Check Point Infinity NDR is a comprehensive technology stack for Network Detection and Response.
The Check Point Infinity NDR service concept:
Sensors analyze network traffic, and create logs which are sent to the NDR cloud for storage and analysis.
Behavioral Analytics AI engines process the logs and create analytical conclusions.
Human analysts use event visualization tools for more data comprehension.
Identify data anomalies through correlation with ThreatCloud intelligence and application risk scoring.
Publish analytical conclusions as threat indicators and tags.
Input feeds pull threat indicators from third party threat intelligence sources.
Enforcement points apply the indicators and match them to network traffic, for detect or prevent actions.