In what’s turning into a big week (and month) for extended detection and response, McAfee rolled out its new XDR platform, aptly named Mvision XDR, at its annual Mpower event today.
In addition to launching Mvision XDR, McAfee also updated its secure access service edge (SASE) platform and announced its Mvision Cloud Native Application Protection Platform (CNAPP). The latter extends McAfee’s data loss prevention, malware detection, governance and compliance capabilities for both container and OS-based workloads.
XDR combines elements of security information and event management (SIEM), security orchestration, automation and response (SOAR), endpoint detection and response (EDR), and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data and incident response.
McAfee’s XDR news comes just a day after Cisco announced XDR updates at its partner summit. Earlier this month, VMware laid out its XDR strategy and CrowdStrike waded into XDR at their respective customer events. And in late September, Microsoft touted its XDR Defender as the “most comprehensive XDR” available today.
"XDR wins if it excels in three areas: analytics for threat detection, strong/simple visualization, and automated response,” said Jon Oltsik, senior principal analyst at ESG and founder of the firm’s cybersecurity service. “McAfee needs to be competitive in all three areas. Also, XDR will be tightly coupled to MDR [managed detection and response] services as most organizations will want some type of service support — from full outsourcing to staff augmentation. McAfee needs a strong story here, alone or with partners.”
What Is McAfee XDR?McAfee made several technology investments that moved it toward XDR before XDR was even a thing, IDC Program VP Frank Dickson said. In addition to its legacy endpoint and internet security, McAfee focused on data elements such as data loss prevention, he explained. The vendor also bought Skyhigh Networks in 2017, which gave it a cloud access security broker (CASB).
“They brought those things together, and they called it Unified Cloud Edge,” Dickson said. “The approach McAfee has taken is let’s make data the center of the universe. I’m a huge fan of their approach.”
Mvision XDR builds on several existing McAfee products including its email security, EDR, cloud, and network visibility and security technologies. “McAfee, in its portfolio, has not just endpoint security as many other point-product vendors do, but we also have a secure web gateway, we have our market-leading CASB, we have data loss prevention capabilities, and we have network security capabilities,” said Ash Kulkarni, chief product officer of McAfee’s Enterprise Group. “This combination allows us to get signals from all of these different threat vectors, which gives us unprecedented visibility.”
But it’s “critical” differentiator, compared with other XDR platforms in the market, comes from McAfee’s analytics engine, Mvision Insights, Kulkarni added. It pulls telemetry from all of McAfee’s sensors, third-party partners, and global threat intelligence to help security operations centers (SOCs) proactively mitigate risks.
Mvision Insights Starring RoleThis predictive element is unique to McAfee, Oltsik said. “So, McAfee threat intelligence detects some type of threat campaign targeting companies like mine,” he said. “It can then assess if I’m vulnerable to an attack and if my controls will be able to detect this type of attack.”
McAfee’s XDR platform then uses this information and context “to guide investigations,” Kulkarni said. This data awareness, or “contextual investigation capability,” comprises the third pillar of Mvision XDR, he added.
“If a threat is detected on a machine that contains highly sensitive data, maybe because that’s a system that belongs to the CFO of the organization, you need to know that quickly so you can take remedial action faster and prioritize that over trying to protect a system that might not have that same level of sensitive data on it,” Kulkarni said. “Having that contextual awareness in your prioritization decisions, being able to connect the dots across the entire kill chain — not just from events on the endpoint but across all vectors — helps our customers drive faster, more efficient investigations.”
Competitive LandscapeIt makes sense for McAfee to move into XDR given its existing products and services, Oltsik said, adding that the platform “should be competitive with all other vendors.”
“Mvision XDR builds upon its products on endpoints, servers, email, and cloud to form a threat detection and response architecture,” Oltsik said. “McAfee anchors this architecture with things like OpenDXL and Kafka, which it has been doing for a long time.”
And in this new, competitive market, each vendor will tout its particular strength and partners to round out its missing pieces.
“For example, PAN [Palo Alto Networks] doesn’t have email security, so it will either ignore or partner for email security coverage in its XDR,” Oltsik said. “Alternatively, PAN will pivot from the firewall and cloud to XDR. Cisco will pivot from the network but also bring in email and cloud. McAfee will likely pivot from the endpoint, cloud, and IDS/IPS. McAfee also has a strong partner story with its partner network and DXL for integration.”
Comments