How it works?
For a UEBA solution to be effective, it must be installed on every device used by or connected to every employee across the organization.
There are three main components of a UEBA solution:
Analytics gathers and organizes data on what it considers to be regular user and entity activity. The system creates profiles of each user’s typical behavior in terms of application use, communication and download activities, and network connectivity. Statistical models are then developed and implemented to detect unusual behavior.
Integration with existing security products and systems in an organization. With proper integration, UEBA systems are able to compare data collected from various sources, such as logs, packet capture data, and other datasets, and integrate these to make the system more robust.
Presentation is the process of communicating the UEBA system’s results and formulating an appropriate response. It may simply generate an alert, either for the employee or for the IT administrator, to indicate the need of further investigation. Or it may set up to take quick action automatically.