McAfee connected its extended detection and response (XDR) and secure access service edge (SASE) platforms in a move the vendor says provides better threat protection and simplifies the security operations center (SOC).
The XDR update, available now, allows McAfee’s Mvision XDR platform to correlate all of the telemetry that its SASE technologies collect to find more threats, and thus boost its automated investigation and response.
“When tracking a cyber event in your environment, you want to have visibility from different perspectives,” said McAfee SVP and CTO Steve Grobman, who is also delivering an RSA Conference keynote. “Clearly, the endpoint is critical and that’s where traditional EDR was a major step forward in that you could see what an advanced actor is doing from a behavioral perspective. The problem is: There’s other critical data that’s coming from the Unified Cloud Edge.”
Mvision Unified Cloud Edge comprises the security pieces of McAfee’s SASE architecture, which includes its secure web gateway (SWG), cloud access security broker (CASB), and data loss prevention (DLP) technologies.
Meanwhile, its Mvision XDR platform builds on several existing McAfee products including its email security, endpoint detection and response (EDR), cloud, and network visibility and security technologies. By updating its XDR to now also correlate SASE attack telemetry, McAfee “empowers an investigator to really interact across the platform and be able to pull in things that are unique to McAfee, like Mvision Insights,” Grobman said.
Mvision Insights is the company’s analytics engine, which provides proactive security and, thus, prevent attacks from entering an organization’s environment. It pulls telemetry from all of McAfee’s sensors as well as third-parties and global threat intelligence to help companies proactively prioritize threats and mitigate risks. Company executives and analysts alike often point to this predictive threat hunting capability as something that’s unique to McAfee’s XDR.
With Mvision Insights, “we’re looking at not only the information and the events that are coming out of the customer’s own environment, but understanding the context of that as it relates to what’s being seen at a global level or, at other environments that are similar in the sector or geography, things of that nature,” Grobman said. “So putting all of that together is really what the updated XDR platform is all about.”
This becomes especially important as organizations face increasingly sophisticated attacks from human attackers (as opposed to bots), like we saw with SolarWinds and the more recent DarkSide ransomware attack against Colonial Pipeline.
“Whether it’s human-aided ransomware or second-stage attacks, the common theme is there’s a human actor on the other side,” Grobman said. “And in those scenarios, having strong XDR capabilities is really critical because it’s what will allow your cyber defenders to have the ability to track, detect, and ultimately thwart some of those more advanced scenarios.”
Comments