Sophos: greater visibility with the Endpoint Detection and Response

in sophos •  6 years ago 

Automation affects not only traditional industries, but also cybercrime. In this case, there is no mention of repercussions on the world of work, but the ability of crackers to automatically identify possible victims and then act manually during the attack. Sophos Intercept X for Endpoint Detection and Response Servers (EDR) offers better protection in corporate networks of any size thanks to the ability to analyze the infrastructure in real time and monitor it for anomalies and possible attacks.

Sophos Intercept X for Endpoint Detection and Response Servers: visibility is the key to excellent defense servers because of two variables that are becoming increasingly the primary target for cyber assaults: on the one side, the quantity of precious information they contain or the chance of using them as a "support base" to launch further assaults; on the other side, the reduced frequency with which they are updated as a result of further assaults.

Therefore, the servers are in the unpleasant condition of needing to be protected more, but not being able to be straight. However, having a clear image of the scenario makes it possible to intervene more rapidly in the case of suspect movements: knowing if behaviors outside the norm within the corporate infrastructure can help to foil assaults or rebuild them.

Therefore, Sophos included the Endpoint Detection and Response technology in Intercept X for Servers: this technology enables complete visibility of the infrastructure and, thanks to machine learning methods, offers IT managers with an automated tool that tells them of the network status.

In this manner it is feasible to rapidly identify attacks and take the required countermeasures. The software detects malicious activity by comparing it with a database comprising hundreds of millions of examples to be used as a reference.

Dan Schiappa, Chief Product Officer at Sophos, claims that "blended cyber assaults, once exclusive to crackers serving nation states, are now becoming prevalent among" ordinary "cyber criminals because they are lucrative. The distinction is that crackers serving states tend to remain in networks for a long time, while prevalent cyber criminals often look for possibilities to make things simple.

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!