The Insider Threat – Detection and Mitigation
From this chapter onward, we will look in detail at the practical application of what we learned in the last seven chapters. QRadar provides a provision wherein Docker-like applications can be installed, called QRadar apps. These apps vary in nature depending on what type of data they consume and how they use this data to provide value to customers. One such app that we will discuss in detail is User Behavior Analytics, also known as UBA.
When thinking about securing an organization, we usually think of the threat actors that come into play. Mostly, we think of securing our organization from outside threats by using firewalls, intrusion prevention systems, honeypots, and so on. If we look at the current trends in security breaches, we find that some threat actors are part of the same organization where the breach has happened. These actors are called insider threats.
The UBA app helps us monitor user behavior. If there is any...