Skip to content
Dekano Logo
  • Home
  • Services
    • Custom Web Applications
    • Cybersecurity Consulting
    • Developer Optimization
  • Blogs
  • About
Dekano Logo
Call Us
[email protected]
Let’s Connect
Dekano Logo
  • Home
  • Services
    • Custom Web Applications
    • Cybersecurity Consulting
    • Developer Optimization
  • Blogs
  • About
Call Us
[email protected]
Let’s Connect
  • 18/04/2023

Enhancing Security Operations with Sophos Network Detection and Response (NDR)

Sophos Network Detection and Response (NDR)

A Sophos Whitepaper: 

In today’s ever-changing threat landscape, organizations must adopt a proactive approach to identify and respond to potential cyber-attacks. Network Detection and Response (NDR) technology plays a critical role in this strategy.

NDR technology leverages deep learning analytics, traditional rule-based matching, and risk-based flow statistics to analyze raw network traffic and identify suspicious and potentially malicious activities on the network. This enables security teams to take proactive measures to prevent cyber-attacks and minimize their impact.

However, the high rate of false positives is a common challenge associated with NDR technology. Sophos NDR addresses this limitation by utilizing patented clustering and scoring technology that combines evidence from multiple threat detection engines.

While NDR technology has been available since the 1990s, the complexity and accuracy vary between vendors. It is crucial for organizations to consider a robust NDR solution like Sophos NDR, which provides advanced levels of threat detection and supports convictions while minimizing false positives. In this white paper, we will delve into the features and benefits of Sophos NDR and explain why it should be a fundamental component of any organization’s security operations.

Evolution of Network Security Monitoring: A Timeline of NDR Technology

Sophos NDR is a critical component of modern security operations, but the history of NDR dates to the 1990s when network-based intrusion detection systems (NIDS) first emerged. Early NIDS systems focused on identifying and blocking network-based attacks, but they lacked the ability to correlate multiple events or detect advanced threats that spanned multiple systems.

In the early 2000s, NDR technology evolved to address these limitations. Instead of simply identifying individual network-based attacks, NDR solutions began analyzing network traffic and correlating events across multiple systems to identify advanced threats. Sophos NDR is a leading NDR solution that utilizes deep learning analytics, traditional rule-based matching, and risk-based flow statistics to identify suspicious and potentially malicious activities on the network.

Over time, NDR technology has become more sophisticated, providing near real-time visibility into network activity, and integrating seamlessly with other security solutions. The following timeline table outlines the key milestones in the evolution of NDR technology:

Sophos NDR: Advanced Network Monitoring for Modern Threats

Sophos NDR is an advanced network monitoring solution designed to address the complex and evolving threat landscape.

Unlike traditional NDR solutions, Sophos NDR combines multiple proprietary detection engines with deep learning analytics, resulting in real-time and actionable intelligence on a wide range of network threats.

Sophos NDR’s proprietary detection engines classify network traffic based on over 330 protocols, 50 flow risks, and thousands of indicators of compromise (IOCs). These engines also incorporate predictions from multiple deep learning models, providing an unprecedented level of threat detection accuracy while minimizing false positives.

Traditional NDRSophos
NDR
Improvement

Limited protocol coverage

Over 330 network protocols

Sophos NDR classifies traffic using over 330 protocols, allowing for a more comprehensive view of network traffic, which is crucial in identifying new and emerging threats

Basic IOCs

Thousands of IOCs

Sophos NDR utilizes thousands of IOCs to detect indicators of compromise, resulting in a higher level of threat detection accuracy.

Minimal flow risk identification

50 flow risks

Sophos NDR incorporates 50 flow risks in its proprietary detection engines, allowing for the detection of more complex threats that may go undetected by other NDR solutions.

Rule-based matching

Deep learning analytics

Sophos NDR utilizes deep learning analytics to provide an unprecedented level of threat detection accuracy while minimizing false positives.

High false positive rates

Patented clustering and scoring technology

Sophos NDR uses patented clustering and scoring technology to reduce false positives, providing actionable intelligence on a wide variety of network threats.

 

These improvements are particularly relevant to NDR because they enable Sophos NDR to accurately identify and respond to network threats without generating an excessive number of false positives. Sophos NDR’s focus on speed, accuracy, and its ability to handle encrypted without having to perform decryption of the traffic makes it an essential component of any comprehensive security strategy.

