Coordinated monitoring of heterogeneous domains in extended detection and response (XDR) systems
A method may include receiving, by a processor, first monitoring data from a first monitoring component and second monitoring data from a second monitoring component. The method may further include determining, by the processor, that the first monitoring data represents a first activity pattern of a computing entity in a first period. The method may further include determining, by the processor, that the second monitoring data represents a second activity pattern of the computing entity in the first period. The method may further include determining, by the processor, first feedback data based on the first monitoring data. The method may further include determining, by the processor, second feedback data based on the second monitoring data. The method may further include providing, by the processor, the first feedback data to the second monitoring component and the second feedback data to the first monitoring component.
1 . A method comprising:
receiving, by a processor associated with an Extended Detection and Response (XDR) system, first monitoring data from a first monitoring component and second monitoring data from a second monitoring component, wherein:
the first monitoring component is configured to monitor one or more network conditions of a network associated with a computing entity to:
determine that the one or more network conditions satisfy a first detection threshold,
based on determining that the one or more network conditions satisfy the first detection threshold, determine that the one or more network conditions are anomalous,
based on determining that the one or more network conditions are anomalous, generate the first monitoring data representing the one or more network conditions, and
send the first monitoring data to the XDR system,
the second monitoring component is configured to monitor one or more endpoint conditions associated with the computing entity to:
determine that the one or more endpoint conditions satisfy a second detection threshold,
based on determining that the one or more endpoint conditions satisfy the second detection threshold, determine that the one or more endpoint conditions are anomalous, and
based on determining that the one or more endpoint conditions are anomalous, generate the second monitoring data representing the one or more endpoint conditions, and
send the second monitoring data to the XDR system;
determining, by the processor, that the first monitoring data represents a first activity pattern of the computing entity in a first period, wherein the first activity pattern represents the one or more network conditions;
determining, by the processor, that the second monitoring data represents a second activity pattern of the computing entity in the first period;
determining, by the processor, first feedback data based on the first monitoring data, wherein the first feedback data represents the first activity pattern;
determining, by the processor, second feedback data based on the second monitoring data;
providing, by the processor, the first feedback data to the second monitoring component, wherein the second monitoring component is configured to adjust the second detection threshold based on the first feedback data; and
providing, by the processor, the second feedback data to the first monitoring component, wherein the first monitoring component is configured to adjust the first detection threshold based on the second feedback data.
2 . The method of claim 1 , wherein:
the first activity pattern represents at least one of: (i) a first measure of frequency of connections between the computing entity and network nodes external to the network, (ii) a second measure of frequency of connections between the computing entity and a geographic system, or (iii) a third measure of frequency of connections between the computing entity and an anomalous system.
3 . The method of claim 1 , wherein:
the second monitoring component monitors software configurations of a software application executed by the computing entity, and
the second activity pattern represents at least one of: (i) a type of the software application, (ii) an operating system type associated with the computing entity, (iii) a system call made by the software application during the first period, (iv) a role performed by the computing entity within the network, or (v) a vulnerability of the software application.
4 . The method of claim 1 , further comprising:
determining, by the processor, a third activity pattern based on a correlation between the first monitoring data and the second monitoring data; and
providing the third activity pattern to a third monitoring component.
5 . The method of claim 4 , wherein determining the third activity pattern comprises:
determining, based on the first monitoring data, that the computing entity uses a first operating system during the first period;
determining, based on the second monitoring data, that the computing entity connects from a first geographic location during the first period; and
determining the third activity pattern to represent that, when connecting from the first geographic location, the computing entity uses the first operating system.
6 . The method of claim 4 , wherein the third monitoring component is configured to monitor the computing entity based on whether an observed activity pattern associated with the computing entity deviates from the third activity pattern.
7 . The method of claim 6 , wherein the third monitoring component is configured to whitelist activity by the computing entity that matches the third activity pattern.
8 . The method of claim 1 , wherein the first monitoring component determines the first monitoring data by applying a predictive model to the second monitoring data and third monitoring data received from a third computing entity.
9 . The method of claim 1 , wherein:
the second monitoring component monitors one or more software configurations of a software application executed by the computing entity;
the second activity pattern represents the one or more software configurations; and
the second feedback data represents the second activity pattern.
10 . The method of claim 1 , wherein the second monitoring component is configured to, based on determining that the first feedback data represents the computing entity is associated with a safe group of computing entities, increase the second detection threshold.
