The battle over best-of-breed security versus a platform approach has officially made its way to the industry’s favorite new acronym: XDR. The ongoing debate will undoubtedly continue playing out on the blogosphere, and recently it reached a fever pitch between competitors CrowdStrike and Trend Micro.
XDR, or extended detection and response, combines elements of security information and event management (SIEM), security orchestration, automation, and response (SOAR), endpoint detection and response (EDR), and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data and incident response. Depending on their existing strengths and technology stacks, different vendors approach XDR from these different entry points — and that largely influences their strategy as well as what they designate “true XDR.”
CrowdStrike Moves From EDR to XDRCrowdStrike comes at XDR from its EDR roots. The vendor, which provides anti-virus protection, EDR, and managed threat hunting from its cloud-based platform, last month said it reached a $400 million deal to buy Humio and boost its XDR technology.
Humio provides cloud log management and observability technology. At the time, CrowdStrike CTO Mike Sentonas wrote a blog about how the Humio acquisition will allow his company to “redefine true XDR.” And in the blog, he also called out the industry for its love of buzzword bingo and XDR-washing a ton of other products that don’t really provide extended detection and response.
“XDR has already become one of those terms that has seen a huge increase in popularity in a short amount of time, but in practice — similar to the early overuse of ML — it is being used to mean many different things,” Sentonas wrote.
Later, he spoke with SDxCentral about CrowdStrike’s XDR strategy and his blog, which he described as “a little bit snarky.”
“Our industry does love an acronym,” Sentonas said. However, XDR “is one of the most overused and over abused terms that we’ve got.”
Crowdstrike’s Falcon platform pulls telemetry and hunts for threats across endpoints, identities, applications, the network edge, and clouds, he explained. It then analyzes this and third-party data in real time via a unified dashboard.
“When we talk about EDR, we don’t just take events from the endpoints,” Sentonas said. “We take telemetry from endpoints, we take cloud configuration data, we take asset data, we take identity information, we take network telemetry off of the endpoint, and we just call that EDR. That, for us, is table stakes for what you need to do to get visibility into the organization. We could have called that XDR two, three years ago.”
What Is ‘True’ XDR?One common criticism that network-centric vendors levy against EDR-turned-XDR companies is that they don’t have the network visibility needed to do true XDR.
“You need to add network,” Sentonas said. “Sure. We agree. And we’ve been doing that.”
And then he turns the tables. “What we’ve seen over the last 18 months is a lot of the legacy vendors, basically saying: we do XDR because we integrate. We’ve got an endpoint product, and we’ve got a web gateway product, and we’ve got an email filtering product. And we put all of the events into the one location, so we do XDR.”
This, he added, amounts to relabeling SIEM — and circles back to where every XDR discussion ultimately lands. SIEM remains a cautionary tale for XDR vendors, and no one wants to be the next SIEM — a once-promising technology that quickly became unruly in customers’ environments, and without orchestration or analysis became just another dumping ground for logs and data.
“That doesn’t help anyone,” Sentonas said. “XDR is not about taking as much data as you can and putting it into a massive bucket. That’s the reason organizations struggle so much with SIEM. It’s really hard to find the needle in the haystack of needles. What we don’t want to do is recreate SIEM. XDR means a lot of things to a lot of different vendors, and as an industry we have to get past that.”
CrowdStrike’s Humio AcquisitionThis, in part, is why CrowdStrike acquired Humio. Its cloud log management and observability technology will extend CrowdStrike’s security use cases, and Humio’s technology will advance CrowdStrike’s ability to provide enterprises with contextual data to solve security problems. “They minimize the challenge of trying to go through a crazy amount of volume event data,” Sentonas said about Humio’s technology. “When I looked at the market, and when I looked at the industry our team couldn’t find anything that would allow you to ingest data at the speed and the scale that Humio provides along with the maturity to be able to hunt as data is being ingested and to build detections.”
In his blog post, Sentonas says the Humio acquisition will “help accelerate our plans to deliver more of the innovation that customers need in this next generation of XDR.”
Not everyone liked this characterization. Because if the security industry has an acronym addiction, it also has a “next-gen” problem.
A few days later, Trend Micro published a blog post titled “Here we go again with ‘Next-Gen’: The new center square on the XDR buzzword bingo card.”
“And their notion of next-gen XDR or XDR 2.0, is not exclusive to CrowdStrike,” said Lori Smith, who leads product marketing for Trend Micro’s Vision One platform. “We just happened to read that blog.”
Trend Micro’s Approach to XDRTrend Micro was one of the early XDR providers, and the vendor says it has helped “hundreds” of organizations reduce their cyber risk by correlating alerts across their environments since it launched its initial XDR managed service in 2019. That one integrated detection and response capabilities across email, network, endpoint, server, and cloud workloads.
Last month the vendor extended its XDR technology with a new platform, Vision One, and the move provides “enhanced XDR,” according to Trend Micro. Purpose-built sensors natively integrate with Trend Micro’s security stack that spans network, email, endpoint, and cloud. It also includes API integrations with existing third-party products.
“With Vision One, we see an opportunity to provide additional value and serve other use cases, outside of just the detection and response, and really become a threat defense platform for security operations over time,” Smith said.
If Crowd Strike falls into the EDR-turned-XDR camp, Trend Micro, on the other hand, espouses a platform approach to XDR.
“Our value proposition is that we have such a broad product portfolio that we’re able to offer that XDR capability across multiple security layers — on the endpoint, servers and cloud, email, network — and so you really have that cross-layer detect,” Smith said. “We’re correlating the data from all of these to really see that bigger picture.”
Native Security IntegrationsTrend Micro can do this because its XDR capabilities are built on top of its native security stack, she added. “So we have that access and can pull contextual, deep data. Not just alerts, but the full telemetry underneath. And then having that intimate knowledge of our own products and our own data gives us a tremendous advantage because no one’s going to know a third-party vendor’s data as much as they know their own.”
Having said that, Trend Micro recognizes that customers’ security environments are diverse, and because of that its platform also integrates with third-party vendors with priority given to SIEM and SOAR vendors, Smith explained.
“It’s not just being able to detect the data, but then also having that integrated investigation view, so actually seeing the attack path across the layers, visualizing that attack path, and being able to click through to understand the different stages of the attack, and then respond directly from the console,” Smith said. “So with email, for example, an EDR solution can identify that something came in through email, but that’s as far as they can go. With XDR that includes email, we can trace that back to the actual mailbox, and then be able to scan all the other mailboxes in the environment to see if that malicious URL or file exists in other inboxes, and we can quarantine and stop the spread of the attack.”
This, she said, shows the value of native security integrations across a customer’s environment. “It’s everything from the detection through to the response all from a single console,” Smith explained.
Best of Breed vs. Platform SecurityTrend Micro rejects the best of breed versus platform approach to security. “We would argue that we have seen industry validation from the different industry analysts, the Magic Quadrants and Waves, and that we have leadership positions for each of those building blocks: for our email solution, for our cloud one, for our endpoint. We have the best of both worlds. You get the best of breed approach with our platform," she said.
Plus, Smith adds, customers want a platform approach to security for its simplicity and operational benefits, and also because it unifies threat detection and response.
“I’d be wary of anyone trying to claim next gen, because it’s usually a little bit biased,” Smith said. “With XDR, you have to have that correlated detection and investigation, and that response from the depth of capability across all those layers” within a customer’s environment.
Comments