Saltar al contenido
03 · SOC Gestionado03 · Managed SOC

Gestión de NDRNDR Management

Detección y respuesta sobre el tráfico de red, incluido el que no pasa por un agente.Detection and response across network traffic, including traffic no agent sees.

NDRNDR 3.3 · Servicios Gestionados de Plataformas3.3 · Managed Platform Services

¿Qué es este servicio?What is this service?

Es la detección y respuesta sobre el tráfico de red: sensores que analizan lo que circula por los enlaces, extraen metadatos y detectan comportamientos anómalos sin instalar nada en los equipos, más el equipo que interpreta esas detecciones.

Detection and response over network traffic: sensors that analyse what flows across the links, extract metadata and detect anomalous behaviour without installing anything on endpoints, plus the team that interprets those detections.

¿Para qué se usa?What is it used for?

Sirve para ver lo que el EDR no puede ver por definición: impresoras, cámaras, controladores industriales, equipos médicos, dispositivos IoT, appliances cerrados y computadoras de terceros o contratistas. En todos esos no se instala un agente, y sin embargo están en la misma red. El NDR no reemplaza al EDR: cubre el porcentaje del parque donde el EDR nunca va a llegar, y además ve el tráfico entre servidores internos que nunca cruza el firewall.

It sees what EDR cannot see by definition: printers, cameras, industrial controllers, medical equipment, IoT devices, closed appliances and third-party or contractor laptops. None of those take an agent, yet all of them sit on the same network. NDR does not replace EDR: it covers the share of the estate EDR will never reach, and it also sees the traffic between internal servers that never crosses the firewall.

Qué beneficios traeBenefits it delivers

  • Cubre los dispositivos donde no se puede poner agente, que en entornos industriales o sanitarios pueden ser la mayoría del parque.
  • Ve el tráfico interno entre servidores, donde ocurre el movimiento lateral y donde el firewall perimetral no mira.
  • El atacante no puede desinstalar el sensor ni desactivarlo desde el equipo comprometido, porque no está ahí.
  • Guarda metadatos de red que sirven de evidencia forense incluso cuando el equipo original ya fue formateado.
  • Covers devices that cannot take an agent, which in industrial or healthcare settings can be most of the estate.
  • Sees internal server-to-server traffic, where lateral movement happens and where the perimeter firewall does not look.
  • The attacker cannot uninstall or disable the sensor from the compromised machine, because it is not there.
  • Retains network metadata that serves as forensic evidence even after the original machine has been wiped.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No es obligatorio en Costa Rica.
  • El Acuerdo CONASSIF 5-24 exige a las entidades supervisadas capacidades de detección; en entornos con muchos dispositivos que no admiten agente, esta suele ser la única forma de tenerlas.
  • It is not mandatory in Costa Rica.
  • CONASSIF Agreement 5-24 requires supervised entities to have detection capabilities; in environments full of devices that cannot take an agent this is often the only way to have them.

InternacionalInternational

  • PCI-DSS v4.0.1 exige mecanismos de detección y prevención de intrusiones que vigilen el tráfico en el perímetro y en los puntos críticos del entorno de datos de tarjeta.
  • ISO 27001 exige monitorizar las redes y los sistemas para detectar comportamientos anómalos.
  • NIS2 y DORA no nombran la tecnología, pero exigen detectar incidentes en entornos que suelen incluir tecnología operativa donde el agente no es opción.
  • PCI-DSS v4.0.1 requires intrusion detection and prevention mechanisms watching traffic at the perimeter and at critical points of the cardholder data environment.
  • ISO 27001 requires monitoring networks and systems to detect anomalous behaviour.
  • NIS2 and DORA do not name the technology, but require detecting incidents in environments that often include operational technology where an agent is not an option.

Requisitos mínimosMinimum requirements

  • Puntos de captura definidos: puertos espejo o derivaciones físicas en los enlaces que de verdad importan, no en cualquiera.
  • Decidir qué se hace con el tráfico cifrado: descifrarlo en un punto de inspección o aceptar el análisis por metadatos y comportamiento.
  • Un inventario de dispositivos, aunque sea parcial, para distinguir lo normal de lo anómalo en los primeros meses.
  • Almacenamiento suficiente para los metadatos, que crecen rápido si se quiere retención útil para investigar.
  • Defined capture points: mirror ports or physical taps on the links that genuinely matter, not on any of them.
  • Deciding what to do about encrypted traffic: decrypt it at an inspection point or accept metadata and behavioural analysis.
  • A device inventory, even a partial one, to tell normal from anomalous in the first months.
  • Enough storage for metadata, which grows fast when the retention has to be useful for investigation.

Plazo típico de entregaTypical delivery time

Servicio continuo Ongoing service rango habitual del mercado usual market range

Es un servicio continuo. El despliegue va de cuatro a ocho semanas: definir dónde se capta, coordinar la intervención en la red, instalar los sensores y dejar que la plataforma aprenda qué es normal. Lo que más suele demorar no es técnico sino conseguir la ventana para tocar los switches del núcleo.

This is a continuous service. Deployment takes four to eight weeks: defining capture points, coordinating the network work, installing sensors and letting the platform learn what normal looks like. What usually takes longest is not technical but getting the window to touch the core switches.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

NDRNDR
Detección y respuesta de red: analiza el tráfico que circula en vez de lo que pasa dentro de cada equipo. Network detection and response: it analyses the traffic flowing rather than what happens inside each machine.
Tráfico este-oesteEast-west traffic
El que va entre sistemas internos, sin salir a internet. Es donde se mueve el atacante y donde casi nadie mira. Traffic between internal systems, never leaving for the internet. Where the attacker moves and where almost nobody looks.
SPAN · TAPSPAN · TAP
Las dos formas de darle una copia del tráfico al sensor: por configuración del switch o con un aparato intercalado en el cable. The two ways of giving the sensor a copy of the traffic: by switch configuration or with a device inserted in the cable.
OTOT
Tecnología operativa: los sistemas que controlan procesos físicos en plantas, hospitales o servicios públicos. Casi nunca admiten agente. Operational technology: the systems controlling physical processes in plants, hospitals or utilities. They almost never accept an agent.
C2C2
El canal por el que el atacante comanda el equipo infectado. Deja un patrón de red reconocible aunque vaya cifrado. The channel through which the attacker commands the infected machine. It leaves a recognisable network pattern even when encrypted.