Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

3/1/2016
06:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Microsoft Develops Next-Generation Endpoint Security Offering

Windows 10 gets a cloud-based advanced threat endpoint detection and response (EDR) service option.

SAN FRANCISCO, CALIF. – RSA Conference 2016 – Microsoft has now joined the next-generation endpoint party with a cloud-based threat detection and response service built into Windows 10, now running in several large companies as well as in the software giant’s internal network.

The new Windows Defender Advanced Threat Protection (ATP) service will be available later this year.  “It will enable enterprises to detect, investigate, and respond to advanced attacks,” says Yusuf Mehdi, corporate vice president of Microsoft’s Windows and Devices Group. “Over time, we’ll [add] remediation tools.”

Microsoft’s new endpoint offering matches events on the endpoint with its cloud-based Security Graph, which gathers data on more than 1 billion Windows devices worldwide and detects some 1 million suspicious files each day. The service also encompasses data from Microsoft’s Digital Crimes Unit, and industry partners in the threat intelligence arena. “Once you detect something’s up or a pattern of logins looks sketchy ... it examines devices, file footprints, and has a ‘Minority Report’ feature where you can time-travel and look at the state of a machine over the last six months,” for example, Mehdi says.

The EDR service will be shipped with Windows 10, and works with Microsoft’s email protection services from Office 365 Advanced Threat Protection and Microsoft Advanced Threat Analytics. There are several early adopter companies running Windows Defender ATP now, including Avanade, Pella Windows, and TDC Hosting.

“You can enable every machine to become a sensor, and it’s powered by the cloud,” Mehdi says. “There’s no on-premise infrastructure required.”

Endpoint security has been undergoing a major renaissance over the past year with a new generation of products and services that focus on detection and incident response at the user device. The endpoint remains the most attractive and soft target for cyber criminals and cyber espionage actors to get inside the door of their targets. There's a treasure trove of intelligence about the attack at the endpoint, and EDR tools gather and store that information in response to an attack and as intel to thwart future ones.

Next-generation endpoint security startups such as Cybereason, enSilo, Hexis, SentinelOne, Tanium, Triumfant, and Ziften, have joined other existing security firms that focus on proactively monitoring and protecting the endpoint, such as Bromium, Cisco Systems, Cylance, CrowdStrike, Mandiant, Bit9/Carbon Black, and CounterTack, ForeScout, Invincea, Palo Alto Networks, and RSA Security, and others. Established security vendors such as Intel McAfee, Symantec, and Trend Micro are also entering the EDR space.

Pricing details are still in the works for Windows Defender ATP, according to Mehdi. But Microsoft indeed will be competing with the wave of EDR startups as well as established security vendors who are adding these features. The software giant is banking on its massive trove of threat and attack data in its Security Graph as a key differentiator.

“This is on the endpoint, but it can also help capture network traffic out of a given endpoint, so we’ll be able to detect the same attacks” as a FireEye or other network-sitting advanced threat detection device, says Tanmay Ganacharya, principal research lead at Microsoft.

Anti-virus software still has a role, however, Mehdi says. “You still want to have anti-virus. This is an additional threat protection and analysis tool,” he says of the new Defender service.

Microsoft is initially targeting large enterprises with the Windows endpoint service, but Mehdi says it also has potential for small- to midsized businesses.

“You need to have several layers of defenses, and Windows Defender Advanced Threat Protection adds to our defense strategy. The worldwide sampling that only Microsoft can offer helps find questionable behavior on our computers and alerts us in a timely manner, making our computers and network safer,” Fran De Hann, senior security advisor for Pella Windows, said in a statement.

Gartner estimates the EDR market to hit around $130 million in revenues in 2015, with the biggest share of the pie going to the established security vendors. EDR revenues are expected double this year, by Gartner's estimates.

Some 80% of endpoint protection platforms will include user activity monitoring and forensics capabilities associated with EDR by 2018, according to Gartner. Just 5% did so as of 2013.

Interop 2016 Las VegasFind out more about endpoint security at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
willkarter
50%
50%
willkarter,
User Rank: Apprentice
3/21/2016 | 3:20:08 PM
Microsoft Support
Well it was long over due I believe. Actually I think are made a but late entry into this. But lets see how do they take it forward.
For Cybersecurity to Be Proactive, Terrains Must Be Mapped
Craig Harber, Chief Technology Officer at Fidelis Cybersecurity,  10/8/2019
A Realistic Threat Model for the Masses
Lysa Myers, Security Researcher, ESET,  10/9/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17593
PUBLISHED: 2019-10-14
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
CVE-2019-17594
PUBLISHED: 2019-10-14
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-17595
PUBLISHED: 2019-10-14
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-14823
PUBLISHED: 2019-10-14
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to...
CVE-2019-17592
PUBLISHED: 2019-10-14
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when using the cast option.