11 . A system comprising one or more processors and one or more computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:
receiving first monitoring data from a first monitoring component and second monitoring data from a second monitoring component, wherein:
the first monitoring component is configured to monitor one or more network conditions of a network associated with a computing entity to:
determine that the one or more network conditions satisfy a first detection threshold,
based on determining that the one or more network conditions satisfy the first detection threshold, determine that the one or more network conditions are anomalous,
based on determining that the one or more network conditions are anomalous, generate the first monitoring data representing the one or more network conditions, and
send the first monitoring data to the system, wherein the system comprises an Extended Detection and Response (XDR) system,
the second monitoring component is configured to monitor one or more endpoint conditions associated with the computing entity to:
determine that the one or more endpoint conditions satisfy a second detection threshold,
based on determining that the one or more endpoint conditions satisfy the second detection threshold, determine that the one or more endpoint conditions are anomalous, and
based on determining that the one or more endpoint conditions are anomalous, generate the second monitoring data representing the one or more endpoint conditions, and
send the second monitoring data to the system;
determining that the first monitoring data represents a first activity pattern of the computing entity in a first period, wherein the first activity pattern represents the one or more network conditions;
determining that the second monitoring data represents a second activity pattern of the computing entity in the first period;
determining first feedback data based on the first monitoring data, wherein the first feedback data represents the first activity pattern;
determining second feedback data based on the second monitoring data;
providing the first feedback data to the second monitoring component, wherein the second monitoring component is configured to adjust the second detection threshold based on the first feedback data; and
providing the second feedback data to the first monitoring component, wherein the first monitoring component is configured to adjust the first detection threshold based on the second feedback data.
12 . The system of claim 11 , wherein:
the first activity pattern represents at least one of: (i) a first measure of frequency of connections between the computing entity and network nodes external to the network, (ii) a second measure of frequency of connections between the computing entity and a geographic system, or (iii) a third measure of frequency of connections between the computing entity and an anomalous system.
13 . The system of claim 11 , wherein:
the second monitoring component monitors software configurations of a software application executed by the computing entity, and
the second activity pattern represents at least one of: (i) a type of the software application, (ii) an operating system type associated with the computing entity, (iii) a system call made by the software application during the first period, (iv) a role performed by the computing entity within the network, or (v) a vulnerability of the software application.
14 . The system of claim 11 , the operations further comprising:
determining a third activity pattern based on a correlation between the first monitoring data and the second monitoring data; and
providing the third activity pattern to a third monitoring component.
15 . The system of claim 14 , wherein determining the third activity pattern comprises:
determining, based on the first monitoring data, that the computing entity uses a first operating system during the first period;
determining, based on the second monitoring data, that the computing entity connects from a first geographic location during the first period; and
determining the third activity pattern to represent that, when connecting from the first geographic location, the computing entity uses the first operating system.
16 . One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
receiving first monitoring data from a first monitoring component and second monitoring data from a second monitoring component, wherein:
the first monitoring component is configured to monitor one or more network conditions of a network associated with a computing entity to:
determine that the one or more network conditions satisfy a first detection threshold,
based on determining that the one or more network conditions satisfy the first detection threshold, determine that the one or more network conditions are anomalous,
based on determining that the one or more network conditions are anomalous, generate the first monitoring data representing the one or more network conditions, and
send the first monitoring data to an Extended Detection and Response (XDR) system associated with the one or more processors,
the second monitoring component is configured to monitor one or more endpoint conditions associated with the computing entity to:
determine that the one or more endpoint conditions satisfy a second detection threshold,
based on determining that the one or more endpoint conditions satisfy the second detection threshold, determine that the one or more endpoint conditions are anomalous, and
based on determining that the one or more endpoint conditions are anomalous, generate the second monitoring data representing the one or more endpoint conditions, and
send the second monitoring data to the XDR system;
determining that the first monitoring data represents a first activity pattern of the computing entity in a first period, wherein the first activity pattern represents the one or more network conditions;
determining that the second monitoring data represents a second activity pattern of the computing entity in the first period;
determining first feedback data based on the first monitoring data, wherein the first feedback data represents the first activity pattern;
determining second feedback data based on the second monitoring data;
providing the first feedback data to the second monitoring component, wherein the second monitoring component is configured to adjust the second detection threshold based on the first feedback data; and
providing the second feedback data to the first monitoring component, wherein the first monitoring component is configured to adjust the first detection threshold based on the second feedback data.
17 . The one or more non-transitory computer-readable media of claim 16 , wherein:
the first activity pattern represents at least one of: (i) a first measure of frequency of connections between the computing entity and network nodes external to the network, (ii) a second measure of frequency of connections between the computing entity and a geographic system, or (iii) a third measure of frequency of connections between the computing entity and an anomalous system.
18 . The one or more non-transitory computer-readable media of claim 16 , wherein:
the second monitoring component monitors software configurations of a software application executed by the computing entity, and
the second activity pattern represents at least one of: (i) a type of the software application, (ii) an operating system type associated with the computing entity, (iii) a system call made by the software application during the first period, (iv) a role performed by the computing entity within the network, or (v) a vulnerability of the software application.
19 . The one or more non-transitory computer-readable media of claim 16 , the operations further comprising:
determining a third activity pattern based on a correlation between the first monitoring data and the second monitoring data; and
providing the third activity pattern to a third monitoring component.