A User and Entity Behavior Analytics Scoring System Explained

in #hacking8 years ago

 How risk assessment for UEBA (user entity behavior analytics) works is not unlike how humans assess risk in our surrounding environment. When in an unfamiliar setting, our brain constantly takes in data regarding objects, sound, temperature, etc. and weighs different sensory evidence against past learned patterns to determine if and what present risk is before us. 

A UEBA system works in a similar manner. Data from different log sources, such as Windows AD, VPN, database, badge, file, proxy, endpoints, etc. are ingested. Given these inputs and learned behaviors, how do we fuse the information to make up a final score for risk ranking? source

Coin Marketplace

STEEM 0.17
TRX 0.24
JST 0.034
BTC 95745.34
ETH 2808.33
SBD 0.67