Network Detection and Response has become an important part of the security stack for a fairly simple reason: the network sees things that other security controls may not.
For a data centre CISO, that view can be particularly useful. Unusual connections between workloads, unexpected communication patterns, lateral movement and changes in behaviour can all leave evidence on the network, even when activity is difficult to identify elsewhere.
The problem is that modern data centres are making that evidence harder to collect and analyse.
Network speeds are increasing. AI infrastructure is generating enormous volumes of east-west traffic. Encryption is changing what security teams can inspect. Meanwhile, the AI and machine learning models used for network detection are developing almost as quickly as the infrastructure itself.
So perhaps the most useful way to think about NDR today is not simply in terms of how good the detection engine is. There are two sides to the problem: getting useful intelligence from the network in the first place, and deciding how that intelligence should be analysed.
Both matter, and increasingly, organisations need more control over both.
Network detection starts with visibility
There is no shortage of discussion about AI in cybersecurity, but an NDR platform can only work with the information available to it. However sophisticated the detection model, it cannot compensate for areas of the network it cannot see.
That makes network visibility fundamental to Network Detection and Response.
In a data centre, achieving that visibility is not necessarily straightforward. There may be thousands of workloads and services communicating with one another, with significant volumes of traffic moving east to west inside the environment rather than simply entering and leaving through a perimeter.
AI infrastructure makes this more challenging again. High-performance and accelerated computing environments can create enormous amounts of network activity, while the underlying networks are increasingly moving towards 400G and 800G connectivity.
For data centre security teams, the obvious answer might appear to be capturing more traffic. But at these speeds, more traffic can quickly mean more infrastructure, more processing and more cost.
That is why it is useful to distinguish between network traffic and network intelligence.
The goal of network detection is not necessarily to copy every packet and send it somewhere else for inspection. Depending on the threat or behaviour being investigated, useful intelligence can come from flow information, metadata, protocols, connection relationships, timing, direction, volume and other behavioural context.
The important question is whether the security team can get enough of the right information to understand what is happening.
What happens to NDR at 400G and 800G?
The move to 400G and 800G changes the practicalities of data centre security monitoring.
If an NDR architecture depends on mirroring and transporting large quantities of traffic to another system for processing, then the security infrastructure has to grow as the network grows. At some point, that becomes an expensive way of creating visibility.
This is particularly important because security monitoring does not operate in isolation. It is sharing the same infrastructure, power, capacity and operational budgets that data centre teams are already working hard to optimise.
The relevant measure of an NDR platform therefore cannot simply be the maximum amount of traffic it claims to inspect. CISOs also need to understand what has to happen around the platform to achieve that inspection.
How is the traffic collected? How much needs to be transported elsewhere? What additional processing is required? And what happens to those requirements when the network moves from 100G to 400G or 800G?
A network detection architecture that works well at one scale may become difficult to justify at another.
For that reason, network visibility needs to be considered as part of the wider data centre architecture rather than something added afterwards.
Encryption is changing the visibility problem too
At the same time, more network traffic is encrypted. That is clearly positive for security and confidentiality, but it changes what network monitoring can see and how useful intelligence can be extracted.
Weakening encryption simply to give a security platform greater visibility is not a sensible answer. The better approach is to think about what useful security information can still be generated around encrypted communications and how that information contributes to detection.
Again, this comes back to the difference between collecting traffic and generating intelligence.
Network visibility is not something an organisation solves once. It has to change with the network. New protocols, higher speeds, different workloads and stronger encryption all alter the information available to security teams and the methods used to collect it.
The same is increasingly true of the models used to analyse that information.
NDR is not one AI model
AI and machine learning are now an important part of Network Detection and Response, but it is easy to talk about “AI-powered NDR” as though AI were a single detection technology.
In reality, different security problems benefit from different approaches.
A model looking for anomalous behaviour across network connections is solving a different problem from one looking for suspicious DNS activity. Detecting lateral movement is different again. Signatures, threat intelligence, behavioural analytics and security rules continue to have a role alongside machine learning.
That matters because AI is changing quickly.
The machine learning models available to security teams today will not necessarily be the models they want to use in three or five years. New approaches will emerge, existing models will improve and organisations may develop models specifically around their own environments.
For a data centre operator making infrastructure decisions with much longer lifecycles, that creates an interesting mismatch.
The network may be built to last for years. The AI used to protect it is likely to change much sooner.
Why an open-model approach to NDR matters
This is where open-model Network Detection and Response starts to make sense.
An open-model approach does not mean that the organisation has to build its own AI, nor does it mean rejecting the detection models supplied by the NDR vendor. Most security teams will want to use those capabilities.
The difference is that they are not necessarily the only models the organisation can use.
