Cato Networks is expanding its secure access service edge (SASE) into threat detection, incident response and endpoint protection and introducing its SASE-based extended detection and response (XDR) solution, dubbed Cato XDR.
Cato XDR aims to address the limitations of traditional XDR tools, which often require the deployment of sensors and struggle with data quality when integrating third-party sensor data.
SASE offers “a single brain that makes a single decision based on all the information that it gets from all the senses,” Cato Networks Founder and CEO Shlomo Kramer told SDxCentral.
“The same value also applies to detection and response; when you've got highly contextualized data, you are able to make better detection capabilities,” he added.
Cato feeds SASE data into XDRThe incident detection and remediation process from Cato XDR is based on data from the vendor’s native sensors for its existing SASE and security capabilities including next-generation firewalls, Intrusion Prevention System, next-generation access management, Domain Name System security, secure web gateway, Cloud Access Security Broker, data loss prevention, zero-trust network access and risk-based inspection, along with its new SASE-managed endpoint protection platform.
“At a high level, a SASE-based XDR takes these enforcement points, leverages them as sensors to pull telemetry into a data lake, and then runs analytics on that information,” John Grady, principal analyst of cybersecurity at Enterprise Strategy Group (ESG), told SDxCentral in an email.
The need to integrate and normalize data that isn’t natively included in an XDR is a valid point from Cato Networks, he added. “Palo Alto Networks makes a similar point when talking about XSIAM [extended security intelligence and automation management] and how native data is stronger. The Open Cybersecurity Schema Framework was developed in part to deal with this issue.”
“But in addition to the ability to pull more native telemetry into a data lake to act on, is the efficiency aspect of leveraging what’s already deployed in the environment,” he said. “This approach will make a lot of sense for customers that are standardizing on Cato SASE to derive more benefits from their investment.”
Cato XDR also uses artificial intelligence (AI) to help identify and rank incidents and generative AI (genAI) to provide human-readable explanations of incident stories.
More vendors will tie SASE and endpoint security togetherGrady pointed out ESG’s current research has shown XDR integrations as a less critical attribute of SASE and security services edge (SSE) right now, “because on the whole, most organizations are in the early stages of adoption, and vendors are still working on converging capabilities.”
However, Cato Networks’ platform has long been purposely built for SASE, so its customers tend to adopt more features.
“I do see the value in network security vendors (especially those offering SASE) expanding into the endpoint to close gaps and fulfill the promise of enforcing security close to the user,” he said.
“With some of the continuing changes to network protocols — including DNS over HTTPS and the proposed Encrypted Client Hello — it will make sense to have an integrated endpoint presence to ensure consistent protection across all types of traffic, devices and access,” Grady added. “So this will be a trend to watch.”
Converging disparate technologies into one platformKramer argues the challenge enterprises face now in cybersecurity is not the lack of technology, but “too much technology.”
“Walk along the rows of booths at a show like RSA [conference] and you’ll see hundreds if not thousands of vendors offering solutions to specific security problems,” he said. “With each point solution they deploy, enterprises create additional threat vectors that must be patched and maintained, another sensor holding key security data, and new security skills that must be learned.”
Cato Networks has designed its SASE platform to address this issue and solve the complexity problem. The vendor's new SASE-based XDR expands this concept of a platform-based approach to security. Kramer said it goes beyond protection to detection response and beyond the network to the endpoint.
Comments