Network detection and response (NDR) is a category of security technology that monitors network traffic, learns what normal activity looks like and flags behavior that suggests an attack, such as a device scanning the network, an account connecting to systems it never uses, or large amounts of data leaving to an unfamiliar destination. It also gives security teams the records and tools to investigate those alerts and respond, for example by triggering a firewall block or isolating a device. NDR is usually one layer of a wider detection strategy alongside endpoint and identity tools.
At a glance
- NDR analyzes network traffic, typically using behavioral analytics alongside known-threat detection.
- Where their traffic passes a sensor, it sees activity from devices that can’t run security agents, such as printers, cameras, OT equipment and unmanaged machines.
- It is especially useful for spotting lateral movement and unusual data transfers inside the network.
- Response options often include integrations with firewalls, network access control and EDR tools.
- It is sold as a product to run yourself and is often included in managed detection services.
What problem it solves
Most attacks involve the network at some point: an attacker who gets onto one device usually scans for others, moves between systems, communicates with external servers and eventually moves data out. Endpoint tools only see devices where their agent is installed, and many devices on a typical network have none, including network equipment, printers, phones, cameras, building systems and unmanaged personal devices. Attackers also try to disable endpoint agents once they get in.
NDR adds a vantage point that is harder for attackers to avoid. Because it watches traffic rather than individual devices, it can spot unusual connections between systems, communication patterns associated with remote control by attackers, and suspicious data transfers. For investigations, its records of who talked to whom, and when, help reconstruct what happened and how far an attacker got.
How it works
Collecting traffic. Sensors receive copies of network traffic from switch mirror ports or network taps at important points: the internet edge, data center core, and links between key segments. In cloud environments, NDR uses flow logs or traffic mirroring features. Some products also ingest flow records from routers and switches.
Analyzing it. The NDR platform extracts metadata about each connection, such as source, destination, protocol, volume and timing, and sometimes deeper protocol details. It applies signatures for known threats, threat intelligence on known bad destinations, and behavioral models that learn normal patterns and flag deviations. Because much traffic is encrypted, analysis often relies on metadata and session characteristics.
Alerting and investigation. Alerts group related activity into incidents. Analysts can look back through stored traffic records, which also supports threat hunting for activity that didn’t trigger alerts.
Response. Depending on the product and integrations, NDR can trigger actions such as blocking traffic at a firewall, quarantining a device through network access control, or asking an endpoint detection and response (EDR) tool to isolate a machine.
Operation. NDR produces alerts that someone has to review. Smaller teams often rely on a security operations center (SOC) or managed detection and response (MDR) provider to monitor it, and NDR data often feeds extended detection and response (XDR) platforms.
When it matters for buyers
- When you have many devices that can’t run security agents. Manufacturing, healthcare, education and multi-site retail environments often do.
- When EDR alone has left gaps. NDR provides detection that doesn’t depend on agents working on every device.
- When an insurer, auditor or customer asks about network monitoring. Some frameworks and questionnaires specifically ask how internal traffic is monitored.
- When choosing an MDR provider. Check whether network data is included or an add-on.
- After an incident where attackers moved undetected. NDR targets exactly that phase.
Our managed detection and response overview covers services that monitor network as well as endpoint data.
Questions to ask vendors
- Where would sensors need to go in our network, and what hardware or cloud resources do they require?
- How do you analyze encrypted traffic, and do you require decryption?
- Which detections are behavioral, and how long does the system take to learn our normal activity?
- How long is traffic metadata kept for investigations?
- What response actions can you trigger, and with which firewalls, NAC and EDR products?
- Who reviews the alerts: our team, your managed service, or our existing MDR provider?
- How is it licensed: by bandwidth, sensors, devices or another measure?
How it differs from an IDS
An intrusion detection system (IDS) monitors traffic and alerts on matches against signatures of known attacks and policy violations. NDR grew out of that idea, and earlier products in the space were often called network traffic analysis. NDR typically adds behavioral analytics to catch unfamiliar attacks, longer records for investigation, and built-in or integrated response actions. In practice, the boundary is blurry: many modern IDS products include behavioral features, and many NDR products include signature detection, so compare what each product actually detects and does.
