
To ensure high effectiveness of information security measures, the interaction of its components plays a crucial role. This connectivity allows for the mitigation of not only external but also internal threats. When designing network infrastructure, every protective measure is significant, whether it's antivirus software or a firewall, so that they operate not only within their own class (Endpoint Security or NGFW) but also have the capability to interact with each other to jointly combat threats.
A Bit of Theory
It's no surprise that today's cybercriminals have become more resourceful. They employ a variety of network technologies to spread malware:

Phishing emails lead to malware 'crossing the threshold' of your network, using known attacks or 'zero-day' exploits followed by privilege escalation or lateral movement within the network. The presence of even one infected device can mean that your network may be exploited for the malicious purposes of an attacker.
In some cases, when it is necessary to ensure the interaction of information security components, conducting an information security audit of the current state of the system cannot be described using a single interconnected set of measures. In most cases, many technological solutions focused on countering specific types of threats do not foresee integration with other technological solutions. For example, endpoint protection products use signature and behavioral analysis to determine whether a file is infected or not. To stop malicious traffic, firewalls utilize other technologies, such as web filtering, IPS, sandboxes, etc. However, in most organizations, these information security components are not linked to each other and operate in isolation.
Trends in implementing Heartbeat technology
The new approach to cybersecurity involves protection at every level, where the solutions used at each level are interconnected and capable of exchanging information with one another. This leads to the creation of a Synchronized Security (SynSec) system. SynSec is the process of ensuring information security as a unified system. In this case, each component of information security is connected to one another in real-time. For example, the solution is implemented based on this principle.

The Security Heartbeat technology ensures communication between security components, enabling the system to function collaboratively and be monitored. In the following classes of solutions are integrated:
- — a classic signature antivirus;
- — a specialized antivirus for servers;
- – next-generation antivirus (signature-less and utilizing artificial intelligence technologies);
- — Next-Generation Firewall;
- — management of mobile devices and access control to corporate email and files;
- ;
- — access points managed both from the cloud and locally via Sophos UTM / Sophos XG;
- — a classic solution for web traffic filtering;
- — cloud/local anti-spam/antivirus solution;
- — employee awareness training, conducting test phishing campaigns;
- — auditing cloud infrastructures.

It is not hard to notice that Sophos Central supports a fairly wide range of information security solutions. In Sophos Central, the SynSec concept is based on three key principles: detection, analysis, and response. To describe these in detail, we will focus on each of them.
SynSec Concepts
DETECTION (identifying unknown threats)
Sophos products managed by Sophos Central automatically share information among themselves to identify risks and unknown threats, which includes:
- analyzing network traffic with the ability to identify high-risk applications and malicious traffic;
- detecting users with high-risk profiles through correlational analysis of their actions on the network.
ANALYSIS (instant and intuitive)
Real-time incident analysis provides immediate insight into the current situation in the system.
- displaying the complete chain of events that led to the incident, including all files, registry keys, URLs, etc.
RESPONSE (automatic incident response)
Configuring security policies allows for automatic responses to infections and incidents in mere seconds. This is achieved by:
- instant isolation of infected devices and halting attacks in real time (even within a single network / broadcast domain);
- restricting access to company network resources for devices that do not comply with policies;
- remote initiation of device scanning upon detection of outgoing spam.
We have reviewed the main principles of protection on which Sophos Central operates. Now, let's describe how the SynSec technology manifests in action.
From theory to practice
To begin, let’s clarify how the interaction of devices based on the SynSec principle is established using Heartbeat technology. The first step is registering the Sophos XG in Sophos Central. At this stage, it receives a certificate for self-identification, an IP address and a port through which the endpoints will interact with it using Heartbeat technology, as well as a list of endpoint IDs managed through Sophos Central and their client certificates.
Shortly after the Sophos XG registration occurs, Sophos Central will transmit information to the endpoints to initiate interaction via Heartbeat technology:
- a list of certificate authorities used to issue Sophos XG certificates;
- a list of device IDs that are registered in Sophos XG;
- the IP address and port for interaction via Heartbeat technology.
This information is stored on the computer at the following path: %ProgramData%SophosHearbeatConfigHeartbeat.xml and is regularly updated.
Communication via the Heartbeat technology takes place through the endpoint sending messages to the magic IP address 52.5.76.173:8347 and back. Analysis has shown that packets are sent every 15 seconds, as stated by the vendor. It should be noted that Heartbeat messages are processed directly by the XG Firewall — it intercepts packets and monitors the endpoint's status. If packet capture is performed on the host, the traffic movement will resemble communication with an external IP address, although the endpoint actually interacts directly with the XG Firewall.

