User and Entity Behavior Analysis
Traditional enterprise cybersecurity relies on a Security Information and Event Management (SIEM) system to gather data needed for detecting and triaging security-related incidents. Based on this data, security experts create rules using their knowledge of known attacker tactics and techniques. They create a playbook where those rules are stored and a series of steps are defined on what actions are performed when data is found that matches those rules. This type of defensive system can detect a majority of threats that traditionally affect IT systems. However, especially in recent years, this kind of defense is becoming insufficient, as the attacks are getting more sophisticated and the threat actors find a way to evade defenses.
User Entity and Behavioral Analysis (UEBA) is a concept that enables us to provide solutions to these problems. Under this term, we consider a set of techniques for characterizing the behavior of users and entities (computers...