What is Adaptive Protection?
Adaptive Protection is a feature within Symantec Endpoint Protection designed to monitor and manage behaviors of applications used in administrative tasks. It learns what constitutes 'normal' behavior for an organization and blocks actions that fall outside of established policies. This helps security teams identify potentially malicious activities while allowing legitimate operations to continue.
How does Adaptive Protection enhance security?
Adaptive Protection enhances security by reducing the attack surface through policy-driven controls. It can block over 450 individual actions that are deemed out of policy, thereby preventing unauthorized behaviors. This proactive approach allows security teams to focus on genuine threats while minimizing disruptions to normal business operations.
What were the results of the MRG Effitas testing?
MRG Effitas found that systems with Adaptive Protection detected threats an average of 4 seconds earlier than those without it. The testing demonstrated that Adaptive Protection could block attacks based on policy, which is generally more difficult for attackers to bypass compared to traditional behavioral signature blocks. Both systems provided robust protection, but Adaptive Protection offered a quicker response to threats.