AT&T Cybersecurity today launched a managed extended detection and response (XDR) service. The offering is based on the service provider's Unified Security Management (USM) Anywhere platform and integrates with third-party endpoint and network platforms from SentinelOne, Microsoft, Palo Alto Networks, and Cisco, to name a few.
“This new solution is a cloud-based security platform with security threat analytics, machine learning, and deep integrations through these third-party products,” said Rakesh Shah, senior director of product management at AT&T Cybersecurity. “USM Anywhere, and the AT&T managed threat detection and response service, plus the AT&T managed endpoint service with SentinelOne, equals this new combined AT&T managed extended detection and response, or MXDR.”
While a still newish security segment, XDR combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a cloud-based platform. This centralizes security data, threat hunting, and incident response.
For AT&T’s managed XDR service, Shah noted SIEM, SOAR, and NTA capabilities come from its AlienVault acquisition, announced three years ago.
AlienVault was perhaps best known for creating the Open Threat Exchange, which is now part of AT&T Cybersecurity. Based on the AlienVault platform, the service provider's USM platform combines threat detection, incident response, and compliance management. It includes AT&T Alien Labs threat intelligence and integrations to third-party products via AlienApps.
However, not all the XDR capabilities are native to AT&T. The EDR and other endpoint protection capabilities are based on a partnership with SentinelOne. AT&T also has integrations with other endpoint platforms including Microsoft Defender and Cisco Advanced Malware Protection (AMP). The company plans to support other platforms in the future to support customers' existing EDR investments, Shah explained.
The USM Anywhere platform integrates with several vendors, including Palo Alto Networks, Zscaler, and Cisco, on the network side as well.
“While customers are looking for the easy button with XDR, it can be challenging to go all-in with a single security platform,” Shah said. “We have a number of best-in-breed partners. We will integrate with multiple of them, and we will work with customers to enable them to leverage their existing investments.”
AT&T Roots XDR In Alien Labs Intel“We have that combination of our services built on the USM Anywhere platform with SentinelOne, but Alien Labs is really key… [to] providing this predictive detection and identification of threats,” Shah said.
As ransomware has become a popular and financially lucrative option for hackers, Alien Labs’ research team has focused much of its attention on ransomware, among other threats.
Alien Labs researchers use AT&T's Open Threat Exchange platform to automate the discovery of infrastructure used by threat actors, specifically for major ransomware operations, Shah said. Many of these machine learning and security analytics capabilities are now integrated into AT&T's managed XDR service.
Pulling Together XDR and SASEIn addition to investing in Alien Labs, AT&T is exploring an integration between its XDR and secure access service edge (SASE) services, Shah said. “Given our position as the network, we can do some really unique things there, so we're really excited about pulling together XDR and SASE in the long run.”
SASE is a network architecture that combines SD-WAN functionality with cloud-based security services like secure web gateways, cloud access security brokers, firewalls, and zero-trust network access.
AT&T recently announced a number of SASE partnerships including Fortinet and Palo Alto Networks.
Comments