Role of User and Entity Behavior Analytics in Detecting Insider Attacks
Salman Khaliq, Zain Ul Abideen Tariq, Ammar Masood
Air University
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
Traditional cybersecurity products are neither designed nor capable of detecting sophisticated and carefully crafted insider attacks. The main focus of these cybersecurity products is on the red interface, the outside attackers; ignoring the green side, the legitimate users. Moreover traditional cybersecurity products do not provide complete vision of user activities within the organization. User and Entity Behavior Analytics (UEBA) has become an important aspect in organization's security because the legitimate users have more rights and access over the organization resources as compared to outsiders. Also, the users are not aware of the security threats that may cause huge damage to organization's confidential information and intellectual property. We discuss the different approaches used in User and Entity Behavior Analytics (UEBA) including user and role-based detection, user and entity activity mapping, user profiling techniques and risk score calculations of individuals. We present the UEBA approaches proposed in literature and generalized design and feature set of top level commercially available UEBA solutions. We also highlight the fact that open source community still lags behind in giving a sophisticated UEBA solution.
逐年被引趋势
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AINetwork Security and Intrusion Detection
Information and Cyber Security · User Authentication and Security Systems
参考文献 10
此处列出前 3 条
引用本文 31
按被引量排序,此处列出前 3 条