Sophos NDR offers organizations an advanced network monitoring solution designed to effectively detect and respond to the ever-evolving threat landscape. By combining multiple proprietary detection engines with deep learning analytics, Sophos NDR provides actionable intelligence that is both accurate and relevant to today’s modern threats.

NDR Sensor conceptual architecture

The Sophos NDR solution deploys as a passive traffic monitor listening on a SPAN/Mirror port and does not add any latency to the network traffic or create a point of failure in the network if it becomes overloaded or is offline.

As the data flows into the Sensor meta data is collected and the network flow details are sent to a series of detection engines before being clustered and scored. Results of the clustered network flows are sent to the Sophos data lake and presented in Central in the detections dashboard.

Network Packet Processing (NPP)

Effective network flow metadata collection is critical to the success of NDR solutions. This process involves aggregating the network packets into a single communication or flow and collecting metadata from each network packet using Deep Packet Inspection (DPI). The collected metadata is then enhanced with geolocation information and other metrics, such as unpopular destinations, periodicity, and packet dynamics. The final step is detecting risk indicators such as bad TLS information, unidirectional traffic, large DNS packets, and more.

To better understand the packet header and application layer data that is collected during this phase, the following tables outline examples of what can be determined from each category, and why they are important for threat hunting.

Sophos NDR Architecture Diagram
Figure 1: Sophos NDR Architecture Diagram

Sophos NDR Detection Engines

Sophos NDR incorporates five distinct detection engines to provide comprehensive threat detection capabilities. These detection engines work together to identify and correlate various indicators of compromise, which are then scored and presented as actionable threat intelligence in Sophos Central for customers and analysts.

For increased performance, the machine learning detection engines (EPA –Encrypted packet Analytics, and DGA – Domain Generation Algorithm) are not run on all network flows and are instead triggered based on findings from the other detection engines. Enabling the detection engines to collaborate in the classification is critical to maintaining performance and reducing false positives.

The results of the detection engines are then fed into a clustering and severity scoring algorithm (CSS) to generate an overall threat score for presentation to the administrator as a detection in the Sophos Central Detections dashboard. The detection record contains the results of each engine’s contribution.

IDS – Intrusion Detection System Engine

This proprietary IDS engine is a streamlined, more efficient engine with the capability to identify Indicators of Compromise (IOC)s in unencrypted traffic. Many security vendors continue to use overly robust content matching systems even with the loss of visibility, due to encryption.

Sophos NDR uses carefully selected threat intelligence to create IDS rules classified into six groups, based on the type of IOC. The following are these rule classifications and their descriptions:

Miscellaneous Activity

This rule classification has a Low Severity and is used for detecting network traffic not associated with the other classifications. Examples include traffic to public DNS servers, traffic to content delivery networks, or traffic to trusted cloud services. Identifying miscellaneous activity helps establish a baseline of normal network traffic and highlights any deviations from that baseline.

Policy Violation

This rule classification has a Low Severity and is used for detecting traffic that potentially violates a corporate policy. Examples include traffic to unauthorized websites or services, or traffic from unauthorized devices. Detecting policy violations helps organizations enforce their security policies and prevent unauthorized access or data exfiltration.

Bad Unknown

This rule classification has a Medium Severity and is used for identifying network communication with a potentially bad destination. This can include communication with a known malicious IP address or domain, or communication with a sinkhole domain used to redirect traffic to malicious infrastructure. Detecting bad unknown traffic can help identify compromised endpoints and prevent data exfiltration or further compromise.

Malware Download

This rule classification has a High Severity and is used to identify network communications with a known malware distribution source. This can include communication with a known command-and-control (C2) server used to download or distribute malware, or communication with a known malware distribution site. Detecting malware downloads helps organizations identify and isolate infected endpoints to prevent further spread of malware.

Trojan Activity

This rule classification has a High Severity and is used to identify network communications with a known malware C2 server. This can include communication with a C2 server used for remote control of a compromised endpoint, or communication with a C2 server used to exfiltrate data. Detecting Trojan activity helps organizations identify and isolate compromised endpoints and prevent data exfiltration or further compromise.

TLS Blacklist

This rule classification has a Critical Severity and is used to identify network communications with a known malicious actor based on TLS certification match. This can include communication with a known malicious domain using a compromised TLS certificate or communication with a known malicious domain that is not using a valid TLS certificate. Detecting TLS blacklisted traffic helps organizations prevent communication with known malicious infrastructure and protect against cyber-attacks.

