Summary
Quad Miners' NDR (Network Detection and Response) solution, Network Blackbox, combines full packet capture and rebuild technology to provide both threat visibility and definitive evidence of risk and impact. Built on the concept of Explainable Security (XSec), the solution supports potential threat hunting through four core technologies and four key functions. It also automatically generates trust-assessment data required under Zero Trust architecture.
Threat Visibility Based on Full Packet Capture
Network Blackbox applies full packet capture technology to all traffic entering and leaving the network. It inspects every transaction to identify abnormal behavior and threats, providing comprehensive threat visibility across the enterprise network. Captured full packet streams are rebuilt to immediately confirm the risk level and impact of a threat, delivered as definitive evidence.
Four Core Technologies
Network Blackbox is built on four core technologies:
- High-performance packet stream storage system: a distributed-architecture storage technology that captures and stores all traffic in large-scale, high-speed network environments without loss
- High-speed packet search: technology that generates a database optimized for search conditions, enabling fast search of user-defined patterns
- Pattern-based indexing system: technology that analyzes and classifies patterns after packet reassembly, then performs real-time indexing tailored to the relevant application
- Scenario-based real-time attack detection system: a supervised-learning-based threat hunting model that identifies and visualizes advanced threats and anomalies in real time
Automatic Generation of Trust-Assessment Data Within a Zero Trust Framework
Based on these core technologies, Network Blackbox provides threat visibility and definitive evidence to security operations teams. It also automatically generates trust-assessment data, a core requirement of Zero Trust architecture.
A Zero Trust access control framework consists of a Policy Decision Point (PDP) — comprising a Policy Engine (PE) and Policy Administrator (PA) — and a Policy Enforcement Point (PEP), which enforces policy between the access subject and enterprise resources. Within this structure, Network Blackbox generates and provides trust-assessment data such as regulatory and internal policy information, data access policies, security information and event data (SIEM), threat intelligence, identity management system data, and network/system behavior logs.
Key Functions That Strengthen Threat Response
Network Blackbox provides four key functions:
- Asset risk analysis: automated risk scoring from an attack-surface management perspective, based on profiling information
- Threat hunting: threat hunting based on analysis of adversary tactics, techniques, and procedures (TTPs)
- Explainable Security (XSec): definitive evidence, presented from an explainable-security perspective, for detected incidents and hunted threats
- Flexible integration for response: integration with a range of security solutions via REST API and integration development support, enabling actionable, connected response
This content has been compiled based on objectively verified facts from an article reported by Datanet on April 18, 2024.