Network Detection and Response
Also known as:NDR
Network DetectionDetectionThe capability to identify suspicious activity, attacks, or policy violations in time. and Response: Analyzes network traffic to detect and investigate suspicious activity. The control operates on network communicationNetwork CommunicationThe exchange of data between systems over network protocols and connections. or network accessNetwork AccessThe ability of a user, device, or workload to connect to and use network resources. points. Effectiveness is achieved through restrictive rules, segmentation, continuous monitoringMonitoringThe continuous observation of systems, identities, networks, and controls for relevant changes., and coordinated response processesResponse ProcessA coordinated sequence of decisions and actions for handling security events and incidents..
How it works and where it fits
Network Detection and Response connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.
Practical security relevance
Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.
Related concepts
- Network Behavior AnalysisNetwork Behavior AnalysisDetection of anomalous communication patterns based on network metadata and behavior.: Detection of anomalous communication patterns based on network metadata and behavior.
- Network FlowNetwork FlowSummary of a communication relationship between endpoints over a specific period.: Summary of a communication relationship between endpoints over a specific period.
- Extended Detection and ResponseExtended Detection and ResponseCorrelated detection and response across endpoints, identities, email, networks, and the cloud.: Correlated detection and response across endpoints, identities, email, networks, and the cloud.
- Network ForensicsNetwork ForensicsReconstruction and analysis of security-relevant events based on network data.: Reconstruction and analysis of security-relevant events based on network data.