Fortinet officially jumped into extended detection and response (XDR) today with the launch of FortiXDR. It’s an extension of Fortinet’s endpoint detection and response (EDR) platform, and it uses artificial intelligence (AI) not only for threat response, but threat investigation as well. The vendor claims the new offering can fully automate security operations processes from detection to investigation and remediation.
“Really the difference between the FortiXDR and the FortiEDR is the difference between the E for endpoint and X for extended across the [Fortinet] Security Fabric,” said David Finger, senior director of products at Fortinet. Security Fabric is the vendor’s open security platform, and while FortiEDR already integrated with the platform, it focused more on the response side of things rather than the front-end detection and investigation, Finger said.
FortiXDR also natively integrates with the Security Fabric, which gives it visibility across a company’s environment, and it pulls telemetry from the Security Fabric for threat correlation and analysis.
“We’re taking that same paradigm, but now we’re looking beyond the endpoint and all across an organization’s Security Fabric for indications that there might be security incidents that need to be investigated and throwing them up to that cloud-native AI, which has been trained to do a broader set of investigations,” Finger explained.
The “out of the box” XDR product layers on automated analytics, incident investigation, and pre-defined responses on top of the Security Fabric, and larger organizations with more security operations staff can also integrate with FortiSIEM for multi-vendor visibility and FortiSOAR to orchestrate response. And then on the network side, the vendor’s FortiGate firewall portfolio and FortiSwitch product line also integrate with the platform to provide network traffic data and enable analytics.
Fortinet Fuses XDR With AIXDR combines elements of security information and event management (SIEM), security orchestration, automation and response (SOAR), endpoint detection and response (EDR), and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data and incident response. This improves and speeds up detection and response because it correlates threat intelligence across security products and visibility across networks, clouds, and endpoints.
With its new XDR product, Fortinet joins a crowded market with all of the major security vendors including Cisco, Palo Alto Networks, and McAfee jockeying for front-runner status.
Fortinet’s XDR approach “is largely underrated,” said Zeus Kerravala, principal analyst at ZK Research, in an earlier interview with SDxCentral. Because Fortinet started integrating all of its security and networking products into its Security Fabric five years ago, “that gives them the same kind of data structure across all of their products because all their products have the same silicon; the same operating system,” he explained. “So from that standpoint, they have a stronger offering than the market understands.”
In addition to this common data structure, Fortinet is betting on AI to give it a boost over other XDR products. It uses a patent-pending Dynamic Control Flow Engine, which is continually trained using the threat data and research feeds provided by FortiGuard Labs and real-world expertise from the company’s incident responders.
The AI engine establishes the context of an alert, performs an investigation to determine if the threat is real, and then identifies the nature and scope of the attack so the response system knows how to proceed. This saves security analysts time — and it works a lot faster than a human to detect, investigate, and respond to threats, Finger said.
Democratizing the Promise of XDREarly adopters report a 77% reduction in their overall security alerts across products, he said. “So they are getting a much more manageable set of high-fidelity alerts,” Finger added. “And an expert investigation that would take our IR folks 30 minutes of more — the AI system returns a response in 30 seconds or less.”
This also makes the promise of XDR more attainable to smaller organizations with less mature security operations, Finger said, pointing to a Gartner report on XDR. “Another benefit of XDR products is that they can provide what traditionally have been complex security operations capabilities, and make them more accessible to security teams that do not have the resources for more custom-made point solutions,” Gartner analysts Peter Firstbrook and Craig Lawson wrote in the report.
“XDR, really operating out of the box, brings that capability to a segment that otherwise wouldn’t really be able to attain it,” Finger said.
Comments