Let’s assume that a malicious application has somehow reached the computer. Sophos Endpoint detects this attack, or we stop receiving Heartbeat from this system. The infected device automatically sends information about the system infection, triggering an automated chain of actions. The XG Firewall immediately isolates the computer, preventing the spread of the attack and interaction with C&C servers.
Sophos Endpoint automatically removes the malware. After its removal, the endpoint synchronizes with Sophos Central, and then the XG Firewall restores network access. Root Cause Analysis (RCA) allows for a detailed understanding of what happened.

If we assume that access to corporate resources is done through mobile devices and tablets, can SynSec be ensured in this case?
For this scenario, Sophos Central provides support for and . Let’s assume that a user attempts to violate the security policy on a mobile device secured by Sophos Mobile. Sophos Mobile detects the security policy violation and sends notifications to the other system components, triggering a pre-configured incident response. If the policy "deny network connection" is set in Sophos Mobile, then Sophos Wireless will restrict network access for that device. On the Sophos Central dashboard under the Sophos Wireless tab, a notification will be displayed indicating that the device is infected. While the user attempts to access the network, a splash screen will appear informing them that internet access is restricted.


The endpoint has several Heartbeat status states: red, yellow, and green.
The red status occurs in the following cases:
- active malware detected;
- attempt to launch malware detected;
- malicious network traffic detected;
- malware was not removed.
The yellow status indicates that inactive malware has been detected on the endpoint or potential unwanted applications (PUAs) have been detected. The green status shows that none of the above issues were found.
Having reviewed some classic scenarios of protected devices interacting with Sophos Central, we will now describe the graphical interface of the solution and discuss the main settings and supported features.
Graphical interface
The dashboard displays the latest notifications. A summary characteristic of various protection components is also shown in the form of charts. In this case, consolidated data on protection for personal computers is displayed. This panel also provides summary information on attempts to access dangerous resources and resources with unacceptable content, along with email analysis statistics.

Sophos Central supports displaying notifications by severity, which prevents users from missing critical security system alerts. In addition to the concisely presented summary information on the protection system status, Sophos Central supports event logging and integration with SIEM systems. For many companies, Sophos Central serves as a platform for both their internal SOC and for providing services to their clients — MSSP.
One of the important features is the support for update caching for endpoint clients. This saves external traffic bandwidth, as updates are downloaded once to one of the endpoint clients, and then other devices download the updates from it. In addition to this capability, the selected endpoint can relay security policy messages and informational reports to the Sophos cloud. This function will be useful if there are endpoint devices that do not have direct internet access but require protection. Sophos Central includes an option (tamper protection) that prohibits changing security settings on the computer or removing the endpoint agent.
One of the components of endpoint protection is next-gen antivirus (NGAV) — . With deep machine learning technologies, the antivirus can detect previously unknown threats without using signatures. Its detection accuracy is comparable to that of signature-based counterparts, but unlike them, it provides proactive protection by preventing zero-day attacks. Intercept X can operate alongside signature-based antivirus solutions from other vendors.
In this article, we briefly discussed the SynSec concept implemented in Sophos Central, as well as some of the capabilities of this solution. We will explain how each of the protection components integrated into Sophos Central functions in future articles. You can obtain a demo version of the solution .
Source: habr.com
