Network visibility and Network Detection and Response (NDR) solutions are deployed to collect, view and analyze network activity to detect suspicious and malicious activity on the network. The majority of these solutions are built to move data from a collection point (or sensor) to a central repository for analysis. This approach has several downsides including issues of scale, performance, cost and accuracy (false positives). All of these problems can be overcome by solutions that perform traffic analysis at source in a distributed manner.
In a centralized approach, packet sensors connect to the enterprise network to monitor network traffic and send the collected data to a centralized server for analysis. The central server is typically in the cloud but can also be a database and analytics server within the customer premises. The first problem with this approach is that it duplicates the traffic within the network since all collected data must be moved by the central server for analysis. This is costly due to the impact on the network, the size of central database and the cost of analysis.
Educational Webinars, Videos & Podcasts: Receive cutting-edge insights and invaluable resources, empowering you to stay ahead in the dynamic world of security.
Empowering Content: At your computer or on-the-go, stay up-to-date when you receive our eNewsletters curated with the latest technology and services that address physical, logical, cyber and enterprise resilience.
Unlimited Article Access: Dive deep into the world of cybersecurity and risk management leadership with unlimited access to our library of online articles.