Cato Networks launched its new managed detection and response (MDR) platform that is designed to cut deployment times from months to minutes.
The network-based MDR 2.0 platform approach to MDR means it can avoid the 30 to 90 days required by competing vendors to establish a baseline.
“If you are a Cato customer, if you are already connected to our private backbone, there is no ‘oh, give us a two or three months to understand what's going on.’ You want it on, it's on,” explained Etay Maor, senior director of security strategy at Cato.
MDR 2.0 is unique in that it doesn’t require any additional hardware or endpoints agents to collect data and operates on the network level, Maor added. The platform is able to achieve this by using a combination of machine learning and artificial intelligence (AI) models to cull through network data harvested from the company’s secure access service edge (SASE) and threat intelligence database.
This database includes enterprise traffic patterns over time, storing the metadata for every IP address, session, and flow crossing the Cato global backbone. The benefit to Cato customers turning on MDR for the first time is they can take advantage of threat intelligence gathered from existing customers.
Cato Boasts Better Visibility, Faster ResponseThe approach has numerous advantages, according to Maor. “If someone wants access to an endpoint, it’s really easy to knock out the antivirus, anti-malware,” he said.
“It's like breaking into somebody's house. If I'm in your house, I can turn off the alarm, I can make it seem as if everything is okay,” Maor said. “But if I go on the road and get stopped by the police, it's going to be very hard for me to explain to the police why I have that stuff in my trunk and why I'm going to that destination. That is the difference between network threat hunting and endpoints of hunting.”
By shifting this functionality to the network layer, Maor explained that it’s possible to apply the same kind of detection and response functionality to all devices on the network, not just company-managed ones.
“On the network level I can do all kinds of things and see all kinds of elements that security solutions won't even prioritize,” he said, adding that in an environment where managed and unmanaged devices are connecting to the network, a network-centric approach to MDR is the only effective way to detect threats.
In many cases customers don’t even know what is happening on their network, he said. “I was shocked to see TikTok being one of the top applications use on our clients networks.”
Cato Champions Managed RemediationThe service also includes one-on-one support from a dedicated security expert, and an automated security assessment of more than 70 best practices to ensure customers are starting on a solid footing.
“We try to identify anything that’s misconfigured and we compare it to what our best practices are, and what we do is we create this security posture document,” Maor said. “It's kind of like a security hygiene report.”
And when a threat is detected, Cato confirms its veracity, contains it at the network level for all MDR subscribers, alerts the customer, and provides recommendations for local containment. If necessary, Cato can also provide access to a security expert to handle any local remediation remotely.
Comments