Fortinet added a network detection and response (NDR) service powered by artificial intelligence (AI) into its threat detection and response portfolio.
The FortiNDR uses AI capabilities and advanced analytics to establish baselines of normal network activity and identifies deviations that may indicate cyberattacks.
It also offers a Virtual Security Analyst to offload human analyst functions by analyzing code generated by malicious traffic. The virtual security analyst is built on deep neural networks capabilities and Fortinet pre-trained it with more than 6 million malicious and safe features for IT- and OT-based malware identification and classification.
Similar to the security vendor’s other detection and response services, FortiNDR natively integrates with Fortinet Security Fabric, combined with API integrations with third-party services for a coordinated response to discovered threats. Rolled out in 2016, the Security Fabric enables visibility in real time across all applications, interoperability among security technologies, control, and automation via a single console.
“With the introduction of FortiNDR, we’re adding robust network detection and response to the Fortinet Security Fabric,” Fortinet CMO John Maddison said in a statement. “Powered by purpose-built machine learning, deep learning, pragmatic analytics, and advanced AI capabilities, FortiNDR automatically detects and responds to abnormal network activity to thwart security incidents.”
FortiNDR Rounds Out Fortinet's Detection and Response PortfolioThe new NDR service is the newest member of Fortinet’s detection and response portfolio, which also includes its endpoint detection and response (EDR), managed detection and response (MDR), and extended detection and response (XDR) services.
“As enterprises struggle to coordinate threat detection and response across individual point products, the ability for them to leverage a complete set of integrated SOC capabilities as part of a cybersecurity platform promises significant improvement in the effectiveness and efficiency of discovering and mitigating threats,” ESG senior analyst John Grady noted.
FortiNDR is for larger organizations or security teams that have already implemented EDR to add broader analytics and anomaly detection across the entire network or organization, the vendor claims.
“Fortinet’s full suite of detection and response offerings feature native integration for a coordinated response to empower security teams to move from a reactive to a proactive security posture,” Maddison said.
Comments