If an NDR platform supports customer-developed machine learning models as well as its own detection capabilities, security teams have more freedom to adapt network detection to their environment. They can use the models that come with the platform where those models work well and introduce their own where there is a particular requirement.
That can be especially relevant in data centre security because there is no single definition of a typical data centre network.
A hyperscale operator, colocation provider, cloud platform and enterprise data centre can have very different architectures and workloads. Their normal traffic patterns can look very different too. A detection approach that works well in one environment will not necessarily be the best approach in another.
The value of an open model is therefore not about choosing between “small” and “large” machine learning. It is much simpler than that: the organisation has more control over the intelligence it uses to protect its network.
The data and the model do not have to evolve together
Separating the network intelligence from the model analysing it has another advantage.
It gives the two parts of the architecture room to evolve at different speeds.
The network visibility layer needs to continue producing useful evidence as traffic volumes increase, architectures change and encryption evolves. The analytical layer needs to be able to take advantage of new detection models and machine learning techniques as they become available.
If those two things are too tightly coupled, changing one can mean changing the other.
An open-model NDR architecture offers a different approach. The organisation can concentrate on generating high-quality network intelligence and retain more choice over how that intelligence is analysed.
This does not make vendor-developed models less valuable. Nor does it mean that every organisation should start training its own models. It simply avoids assuming that the models available today will always be the only or best way to analyse the network tomorrow.
For a CISO, that is less an AI question than an architectural one.
Control is becoming part of the AI security conversation
There is also a wider issue for data centre security teams.
Network telemetry can reveal a great deal about infrastructure, workloads and communications. As AI becomes more deeply integrated into security operations, organisations will need to understand what happens to that information once it has been collected.
Which models are analysing it? Where does that analysis happen? Can the organisation apply its own threat intelligence and detection logic? Can it introduce a different model if its requirements change?
Those are useful questions regardless of how sophisticated the vendor’s AI may be.
It also changes the way CISOs can evaluate NDR. Asking whether a product “uses AI” tells you relatively little now. Understanding what information the AI receives, what it is designed to detect and how much control the organisation has over the process tells you considerably more.
Good models still need good network intelligence
None of this diminishes the importance of visibility. In fact, open models make the quality of the underlying network intelligence even more important.
A sophisticated machine learning model working with incomplete information is still working with incomplete information. A custom model cannot identify activity in an area of the network that is invisible to it.
This brings the two sides of Network Detection and Response back together.
Security teams need an efficient way to generate useful intelligence from high-speed data centre networks. They also need the flexibility to decide how that intelligence is analysed as detection technology changes.
The strength of the NDR architecture ultimately depends on both.
What should a data centre CISO ask when evaluating NDR?
There will always be questions about detection performance, coverage, investigation and response when evaluating Network Detection and Response. But in a modern data centre, it is worth looking underneath those capabilities as well.
Where does the network intelligence come from? How much of the environment can actually be observed? How is network traffic collected and processed, and what additional infrastructure does that require at 400G and 800G?
Then there is the analytical side. Can the security team combine its own threat intelligence and detection rules with the platform? Is it restricted to the vendor’s machine learning models, or can it deploy its own? Which frameworks are supported, and where does that analysis take place?
Perhaps the most useful question is a very practical one: what happens when things change?
If the network doubles in speed, does the visibility architecture still make sense? If traffic patterns change because of new AI workloads, can detection adapt? And if a better model becomes available in a few years, can the security team use it without redesigning the rest of the NDR environment?
Those questions provide a much better indication of whether a network detection architecture has been designed for where the data centre is going, rather than where it has been.
Building NDR for what comes next
The future of Network Detection and Response is unlikely to be about collecting as much network traffic as possible or finding a single AI model capable of solving every detection problem.
Data centre networks are becoming too fast and too complex for that.
Security teams need to be more deliberate about the intelligence they generate from the network, particularly as environments move towards 400G and 800G. At the same time, they need to recognise that the models analysing that intelligence will continue to change.
An architecture that provides both high-speed network visibility and flexibility over the models used for detection gives the organisation more room to adapt to both.
That does not mean every organisation needs to develop its own AI. It means the choice remains with the organisation responsible for protecting the network.
And as both data centre infrastructure and AI continue to evolve, that choice is likely to become increasingly valuable.
See open-model Network Detection and Response in practice
Telesoft’s intSOC 400 has been developed for high-speed data centre security, combining network visibility and Network Detection and Response with an open approach to AI and machine learning models.
Security teams can use Telesoft’s own detection models while retaining the ability to deploy their own models for specific environments and requirements.
To see how that works in practice, watch the intSOC 400 – Cyber video and explore how open-model NDR can be applied to high-speed data centre networks.
Go Back