{"id":66381,"date":"2021-10-26T09:06:56","date_gmt":"2021-10-26T09:06:56","guid":{"rendered":"https:\/\/www.kriativ-tech.com\/?p=66381"},"modified":"2022-01-04T14:24:00","modified_gmt":"2022-01-04T14:24:00","slug":"extended-detection-and-response-importance-of-events-context","status":"publish","type":"post","link":"http:\/\/www.kriativ-tech.com\/?p=66381","title":{"rendered":"Extended Detection and Response Importance of Events Context"},"content":{"rendered":"<p>[vc_row][vc_column width=&#8221;1\/2&#8243;][vc_custom_heading heading_semantic=&#8221;p&#8221; text_font=&#8221;font-213936&#8243; text_size=&#8221;h5&#8243; text_height=&#8221;fontheight-843833&#8243;]Kriativ-tech Volume 1, Issue 9, April 2018, Pages: xxx Received: Dec. 28, 2019; Accepted: Feb. 25, 2020. Published: Oct. 11, 2021.[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;h3&#8243; text_size=&#8221;h3&#8243;]Authors[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;p&#8221; text_size=&#8221;h5&#8243; uncode_shortcode_id=&#8221;139170&#8243;]Pedro Ramos Brandao, Coordinator Professor at Instituto Superior de Tecnologias Avan\u00e7adas<br \/>\nJo\u00e3o Nunes, Master Degree Student at Instituto Superior de Tecnologias Avan\u00e7adas [\/vc_custom_heading][\/vc_column][vc_column width=&#8221;1\/2&#8243;][vc_custom_heading]Media[\/vc_custom_heading][vc_button button_color=&#8221;accent&#8221; border_animation=&#8221;btn-ripple-out&#8221; border_width=&#8221;0&#8243; link=&#8221;url:http%3A%2F%2Fwww.kriativ-tech.com%2Fwp-content%2Fuploads%2F2021%2F10%2FExtendedDetectionResponse.pdf|target:_blank&#8221; button_color_type=&#8221;uncode-palette&#8221; uncode_shortcode_id=&#8221;490301&#8243;]PDF[\/vc_button][vc_custom_heading heading_semantic=&#8221;h4&#8243; text_size=&#8221;h4&#8243;]To cite this article[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;p&#8221; text_size=&#8221;h6&#8243; uncode_shortcode_id=&#8221;498713&#8243;]Pedro Ramos Brandao, Jo\u00e3o Nunes, <strong>Extended Detection and Response Importance of Events Context<\/strong><\/p>\n<p>DOI: 10.31112\/kriativ-tech-2021-10-58[\/vc_custom_heading][\/vc_column][\/vc_row][vc_row row_height_percent=&#8221;0&#8243; overlay_alpha=&#8221;50&#8243; gutter_size=&#8221;1&#8243; column_width_percent=&#8221;100&#8243; shift_y=&#8221;0&#8243; z_index=&#8221;0&#8243;][vc_column column_width_percent=&#8221;100&#8243; gutter_size=&#8221;0&#8243; override_padding=&#8221;yes&#8221; column_padding=&#8221;1&#8243; overlay_alpha=&#8221;50&#8243; shift_x=&#8221;0&#8243; shift_y=&#8221;0&#8243; shift_y_down=&#8221;0&#8243; z_index=&#8221;0&#8243; medium_width=&#8221;0&#8243; mobile_width=&#8221;0&#8243; width=&#8221;1\/1&#8243;][vc_custom_heading heading_semantic=&#8221;h3&#8243; text_size=&#8221;h3&#8243;]Abstract[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;p&#8221; text_font=&#8221;font-213936&#8243; text_size=&#8221;h5&#8243; text_height=&#8221;fontheight-843833&#8243; uncode_shortcode_id=&#8221;151038&#8243;]<em>In an increasingly dynamic and unpredictable world regarding IT security, it&#8217;s essential to use adequate solutions that boost infrastructures protection, whether local, in the cloud, or hybrid. This article contextualizes the challenges of the new reality of remote work with traditional security solutions. Furthermore, it explains the importance of implementing a solution that has a holistic view of the infrastructure and correlates all suspicious or attack events. Thus, it enhances an improved and updated security to the current reality.<\/em>[\/vc_custom_heading][vc_empty_space empty_h=&#8221;2&#8243;][vc_custom_heading heading_semantic=&#8221;h3&#8243; text_size=&#8221;h3&#8243;]Keywords[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;p&#8221; text_size=&#8221;h5&#8243; uncode_shortcode_id=&#8221;140074&#8243;]XDR, EDR, SIEM, Correlation, Context, Cybersecurity[\/vc_custom_heading][\/vc_column][\/vc_row][vc_row][vc_column column_width_percent=&#8221;100&#8243; gutter_size=&#8221;0&#8243; overlay_alpha=&#8221;50&#8243; shift_x=&#8221;0&#8243; shift_y=&#8221;0&#8243; shift_y_down=&#8221;0&#8243; z_index=&#8221;0&#8243; medium_width=&#8221;0&#8243; mobile_width=&#8221;0&#8243; width=&#8221;1\/1&#8243;][vc_custom_heading heading_semantic=&#8221;h3&#8243; text_size=&#8221;h3&#8243;]References[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;p&#8221; text_font=&#8221;font-213936&#8243; text_size=&#8221;h5&#8243; text_height=&#8221;fontheight-843833&#8243; uncode_shortcode_id=&#8221;283090&#8243;][1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Kaspersky, &#8220;How COVID-19 changed the way people work,&#8221; 2020.