KR / KO

What Is UEBA? Definition, Benefits, and How It Works

What Is UEBA? Definition, Benefits, and How It Works

UEBA stands for user and entity behavior analytics. Previously known as user behavior analytics, UEBA is the process of tracking user behavior anomalies to identify potential cybersecurity risks or threats. The idea is to have a large data set on user behaviors and use variations from the norm of data within that set to trigger alerts or specific actions that can proactively fend off cyberattacks or stop them before they cause too much damage.

How Does UEBA Work?

UEBA tracks the behavior of users and entities of an organization to distinguish normal behavior from abnormal behavior. In the context of cybersecurity, a user or an entity can be any IT system, business process, or organization (including government).

UEBA monitors these users and entities by constantly reviewing and analyzing their data to determine whether a particular activity or behavior is anomalous and hence potentially dangerous because it could result in a cyberattack.

For example, a hacker could steal an employee’s password and log in to a system. Once inside that system, the hacker would likely behave in a way that’s totally different from the way the user has historically behaved and thus would trigger cyber threat alerts.

UEBA achieves this sophisticated anomaly tracking through a combination of machine learning, statistical analysis, and advanced analytics. Typically, a UEBA system establishes a “baseline” for user behavior and compares activity to this baseline.

UEBA vs. SIEM: How Are They Different?

Security information and event management (SIEM) uses dashboards to provide a holistic view of all security-related information and events and then triggers alerts if needed. SIEM platforms collect and aggregate data from various security tools and IT systems and then analyze that data.

UEBA systems, on the other hand, apply machine learning to analyze user behavior and hence can use this information to predict a potential cyber threat and send real-time alerts. SIEM is the original process, but companies soon found that incorporating UEBA strategies into SIEM made SIEM much more effective at monitoring threats in real time and responding quickly. That’s because UEBA tracks and analyzes user behavior, while SIEM doesn’t.

UBA vs. UEBA: Are They the Same?

Understanding the difference between user behavior analysis (UBA) and UEBA comes down to understanding why the “E” was added and who added it.

The “E” in “UEBA” stands for “entity” and came from a Gartner Market Guide published in 2017. That was the first time “UEBA” was used instead of “UBA.” Until then, the primary focus of UBA technology was on data theft and fraud. But companies soon realized that cyber threats were starting to come from places far beyond just users, including managed and unmanaged endpoints, cloud and mobile applications, networks, and various external threats. Gartner referred to these other sources of cyber risk as “entities.”

So, in short, UBA and UEBA are not the same, but they’re very closely related. UEBA is the more up-to-date version of UBA.

UEBA vs. SOAR: Which Is Better?

Security orchestration, automation, and response (SOAR) tools allow organizations to respond faster to security threats by collecting and centralizing data from different systems and platforms. In this way, SOAR tools are seen as a method of achieving a “single source of truth” for all cybersecurity-related data and activities. SOAR systems can also be used to automate responses to low-level security threats.

While SOAR emphasizes automation, data collection, and aggregation, UEBA focuses on the analysis of user and entity behavior. SOAR can speed things up, but UEBA can find anomalies that SOAR can’t. As such, neither tool or method is better than the other. Rather, they’re complementary, with different benefits, and probably best used in conjunction with each other.

Three Reasons to Use UEBA

UEBA is a powerful tool for monitoring and limiting potential cyber threats. These are the three main reasons to use UEBA:

  1. Reduced attack surface
  2. UEBA informs security teams of loopholes and weak points in their systems, thus reducing the potential for cyberattacks by reducing the overall attack surface.

  3. Improved operational efficiency
  4. UEBA can reduce the manual workload of security teams by using automation and machine learning to identify and validate threats. This gives security professionals more time to focus on real threats instead of chasing alerts.

  5. Superpowers
  6. “Superpowers” may be an exaggeration, but UEBA brings certain cybersecurity-related special powers to an organization, including the ability to detect potential data exfiltration before it happens, identify hijacked accounts, and prevent misuse of privilege.

    For these reasons, UEBA, especially in combination with other strategies such as SOAR, is an extremely effective way to proactively identify and prevent cyberattacks and reduce an organization’s exposure to cyber threats.

연락처
질문하기

퓨어스토리지 제품이나 인증 관련 질문이나 코멘트가 있으신가요?   저희가 도와드립니다.

데모 예약

라이브 데모를 예약하고 퓨어스토리지가 데이터를 어떻게 강력한 결과로 전환해주는지 직접 확인해 보세요. 

연락하기: +82 2 6001-3330

언론홍보팀:  pr@purestorage.com

 

퓨어스토리지코리아 주소

30F 아셈타워,

517 영동대로,

강남구, 서울

대한민국

korea@purestorage.com

닫기
지원하지 않는 브라우저입니다.

오래된 브라우저는 보안상 위험을 초래할 수 있습니다. 최상의 경험을 위해서는 다음과 같은 최신 브라우저로 업데이트하세요.