The technology industry loves its buzzwords, but “open” may be the most overused and abused. Depending on who you are talking to, open may mean anything from fully open source to API integrations, and the latest in a very long list of verbiage offenders is extended detection and response (XDR).

XDR vendors have recently glommed on to the open label for their products and approaches, and none of their definitions of open XDR are the same.

XDR combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a cloud-based platform. This centralizes security data, threat hunting, and incident response.

Vendors generally use open to mean heterogeneous XDR, but “there are some subtleties,” said Jon Oltsik, ESG senior principal analyst and fellow.

“Some vendors want to offer most of the components, but also build ecosystems for partners to participate in their XDR architecture,” he wrote in response to questions. “In this case, they are ‘open’ to third parties, but only in support of their offering. In other cases (Reliaquest, Stellar Cyber, etc.) ‘open’ XDR is sort of an abstraction layer that sits above all other detection controls, acting as a central management plane. These tools connect to other technologies, centralize visibility, and adding analytics.”

Stellar Cyber, Exabeam, Hunters, ReliaQuest Raise Open XDR Flag

Stellar Cyber, in fact, calls its platform “Open XDR.” It integrates with customers’ existing third-party EDR, SIEM, NTA, and user and entity behavior analytics (UEBA) tools. The platform aggregates and correlates threat data, applies artificial intelligence (AI) based analytics to inspect it, and automatically responds to threats through a single console.

Exabeam takes a similar approach to XDR. Like Stellar, Exabeam is a next-generation SIEM that more recently started talking about its XDR.

Exabeam’s Fusion XDR product combines its UEBA; threat detection, investigation, and response (TDIR) analytics; and “hundreds” of pre-built, third-party security integrations, along with its newer TDIR use-case packages. These provide prescriptive workflows and other content around data sources, detection models, watchlists, investigation checklists, and response playbooks designed to assist security analysts.

Also similar to Stellar, Exabeam calls its approach “open XDR,” as opposed to a closed, “native XDR” ecosystem or a single-vendor platform. In an earlier interview, Exabeam Chief Product Officer Adam Geller said Exabeam’s open approach gives customers more flexibility. It’s vendor agnostic, and it works with the security products and tools that they’re already deployed in their security operations center.

“For the most part, people’s SecOps approach is a collection of lots and lots of different tools and technologies,” he said. “Security has not lived up to the Salesforce-for-security analogy that a lot of security vendors like to target or postulate can that happen. Security’s not there.”

Hunters and ReliaQuest also espouse an open XDR strategy. Hunters XDR is another vendor-agnostic threat detection and response platform that ingests security telemetry from all sources in a customers’ environment.

Similarly, ReliaQuest’s GreyMatter Open XDR platform uses its proprietary integration engine called Universal Translator, along with open APIs, to integrate with more than 60 technology partners spanning SIEM, EDR, anti-virus, firewall, and cloud platform providers.

“XDR is thrown around a lot, and there’s a lot of buzz around it,” ReliaQuest CEO Brian Murphy said in an interview with SDxCentral. “We are technology independent, and so we understand that our customers in the enterprise use a multitude of tools and technologies that do different things. Our job is to get them visibility across that spectrum. We take the perspective that it’s about the outcome for the customer, and a problem that we solve for the customer, not about making sure that one technology platform rules them all.”

Open Ecosystems, APIs

While these security analytics vendors’ sit on top of third-party detection tools and centralize visibility and threat hunting, still other security vendors including VMware and Netskope take an open ecosystem approach to XDR that lets partners connect via APIs — and fill XDR technology holes that they don’t already provide.

For example: Cybereason’s an EDR vendor, and while it doesn’t have in-house SIEM and SOAR capabilities, its XDR focuses on what it does best: detection and response, and proactive threat hunting. And it also pulls data from customers’ existing SIEMs and other sources, both through a partner program and open APIs.

“What the API route does: It lets vendors build a consortium or partnership, it provides a higher level of fidelity and threat intelligence, but to me that’s not really open XDR. That’s just integrated XDR,” said Zeus Kerravala, principal analyst at ZK Research. “Open XDR would mean fully open, but that will require a lot of work for the entire industry, and frankly I’m not sure that most of vendors are willing to do that.”

Open XDR? Or Hybrid XDR?

Instead of calling it open XDR, Forrester Research uses “hybrid” XDR. “I am not a huge fan of the open XDR terminology,” Forrester analyst Allie Mellen said. “Because I, myself, come from a development background, and when I talk to people who are technical in the space, they hear open XDR and they think it has something to do with open source.”

So instead of calling it open or closed, Forrester uses hybrid and native with “hybrid XDR being vendors that choose to build a series of partnerships and integrations with other security vendors for these additional sources of telemetry,” Mellen said, citing CrowdStrike as an example.

Native XDR, on the other hand, “is really all about putting the vendor’s own portfolio forward, first and foremost, and really prioritizing the integrations that they have with their own existing technology,” Mellen said. “Typically, this is done by those vendors who have more of a suite of offerings.” These include Microsoft, Sophos, and TrendMicro, she said.

These two differing strategies is similar to the argument over best-of-breed versus a platform approach to security, and Mellen said she believes that ultimately the XDR market will remain a mix of hybrid and native. Plus, even native XDR vendors realize that they need to support other third-party tools and threat sources via integrations.

“Ultimately, I think we’ll start to see a blending where hybrid XDR vendors start to build in more of their own capabilities to put them in more of the native category, and then the native vendors start supporting more third-party telemetry sources to put them more in the hybrid category,” she said.

Can XDR Be Open Without Standards?

There’s also a strong argument to be made that you can’t have open XDR (or open anything) without industry standards. When asked if you can have one without the other, “I would say the answer is really no, but vendors are clever in how they get around this,” Oltsik said, citing things like open APIs, developer support, partner ecosystems, and sales and marking programs for partners. “These vendors may be ‘open’ to working with others, but on their terms.”

Oltsik said standards including OASIS’ Open Cybersecurity Alliance (OCA) and openC2 “have some promise, but many vendors aren’t onboard, the standards are early on, and the efforts seem dominated by engineers.”

The Open Cybersecurity Alliance launched in late 2019, and it aims to make the myriad of security products on the market interoperable using open source code as well as open standards and protocols.

At launch, IBM contributed STIX Shifter, an open source library that can identify information about potential threats within a variety of data repositories and translate it into a format that can be digested and analyzed by any security tool that has this standard enabled. A couple months later McAfee released the Open Data Exchange Layer (OpenDXL) Ontology, which is an open messaging framework to develop and share integrations with other tools.

“IBM and McAfee are championing OCA, so there are at least a few XDR vendors pushing on this.” Oltsik said. “I’d like to see others join, but don’t expect industrywide agreement anytime soon.”