DefinitionNDR (Network Detection and Response) is a solution that continuously analyzes network traffic to identify suspicious behavior, such as lateral movement, communication with command-and-control servers and data exfiltration, and to support response.
How it works
NDR receives a copy of the traffic (via port mirroring, TAPs or cloud sensors) and flow metadata. From this, it builds a baseline of what is normal in the environment and flags deviations. Typical signals include:
- Lateral movement, such as internal scanning and unusual use of administrative protocols.
- Command and control: periodic connections to suspicious destinations or traffic that mimics legitimate protocols.
- Exfiltration: atypical volumes of data leaving the network.
- Agentless devices, such as IoT, OT equipment and appliances, which can only be observed through the network.
Even with encrypted traffic, metadata such as destination, volume, frequency and connection characteristics still reveal a great deal.
NDR vs EDR
EDR sees in detail what happens inside each endpoint, but only where an agent is installed. NDR sees communication between all devices, including those that cannot run an agent. An attacker can disable an EDR agent; hiding their own network traffic is much harder. That is why the two views complement each other.
In practice
NDR is one of the layers that feed an XDR strategy: correlating a network alert with what happened on the endpoint and in identity speeds up investigation. Like other tools, it depends on analysts who know the environment to separate the unusual from the truly malicious.
Network Secure brings network visibility into its Open XDR platform.
Frequently asked questions
What is the difference between NDR and IDS?
Traditional IDS relies mainly on signatures of known attacks. NDR adds behavioral traffic analysis along with investigation and response capabilities.
Does NDR work with encrypted traffic?
Largely, yes. Even without seeing the content, NDR analyzes metadata such as destination, volume, frequency and connection characteristics to identify suspicious behavior.