SRA – Session Risk Analytics Engine

The SRA engine detects when network traffic deviates from documented protocol standards, which could indicate suspicious or risky network activity. This is important in a threat hunt because it helps identify nonstandard behavior that may indicate an attack. When the SRA engine observes such activity, it adds information about the behavior to the flow metadata. These flow risks are not considered indicators of compromise on their own, but when combined with detections from other engines, they can help in identifying malicious activity.

The following is a list of general flow risks, which can be found across multiple protocols, and what they indicate:

 

TypeFlow RiskDescription

General

Possible Exploit

Indicates a possible exploit was detected, such as Log4J/Log4Shell. Important for detecting exploit activity and preventing/mitigating attacks.

General

Known Protocol on Non-Standard Port

Indicates a protocol is being used on a non-standard port, such as HTTP on TCP/8000 instead of the standard TCP/80. Important for detecting attackers who use non-standard ports to evade detection.

General

Risky ASN

Indicates network traffic was exchanged with a server belonging to an ASN (Autonomous System Number) that is considered risky. Important for identifying malicious hosts or networks.

General

Unidirectional Traffic

Indicates a session is only one direction, which could indicate C2 activity to a server that is no longer operating at the address. Important for identifying compromised hosts or C2 servers.

General

Desktop or File Sharing Session

Indicates the flow carries desktop or file sharing data, such as TeamViewer or AnyDesk. Important for detecting attackers who use these tools to remotely control a compromised host.

General

Unsafe Protocol

Indicates the protocol used is insecure and should not be used, such as Telnet instead of SSH. Important for detecting attackers who can intercept and read traffic sent over insecure protocols.

General

Clear Text Credentials

Indicates credentials were transmitted in clear text over a known protocol, such as FTP, HTTP, IMAP, POP3, or SMTP. Important for detecting attackers who can intercept and read clear text credentials.

General

Malformed Packet

Indicates a packet has an unexpected format, which could indicate a protocol error or a takeover of a valid protocol to carry another type of data. Important for detecting attacks that use packet manipulation or protocol misuse.

General

TCP Issues

Indicates issues were found in the TCP settings of the network session. Important for detecting attackers who use TCP issues in attacks to disrupt or evade detection.

General

Periodic Flow

Indicates the network session is repeating at a scheduled interval, which could indicate C2 activity from a Trojan or Botnet. Important for detecting attackers who use periodic communication to maintain control over compromised hosts.

 

EPA – Encrypted Payload Analytics Engine and Machine Learning [ML]

Machine learning is increasingly being used in network detection and response (NDR) solutions to detect suspicious traffic on enterprise networks. NDR tools continuously analyze raw traffic and/or flow records, such as NetFlow, to build models that reflect normal network behavior, according to Gartner. Deep learning takes this approach further by allowing for the detection of patterns across multiple attributes, enabling detections without IOC-based threat intelligence.

Sophos has developed a specific solution called Encrypted Payload Analytics (EPA) to address the challenge of detecting threats in encrypted traffic using older technologies. Network flows consist of packets with header and payload data, and when inspecting an encrypted communication, only the payload data is encrypted, making it impossible to know the contents without decryption. EPA is a multi-class deep learning prediction model trained to detect patterns in network flows based on Sequence of Packet Length and Interarrival Time (SPLIT). These SPLIT attributes are simple to compute and are used to train a Convolutional Neural Network (CNN) for classification. Sophos NDR uses a patented process for normalizing, transforming, and presenting this data to the CNN for classification.

By using live malware samples, the EPA model can identify malicious activity in realtime, including zero-day or unknown malware variants and C2 servers based on the patterns in the network flows between them. The EPA engine also enriches the flow metadata with the detected malware family and a confidence score to reduce the number of false positives. Overall, EPA enables organizations to detect and respond to encrypted threats that would have previously gone undetected. This approach is particularly useful when the endpoint devices cannot run a traditional endpoint protection product and when network communications should not be decrypted because of requirements to protect PII (Personal Identifying Information).

The Encrypted Payload Analytics (EPA) engine enhances the flow metadata by identifying the specific Malware Family (such as Bumblebee, Cobalt Strike, Emotet, Dridex, QakBot) and provides a Confidence Score ranging from 0-100. To reduce the number of false positives, the model also includes an “unknown” classification.

DGA – Domain Generation Algorithm Engine

Domain Generation Algorithms (DGA) are used by malicious actors to generate domain names that can be used for Command-and-Control (C2) purposes without being blacklisted. Using these algorithms, malware can generate a list of potential domain names that the C2 server might be hosted on. After numerous attempts, the algorithm will find a domain that exists and establish a connection.

