Sangfor Athena - NDR

Sangfor Athena NDR is a next-generation network detection and response solution that provides comprehensive visibility into network traffic and threats, enabling security teams to detect and respond to advanced attacks in real-time.

Modern Network Security Challenges

The expansion of corporate networks, cloud integrations, and the increasing volume of encrypted traffic create blind spots across the network. Traditional firewalls and signature-based systems fall short in detecting threats that have bypassed borders and remain hidden.

Lateral movements performed by attackers within the network, data exfiltration attempts, and insider threats can remain active for long periods without being noticed. Manually analyzing massive traffic data from different network segments is impossible, while the lack of contextual analysis makes it difficult for security teams to differentiate between real threats and false alarms.

What Problems Does It Solve?

  • Providing visibility into threats hidden within network traffic blind spots.
  • Detecting lateral movements and data exfiltration attempts within the network.
  • Overcoming the challenges of analyzing malicious activities within encrypted traffic.
  • Automating threat response processes and monitoring the attack chain end-to-end.

Core Principles

Deep Visibility

Eliminates all network blind spots to ensure full control.

Intelligent Analysis

Detects suspicious behaviors and anomalies using AI.

Rapid Containment

Instantly blocks the spread of attacks across the network.

Unified Response

Transforms network and endpoint systems into an integrated defense.

Technical Specifications

Network Traffic Analysis

  • Real-time deep packet inspection (DPI)
  • North South and East West traffic monitoring
  • Encrypted traffic analysis (ETA) support
  • NetFlow, IPFIX, and mirror traffic collection

Advanced Threat Detection

  • AI based behavioral anomaly detection
  • Full alignment with MITRE ATT&CK taxonomy
  • Unknown threat and zero-day detection
  • Command and Control (C2) communications tracking

Attack Chain Visualization

  • Graph-based cyber attack chain analysis
  • Root cause analysis of threats and incidents
  • Identification of affected assets and devices
  • Forensic investigations and log analysis support

Security Orchestration and Response

  • Automated IP blocking via firewalls
  • Endpoint quarantine with EDR integration
  • REST API over external systems compatibility
  • Flexible and automated response playbook framework

Consulting and Managed Services

  • Topology analysis, traffic throughput profiling, and sensor placement planning
  • Core switch TAP/SPAN port configuration and turnkey Cyber Command integration
  • Reduction of false positive rates, alert analysis, and optimization support
  • DPI, ETA, platform forensics, and technical threat hunting instruction for SOC teams

How Does Sangfor NDR Work?

Sangfor Athena NDR (Cyber Command) operates by collecting mirror traffic data or flow logs across the corporate network within its centralized infrastructure. Collected data is analyzed using artificial intelligence models and machine learning algorithms to identify network anomalies. When a cyber attack chain is detected, the system generates alerts and automatically isolates the threat via integrated security products.

Workflow

1. Traffic Collection and Monitoring

  • Mirror traffic data is received from all network segments.
  • Encrypted and unencrypted traffic flows are continuously monitored.
  • Communication maps of network components are generated.
  • Protocol and packet analyses are transmitted to the central system.

2. AI-Based Behavior Analysis

  • Movements deviating from the baseline profile and anomalies are searched.
  • Malicious connections are matched with threat intelligence.
  • Attack stages are correlated with the MITRE ATT&CK framework.

3. Coordination and Response

  • The attacker IP is blocked via the integrated Firewall.
  • The infected endpoint is isolated via the integrated EDR.
  • Detailed forensic analysis and SOC reports are generated.

Continuous Improvement

The Sangfor Athena NDR infrastructure continuously learns traffic patterns in the network to optimize its machine learning models, regularly increasing detection accuracy against next generation threat variants.

Advantages

Advanced Encrypted Traffic Analysis

Detects hidden malicious activities with high accuracy by analyzing metadata such as packet size and timing using AI, without decrypting the encrypted network traffic.

XDDR Threat Correlation

Integrates with Sangfor Athena EPP and Firewall solutions to merge network anomaly information with endpoint transaction logs, offering an autonomous and seamless response ecosystem.

Visual Attack Chain

Transforms complex network alarms into a meaningful story; clearly showing where the attacker entered the network, which devices they moved through, and their ultimate objective.

Proactive Threat Hunting

Provides comprehensive historical data analytics tools that allow security analysts to proactively hunt for advanced persistent threats (APTs) hidden inside systems.