Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

3/1/2016
06:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Microsoft Develops Next-Generation Endpoint Security Offering

Windows 10 gets a cloud-based advanced threat endpoint detection and response (EDR) service option.

SAN FRANCISCO, CALIF. – RSA Conference 2016 – Microsoft has now joined the next-generation endpoint party with a cloud-based threat detection and response service built into Windows 10, now running in several large companies as well as in the software giant’s internal network.

The new Windows Defender Advanced Threat Protection (ATP) service will be available later this year.  “It will enable enterprises to detect, investigate, and respond to advanced attacks,” says Yusuf Mehdi, corporate vice president of Microsoft’s Windows and Devices Group. “Over time, we’ll [add] remediation tools.”

Microsoft’s new endpoint offering matches events on the endpoint with its cloud-based Security Graph, which gathers data on more than 1 billion Windows devices worldwide and detects some 1 million suspicious files each day. The service also encompasses data from Microsoft’s Digital Crimes Unit, and industry partners in the threat intelligence arena. “Once you detect something’s up or a pattern of logins looks sketchy ... it examines devices, file footprints, and has a ‘Minority Report’ feature where you can time-travel and look at the state of a machine over the last six months,” for example, Mehdi says.

The EDR service will be shipped with Windows 10, and works with Microsoft’s email protection services from Office 365 Advanced Threat Protection and Microsoft Advanced Threat Analytics. There are several early adopter companies running Windows Defender ATP now, including Avanade, Pella Windows, and TDC Hosting.

“You can enable every machine to become a sensor, and it’s powered by the cloud,” Mehdi says. “There’s no on-premise infrastructure required.”

Endpoint security has been undergoing a major renaissance over the past year with a new generation of products and services that focus on detection and incident response at the user device. The endpoint remains the most attractive and soft target for cyber criminals and cyber espionage actors to get inside the door of their targets. There's a treasure trove of intelligence about the attack at the endpoint, and EDR tools gather and store that information in response to an attack and as intel to thwart future ones.

Next-generation endpoint security startups such as Cybereason, enSilo, Hexis, SentinelOne, Tanium, Triumfant, and Ziften, have joined other existing security firms that focus on proactively monitoring and protecting the endpoint, such as Bromium, Cisco Systems, Cylance, CrowdStrike, Mandiant, Bit9/Carbon Black, and CounterTack, ForeScout, Invincea, Palo Alto Networks, and RSA Security, and others. Established security vendors such as Intel McAfee, Symantec, and Trend Micro are also entering the EDR space.

Pricing details are still in the works for Windows Defender ATP, according to Mehdi. But Microsoft indeed will be competing with the wave of EDR startups as well as established security vendors who are adding these features. The software giant is banking on its massive trove of threat and attack data in its Security Graph as a key differentiator.

“This is on the endpoint, but it can also help capture network traffic out of a given endpoint, so we’ll be able to detect the same attacks” as a FireEye or other network-sitting advanced threat detection device, says Tanmay Ganacharya, principal research lead at Microsoft.

Anti-virus software still has a role, however, Mehdi says. “You still want to have anti-virus. This is an additional threat protection and analysis tool,” he says of the new Defender service.

Microsoft is initially targeting large enterprises with the Windows endpoint service, but Mehdi says it also has potential for small- to midsized businesses.

“You need to have several layers of defenses, and Windows Defender Advanced Threat Protection adds to our defense strategy. The worldwide sampling that only Microsoft can offer helps find questionable behavior on our computers and alerts us in a timely manner, making our computers and network safer,” Fran De Hann, senior security advisor for Pella Windows, said in a statement.

Gartner estimates the EDR market to hit around $130 million in revenues in 2015, with the biggest share of the pie going to the established security vendors. EDR revenues are expected double this year, by Gartner's estimates.

Some 80% of endpoint protection platforms will include user activity monitoring and forensics capabilities associated with EDR by 2018, according to Gartner. Just 5% did so as of 2013.

Interop 2016 Las VegasFind out more about endpoint security at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
willkarter
50%
50%
willkarter,
User Rank: Apprentice
3/21/2016 | 3:20:08 PM
Microsoft Support
Well it was long over due I believe. Actually I think are made a but late entry into this. But lets see how do they take it forward.
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16531
PUBLISHED: 2019-09-20
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
CVE-2019-9717
PUBLISHED: 2019-09-19
In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex format argument to sscanf.
CVE-2019-9719
PUBLISHED: 2019-09-19
A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.
CVE-2019-9720
PUBLISHED: 2019-09-19
A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.
CVE-2019-16525
PUBLISHED: 2019-09-19
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.