To protect against sophisticated attacks, you need to detect anomalous behavior of all your users and entities. User and entity behavior analytics (UEBA) uses machine learning to establish a ‘normal profile’ for each user and entity; actions performed by users and entities are then compared to their ‘normal profile’ to identify anomalies and potential threats.
With the use of examples, this white paper breaks down the intricacies of UEBA, and helps you keep attackers at bay.
Key takeaways include:
- How a multi-layered defense strategy that includes both UEBA and SIEM safeguards businesses
- The benefits of using UEBA
- Determining your risk appetite and working with risk scores
- How UEBA works to discover unknown threats
- The different anomalous behaviors of users and entities