threat model and the maturity of your security program (and willingness to spend).

The first point is easy. If your threat model entails APTs that go beyond your garden variety ransomware actor, then XDR is the right direction. Given that big-game hunting (BGH) ransomware actors learn from nation-state actors who sometimes collude with them (like Russian ransomware groups) are well-funded and grow in sophistication it’s warranted to look beyond EDR.

The second point is more difficult. XDR more so than EDR necessitates a certain maturity in your information security program. If a corporation is already failing at security, for example, asset management, vulnerability management, information protection processes, and procedures or protective technologies (including hardening), and doesn’t have any maturity in detective and responsive capability, then it is highly likely that the introduction of sophisticated detection capability and response will be difficult. Furthermore, if there are no plans to significantly invest in a response team (or MDR), keep in mind, it is they who reduce the dwell time, by properly investigating, documenting, remediating, and learning from alerts. From my experience, even an EDR is wasted. XDRs are designed to make things simpler by unifying disparate event information and bolstering response capabilities (beyond what an EDR could do). But keep in mind, these systems need to be configured, and maintained, new sources embedded, automated responses defined, rules created, and triggered events need to be investigated.

Outsourcing Response Capability

If XDR is on the roadmap but a dedicated response team seems daunting, a managed detection and response (MDR) service is an option. Often, but not always, MDR providers offer a readyto-use experience using a predefined technology stack. The list of service providers is vast, most EDR and XDR vendors provide such services but apart from the known players, new names pop up all the time. MDR provides security operations center (SOC) functions, that is, it can provide 24/7 manual and automated threat hunting, security analytic creation for detection (think YARA rules, SIEM rules), and response capabilities via XDR, EDR, and other technologies through security orchestration and automated response (SOAR). MDR providers come in distinct flavors, or maturities, ranging from basic services, such as hunting and alerting to managing EDR or XDR to going the full mile with on-site manual incident response. Since attacks get more sophisticated response capabilities also need to improve, yet this comes at a premium, in-house talent and experience are scarce, and hiring analysts is expensive. It is no wonder many corporations turn to MDR services, which Emergen Research forecasts to grow 18 percent annually to approximately 22 billion in 2030.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.