Today, endpoint detection and response (EDR) vendors are pivoting their products toward extended detection and response (XDR) solutions. XDR has the potential to become an advanced form of EDR, but the market lacks a universal standard, said Gartner Senior Director Analyst Jon Amato, who predicts that within the next 12 months, dominant players will emerge and shape the definition and standards of the XDR market.
Endpoint security, including EDR, is “hitting a place of stasis to a degree where there is a table stakes set of functionality that everybody expects to have in their products,” Amato told SDxCentral. “And EPP [endpoint protection platform] to a degree is becoming a part of XDR.”
So, what is XDR? Per Gartner’s definition, it incorporates telemetry gathering and analytics techniques that are part of EDR, extending them across multiple tools, such as network threat detection, email or web security, firewalls and deception engines, that are typically found in a medium to large enterprise environment. And this expansion allows for more straightforward detections and orchestration of responses across these tools, according to Amato.
An XDR solution commonly combines elements of security information and event management (SIEM), security orchestration, automation and response (SOAR), EDR and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data and incident response.
However, Amato pointed out every XDR vendor has a different set of capabilities they offer based on their ability to integrate, so there isn’t a standard for XDR yet.
The market lacks a universally accepted XDR definition, making it difficult to measure success or benchmark products. “Eventually, the market as a whole will standardize on that definition of what XDR actually is and thus what good XDR should be. But until that happens, whether or not any XDR implementation will turn out to have been a good thing or a bad thing might be too early to tell,” Amato said.
He expects within a year, a few dominant XDR players will emerge to shape the XDR standards, and other vendors will catch up to the market standards they set.
The multi-vendor XDR trendSo until that happens, what should you look for? The main question users should ask their XDR vendors is if their XDR product has the ability to ingest telemetry from other tools already present in the user's environment, Amato noted.
“Not every XDR has the ability to take in this extra data from every tool,” he said, and some XDRs only work with such a small number of typical enterprise tools that you have to “replace half your stuff” to get any “real use out of the EDR.”
“And that's never going to be practical for most businesses.”
On the other hand, very few XDR vendors can provide all the capabilities and tools that are needed for an XDR, so he expects the industry as a whole to embrace a multi-vendor and partnership model.
For example, Cisco's recently-announced XDR services take its own native telemetry and integrate with leading third-party vendors, including Microsoft, Palo Alto Networks and CrowdStrike to share telemetry, increasing interoperability and delivering consistent outcomes for multi-vendor environments.
Other vendors like Palo Alto Networks, CrowdStrike, and VMware are also expanding their partnerships to ingest third-party telemetry. CrowdStrike created the CrowdXDR Alliance to support this open-XDR approach.
“Making sure any XDR platform can take in data from as many third-party tools as possible … That was the trend over the last maybe year or so, and it's only going to become stronger,” Amato said.
Is XDR a better EDR?Amato saw an uptick in interest in XDR among his clients and currently, the majority of these conversations are triggered by vendors recommending it over EDR.
“Every EDR vendor is now slapping the X on their product, every single one,” he said. “The most common conversation that I am personally having is where the client went in wanting EDR and someone tried to sell them XDR and now they want to know what XDR is.”
Vendors claim XDR offers more information for threat detection, but Amato argues more information doesn't necessarily translate into better detection capabilities.
“That's the concern that I have with XDR,” he said. “Maybe that signal-to-noise ratio makes the malicious activity stand out to a greater degree. It just means that there's more information there that could be used for detections, but not necessarily that it will be detected.”
Some vendors argue XDR is the natural evolution of EDR. But is XDR a better EDR? “I think it has the potential to be, but today, it's mostly potential,” Amato said.
Will EDR leaders transition into XDR dominant players?Gartner named Microsoft, CrowdStrike, SentinelOne, Cybereason, Trend Micro and Sophos as leaders in its 2022 Magic Quadrant for Endpoint Protection Platform (EPP).
Amato admitted leaders like Microsoft and CrowdStrike would have some advantage to offer XDR but not a very large one. For example, their XDR can offer a familiar analytics interface similar to their EDR services.
But it doesn't guarantee the vendor's selection, Amato said. “The EDR vendor [who] also has an XDR offering — that almost guarantees that EDR vendor a place on the XDR shortlist. But it doesn't guarantee that they'll be the ones to be selected.”
Factors from financials to compatibility with other tools in the environment could influence the decision-making process, he added.
Comments