<\/p>\n<p>[2]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 W. U. Hassan, A. Bates, and D. Marino, &#8220;Tactical provenance analysis for endpoint detection and response systems,&#8221; <em>Proc. &#8211; IEEE Symp. Secur. Priv.<\/em>, vol. 2020-May, pp. 1172\u20131189, 2020, doi: 10.1109\/SP40000.2020.00096.<\/p>\n<p>[3]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 G. Karantzas and C. Patsakis, &#8220;An Empirical Assessment of Endpoint Detection and Response Systems against Advanced Persistent Threats Attack Vectors,&#8221; pp. 387\u2013421, 2021, doi: 10.3390\/jcp1030021.<\/p>\n<p>[4]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 S. Slate, &#8220;Endpoint Security: An Overview and a Look into the Future,&#8221; <em>Lat. Am. Polit. Hist.<\/em>, 2018, doi: 10.4324\/9780429499340-15.<\/p>\n<p>[5]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 G. Gonz\u00e1lez-granadillo, S. Gonz\u00e1lez-zarzosa, and R. Diaz, \u201cTrends, and Usage in Critical Infrastructures,\u201d 2021.<\/p>\n<p>[6]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 M. Chopra and C. Mahapatra, &#8220;Significance of security information and event management (SIEM) in modern organizations,&#8221; <em>Int. J. Innov. Technol. Explor. Eng.<\/em>, vol. 8, no. 7, pp. 432\u2013435, 2019.<\/p>\n<p>[7]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 M. Vielberth and G. Pernul, &#8220;A Security Information and Event Management Pattern,&#8221; <em>Fed. Minist. Educ. Res.<\/em>, vol. 1, no. November 2018, pp. 1\u201312, 2018.<\/p>\n<p>[8]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 H. Jauhiainen, &#8220;Designing End User Area Cybersecurity for Cloud-based Organization,&#8221; no. February 2021.<\/p>\n<p>[9]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 A. Chuvakin, &#8220;Gartner Blog Network,&#8221; 2013. https:\/\/blogs.gartner.com\/anton-chuvakin\/2013\/07\/26\/named-endpoint-threat-detection-response\/ (accessed July 2021).<\/p>\n<p>[10]\u00a0\u00a0\u00a0\u00a0 Mcafee, &#8220;What is Endpoint Detection and Response (EDR)? &#8221; 2021.<\/p>\n<p>[11]\u00a0\u00a0\u00a0\u00a0 &#8220;Endpoint Detection and Response &#8211; Global Market Outlook (2017-2026),&#8221; <em>Stratistics Market Research Consulting<\/em>, 2018. https:\/\/www.marketresearch.com\/Stratistics-Market-Research-Consulting-v4058\/Endpoint-Detection-Response-Global-Outlook-12066121\/ (accessed July 2021).<\/p>\n<p>[12]\u00a0\u00a0\u00a0\u00a0 L. Neely and A. Torres, &#8220;Endpoint Protection and Response: A SANS Survey,&#8221; <em>SANS Inst.<\/em>, no. June, p. 16, 2018.<\/p>\n<p>[13]\u00a0\u00a0\u00a0\u00a0 J. Petters, &#8220;What is SIEM? A Complete Beginner&#8217;s Guide &#8211; Varonis,&#8221; 2020. https:\/\/www.varonis.com\/blog\/what-is-siem\/ (accessed July 2021).<\/p>\n<p>[14]\u00a0\u00a0\u00a0\u00a0 Cisco, \u201cWhat is XDR? &#8211; Extended Detection and Response &#8211; Cisco,\u201d 2021. https:\/\/www.cisco.com\/c\/en\/us\/products\/security\/what-is-xdr.html (accessed July 2021).<\/p>\n<p>[15]\u00a0\u00a0\u00a0\u00a0 Mcafee, &#8220;What Is XDR? Extended Detection and Response l McAfee,&#8221; 2021. https:\/\/www.mcafee.com\/enterprise\/en-us\/security-awareness\/endpoint\/what-is-xdr.html (accessed July 2021).<\/p>\n<p>[16]\u00a0\u00a0\u00a0\u00a0 &#8220;Endpoint Detection and Response (EDR): o caso do contexto | Security Report,&#8221; 2019. https:\/\/www.securityreport.com.br\/overview\/endpoint-detection-and-response-edr-o-caso-do-contexto\/#.YPc5kRNKj0p (accessed July 2021).[\/vc_custom_heading][\/vc_column][\/vc_row]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Pedro Ramos Brandao, Coordinator Professor at Instituto Superior de Tecnologias Avan\u00e7adas<br \/>\nJo\u00e3o Nunes, Master Degree Student at Instituto Superior de Tecnologias Avan\u00e7adas<br \/>\nDOI: 10.31112\/kriativ-tech-2021-10-58<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[70],"tags":[],"_links":{"self":[{"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/posts\/66381"}],"collection":[{"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=66381"}],"version-history":[{"count":4,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/posts\/66381\/revisions"}],"predecessor-version":[{"id":66432,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/posts\/66381\/revisions\/66432"}],"wp:attachment":[{"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=66381"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=66381"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=66381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}