User and Entity Behavior Analytics (UEBA)
5 slides · 2 min read · Domain 7
User and Entity Behavior Analytics
User and Entity Behavior Analytics detects threats by analyzing unusual behavior patterns across users, devices, and systems.
User and Entity Behavior Analytics (UEBA) tools rely on machine learning (ML) and Al to analyze user and entity behavior within an organization.
UEBA systems typically consist of three core components use cases, analytics, and data.
These systems build templates of normal behavior by continuously monitoring the environment over time. Templates may include behavioral patterns for individual users in the identity and access management (IAM) environment, as well as system-level behaviors. UEBA systems are also informed by predefined use cases that reflect known attack patterns, such as malicious insiders, compromised user identities, or zero-day threats. For example, MITRE's ATT&CK framework offers numerous use cases that organizations or system vendors can use to train models.
As UEBA systems collect more data, they may require supervised training to help distinguish between acceptable anomalies and suspicious behavior.
This enables them to detect previously unknown attacks using a gradual or escalating response model. Managers must then decide whether to apply strict enforcement-which may generate more false positives and disrupt legitimate activity—or a more lenient approach, which could reduce false positives but increase the risk of allowing unauthorized access.
UEBA systems rely on the information collected by the logging and Security Information and Event Management (SIEM) systems and are often implemented as an analytical function of the SIEM environment.
This distinction between SIEM and UEBA may seem somewhat blurred, as both approaches rely on much of the same data for decision-making. Rather, they are complementary technologies, with the SIEM providing incident response and security automation and the UEBA system focusing on analysis of large volumes of data. Anomalous system activity can then be passed to the SIEM for action. (Some market analysts suggest that SIEM and UEBA are converging, so the need to distinguish the two as capabilities may become moot.)
Integrating UEBA capabilities into an existing systems environment can be complex. However, once aligned with your access control, security data gathering, incident detection, and response processes, UEBA can continue to adapt and learn as new threats emerge.
