Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

3/1/2016
06:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Microsoft Develops Next-Generation Endpoint Security Offering

Windows 10 gets a cloud-based advanced threat endpoint detection and response (EDR) service option.

SAN FRANCISCO, CALIF. – RSA Conference 2016 – Microsoft has now joined the next-generation endpoint party with a cloud-based threat detection and response service built into Windows 10, now running in several large companies as well as in the software giant’s internal network.

The new Windows Defender Advanced Threat Protection (ATP) service will be available later this year.  “It will enable enterprises to detect, investigate, and respond to advanced attacks,” says Yusuf Mehdi, corporate vice president of Microsoft’s Windows and Devices Group. “Over time, we’ll [add] remediation tools.”

Microsoft’s new endpoint offering matches events on the endpoint with its cloud-based Security Graph, which gathers data on more than 1 billion Windows devices worldwide and detects some 1 million suspicious files each day. The service also encompasses data from Microsoft’s Digital Crimes Unit, and industry partners in the threat intelligence arena. “Once you detect something’s up or a pattern of logins looks sketchy ... it examines devices, file footprints, and has a ‘Minority Report’ feature where you can time-travel and look at the state of a machine over the last six months,” for example, Mehdi says.

The EDR service will be shipped with Windows 10, and works with Microsoft’s email protection services from Office 365 Advanced Threat Protection and Microsoft Advanced Threat Analytics. There are several early adopter companies running Windows Defender ATP now, including Avanade, Pella Windows, and TDC Hosting.

“You can enable every machine to become a sensor, and it’s powered by the cloud,” Mehdi says. “There’s no on-premise infrastructure required.”

Endpoint security has been undergoing a major renaissance over the past year with a new generation of products and services that focus on detection and incident response at the user device. The endpoint remains the most attractive and soft target for cyber criminals and cyber espionage actors to get inside the door of their targets. There's a treasure trove of intelligence about the attack at the endpoint, and EDR tools gather and store that information in response to an attack and as intel to thwart future ones.

Next-generation endpoint security startups such as Cybereason, enSilo, Hexis, SentinelOne, Tanium, Triumfant, and Ziften, have joined other existing security firms that focus on proactively monitoring and protecting the endpoint, such as Bromium, Cisco Systems, Cylance, CrowdStrike, Mandiant, Bit9/Carbon Black, and CounterTack, ForeScout, Invincea, Palo Alto Networks, and RSA Security, and others. Established security vendors such as Intel McAfee, Symantec, and Trend Micro are also entering the EDR space.

Pricing details are still in the works for Windows Defender ATP, according to Mehdi. But Microsoft indeed will be competing with the wave of EDR startups as well as established security vendors who are adding these features. The software giant is banking on its massive trove of threat and attack data in its Security Graph as a key differentiator.

“This is on the endpoint, but it can also help capture network traffic out of a given endpoint, so we’ll be able to detect the same attacks” as a FireEye or other network-sitting advanced threat detection device, says Tanmay Ganacharya, principal research lead at Microsoft.

Anti-virus software still has a role, however, Mehdi says. “You still want to have anti-virus. This is an additional threat protection and analysis tool,” he says of the new Defender service.

Microsoft is initially targeting large enterprises with the Windows endpoint service, but Mehdi says it also has potential for small- to midsized businesses.

“You need to have several layers of defenses, and Windows Defender Advanced Threat Protection adds to our defense strategy. The worldwide sampling that only Microsoft can offer helps find questionable behavior on our computers and alerts us in a timely manner, making our computers and network safer,” Fran De Hann, senior security advisor for Pella Windows, said in a statement.

Gartner estimates the EDR market to hit around $130 million in revenues in 2015, with the biggest share of the pie going to the established security vendors. EDR revenues are expected double this year, by Gartner's estimates.

Some 80% of endpoint protection platforms will include user activity monitoring and forensics capabilities associated with EDR by 2018, according to Gartner. Just 5% did so as of 2013.

Interop 2016 Las VegasFind out more about endpoint security at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
willkarter
50%
50%
willkarter,
User Rank: Apprentice
3/21/2016 | 3:20:08 PM
Microsoft Support
Well it was long over due I believe. Actually I think are made a but late entry into this. But lets see how do they take it forward.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Introducing 'Secure Access Service Edge'
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  7/3/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5604
PUBLISHED: 2020-07-09
Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remoto attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.
CVE-2020-5974
PUBLISHED: 2020-07-08
NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileges.
CVE-2020-15072
PUBLISHED: 2020-07-08
An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.
CVE-2020-15073
PUBLISHED: 2020-07-08
An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document. This also affects the Subscriber Lists section.
CVE-2020-2034
PUBLISHED: 2020-07-08
An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires some knowledge of the firewall to exploit this issue. This issue can not be exploited if GlobalProtect...