Introduction
FortiNDR (On-premises) is Fortinet’s Network Detection and Response product, targeted for on-premises installation where no network metadata leaves the network, supporting OT and air-gapped infrastructure. FortiNDR form factors include appliances, VM/KVM and public cloud (BYOL), with distributed sensor and center support. FortiNDR can classify both network-based and file-based (malware) threats, provide network visibility, including East-West traffic in Datacenter/Cloud environments. The solution is equipped with Artificial Neural Networks (ANN) to classify malware into attack scenarios, surface outbreak alerts, and trace the source of malware infections. Network-based attacks such as intrusions, botnets, compromised IOCs, weak ciphers and vulnerable protocols can also be detected. Supervised and unsupervised machine learning (ML) continuously analyze metadata across networks to identify threats; remediation can be leveraged via Fortinet Security Fabric.