Historically, DGA has been used in several high-profile attacks. For example, in the Conficker worm outbreak of 2008, DGA was used to generate a list of over 50,000 domain names each day that could be used as C2 servers. This made it extremely difficult for security researchers to shut down the worm’s C2 network. Another example is the use of DGA in the Gameover Zeus malware, which was used to generate up to 1,000 domain names per day for C2 purposes. The Gameover Zeus botnet was responsible for stealing over $100 million from victims around the world.

The Sophos NDR’s DGA detection engine is crucial for identifying malicious activity in real-time. Sophos NDR’s DGA detection engine is powered by a Deep Learning Long Short-Term Memory (LSTM) neural network that evaluates every domain name queried and accessed. It is important to note that not all DGA activity is malicious; many legitimate services use DGA regularly. Therefore, Sophos NDR does not generate an alert every time a DGA is detected. Instead, a confidence score (0-100) is added to the flow metadata and is used by the Clustering and Severity Scoring (CSS) engine to determine if the activity involving DGA detections is indeed malicious.

DDE – Data Detection Engine

The Data Detection Engine (DDE) is a component of Sophos NDR that runs on each sensor. It is a lightweight correlation engine that utilizes the onboard database storage of network flows and clusters of flows. The DDE performs scheduled datamining activities on this information to identify complex network threats such as enumeration activities. This information is then sent to Sophos Central and used to generate network information reports.

Additionally, the data collected by the DDE can be correlated with data from Sophos XDR (Extended Detection & Response) endpoint sensors to identify unmanaged assets on the network. This correlation happens in the Sophos Data Lake and provides a comprehensive view of the network, allowing administrators to identify potential security risks and take appropriate action. It is important to note that the DDE performs datamining activities on a set schedule and not in real-time.

CSS – Clustering and Severity Scoring

The Clustering and Severity Scoring (CSS) feature is an essential part of Sophos NDR’s threat detection capabilities. During network sessions between clients and servers, the system observes a wide range of threat indicators. These indicators, when analyzed alone, may not accurately represent a problem or malicious activity. Therefore, Sophos NDR utilizes a patented process to cluster these indicators over time, providing a higher level of confidence in identifying threats.

The clustering process groups network flows based on basic network information, such as source and destination IP/Port and protocol information. By clustering multiple flows that have occurred over time the system is able to generate a more comprehensive view of suspect activity and to aggregate related network flows into a single detection event where the correlation between the flows aids in understanding of the suspect activity.

Once these clusters are created, they are scored based on the information gathered from each of the detection engines. The CSS algorithm evaluates all activities within a cluster to provide additional context, improving accuracy and reducing false positives.

The scoring system within CSS is based on various factors, including severity levels and threat indicators identified by the various detection engines. By combining this information, Sophos NDR assigns a score to each cluster, reflecting the potential risk posed by the network activity. This scoring system provides network administrators with valuable information on potential threats, allowing them to prioritize responses based on the severity of the risk.

To learn more about Sophos NDR, contact us today!

Share Follow Tweet
Share Tweet

Related Articles

Loading...
State of Ransomware 2023

The State of Ransomware 2023

A Sophos Whitepaper:  Findings from an independent, vendor-agnostic survey of...
Read More
18/04/2023
Cyber Defenses in Cyber Insurance Adoption

The Critical Role of Frontline...

A Sophos Whitepaper:  Findings from a research study into the relationship...
Read More
18/04/2023

Let’s Connect

We provide more than just services.
We forge partnerships

"*" indicates required fields

By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. Reply Help for more information. You can reply STOP to opt-out of further messaging*
This field is for validation purposes and should be left unchanged.
Dekano Logo

© Dekano Strategic Partners
16 Industrial Pkwy S, Suite 105 Aurora, Ontario, L4G 0R4 Canada
All Rights Reserved | Privacy policy

Linkedin Instagram Twitter social-icon-svg tiktok_fill
Linkedin Twitter social-icon-svg tiktok_fill

Subscribe to Industry Insights

Subscribe to Industry Insights

"*" indicates required fields

By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. Reply Help for more information. You can reply STOP to opt-out of further messaging*
This field is for validation purposes and should be left unchanged.
  • Home
  • Services
    • Custom Web Applications
    • Cybersecurity Consulting
    • Developer Optimization
  • Blogs
  • About