With the surge in increasingly rapid and complex attacks, defenders must be more ingenious than ever to implement the countermeasures needed for an effective defense. But which ones? One potential answer lies in user behavior analytics tools.

TheEndpoint Detection & Response (EDR) andXDR are tools based on artificial intelligence and behavioral analysis.

UBA, or " User Behavior Analytics ," which has been around for a few years, should be part of every cybersecurity team's detection arsenal. But what is its purpose? Why is it necessary? And how does it work?

These are the questions we are asking today, and we will attempt to answer them. We will also look at how behavioral analysis can effectively integrate with existing tools like SIEM or XDR technology, and provide some tips for getting the most out of this type of tool.

  1. How can UEBA detect security incidents that traditional tools miss?
  2. What behaviors are detected?
  3. What is the relationship between UEBA, SIEM, and EDR?
  4. Best practices for using UEBA
    1. Define use cases
    2. Diversify analysis types
    3. Define data sources and behaviors
    4. Regular updates
    5. Enhance correlation and contextualization
  5. Adopt a holistic approach to cybersecurity

How can UEBA detect security incidents that traditional tools miss?

Behavioralanalysis is not a new technique, especially in cybersecurity. In recent years, it has become clear that information systems are in constant flux and that users would become one of the most complex "objects" to monitor.

Simply put, behavioral analysis implements a number of more or less sophisticated mechanisms to detect activities that indicate unusual or abnormal behavior in a given environment. By extension, User Behavior Analytics (UBA) focuses more specifically on user activity, helping to answer the questions most often missing from traditional detection systems: who, when, and where?

However, the limitations of analysis focused solely on the user quickly became apparent. Indeed, the contextualization required for effective cybersecurity detection meant we also needed to define the "what?" (What on? What with? From what?)

UBA then evolved into UEBA (User and Entity Behavior Analytics), a term concretely defined by Gartner in 2015.[1] UEBA focuses on the behavior of both users and applications. The latter are represented by the "E" for "Entity." The "E" therefore refers to specific assets such as the cloud, endpoints, the network, and so on.

UEBA has the same capabilities as UBA, but in addition to analyzing user activity, the engine also analyzes the activity of these entities, which can impact user behavior and vice versa.

To function, UEBA is capable of processing a multitude of data from various sources such as SIEMs, EPP solutions, NTA, system logs, and, of course, EDRs.

The power of a UEBA analysis engine lies in learning behavioral patterns. Generally, UEBA uses Machine Learning, and sometimes Deep Learning, to create a behavioral map of every monitored object, thereby defining a comprehensive baseline matrix against which each new entry is evaluated.

What behaviors are detected?

These can include the use of unusual devices or commands, logins at odd hours, typing sequences that are too fast, data exfiltration attempts, access to specific system files, privilege modifications on certain user accounts, or anomalous geographic logins.

Naturally, more complex scenarios can be implemented to cover specific risks related to particular groups within the company, precise job functions, or highly critical applications.

Here is a specific example of a detection stage:

étapes de détection d'une attaque

Below is a more comprehensive look at how behavioral analysis works :

What is UEBA?

Behavioral analysis acts as a proactive measure by enabling the earliest possible detection of potential threats. As shown in the diagram above, this can range from suspicious traffic to an excessive number of login attempts, and more.

All this information helps provide additional insights, allowing for a response that mitigates risk. UEBA is not a defense mechanism, but a monitoring process.

What is the link between UEBA, SIEM, and EDR?

Some EDRs lack contextual awareness, which limits their performance. This lack of visibility becomes a barrier to automation and alert processing. The TEHTRIS EDR includes an integrated tactical SIEM and behavioral analysis mechanisms that provide context during the detection phase. By supplementing an EDR with behavioral analysis within a SIEM, detection capabilities are significantly enhanced.

UEBA is now integrated into XDR technologies.

As a reminder, SIEMs collect and aggregate data from security tools and IT systems, analyze it, and provide real-time alerts to analysts. Behavioral analysis components are increasingly being added. This allows for better detection by incorporating a human dimension that was previously overlooked. Adding UEBA to a SIEM provides a complete view of data usage in a hybrid environment (at both the user and device levels).

UEBA is a technological opportunity that allows defenders to focus on their core work. Certain controls are now performed in a hyper-automatedway. Behavioral analysis helps eliminate false positives by assisting analysts in determining what to look for, answering the question: what is normal and what is not? To do this, the UEBA engine collects information on the expected behavior of both users and machines, creating baselines via the SIEM, which then determines whether unusual behavior constitutes a real threat. UEBA combines machine learning and rules to create standard profiles.

UEBA is a reliable solution when paired with technologies that provide context, such as EDR, NTA, etc. Here is a diagram representing an optimal detection system:

UEBA integrated into a solution like XDR technology adds an extra layer of detection against internal and external threats. It provides added value in terms of protecting movements on the endpoint, the user, and local network traffic.

The XDR platform centralizes and consolidates data collected by the various sensors and probes deployed within an information system.

According to the 2020 Verizon Data Breach Investigations Report, more than 25% of breaches took months or even longer to be discovered.

It is now understood that we must no longer focus solely on monitoring technical infrastructure. We must now also monitor the user and their ecosystem, which can potentially be a source of threat.

Early detection and reduced response time are the primary benefits of UEBA technology. Anticipate the threat, and thereby reduce the risk.

But to be as effective as possible, UEBA algorithms must be fed with multiple, comprehensive, and, above all, reliable data. And this is where TEHTRIS provides its full value. All components of the TEHTRIS XDR Platform come into play, not only in collection but also in processing, scoring, aggregation, and more. The behavioral analysis engine integrated into our XDR platform is therefore fed with immediately actionable data in real time.

Equipping yourself with UEBA technology is a real asset in your cyber defense arsenal, but you must keep a few best practices in mind to make it work.

UEBA best practices

For optimal UEBA performance, it is important to be as close as possible to the endpoint and the user; this is the case with the TEHTRIS XDR Platform which, thanks to its technology, is the most effective and advanced on the market. It can map precise behavioral profiles and adapt to each client's context.

UEBA does not replace other security systems but provides real added value.

Therefore, to be effective, you will need to:

Define use cases

Depending on their detection needs and the associated risk coverage, each operational detection team will focus on detecting privileged account abuse, compromise, identity theft, or fraud. Each situation to be monitored is a specific use case that unfolds one or more technical scenarios. This is a crucial phase in the implementation of behavioral analysis. The algorithms must "understand" where they are to be relevant. And these use cases must not be set in stone; on the contrary, they must be scalable, dynamic if necessary, and capable of taking multiple organizational systems into account.

Multiply analysis types

The analysis must, of course, focus on privileged or high-risk users, but not exclusively. As we have seen previously, depending on the risk to be covered, several scenarios can be deployed. And it is highly recommended to create, cross-reference, and correlate them all.

Define data sources and behaviors

Choosing the right data is essential. You must be able to define what you are looking for and where to find it. To do this, it is imperative to determine data sources and evaluate their quality, quantity, frequency, and more. This qualitative and quantitative audit work is what is performed upstream and on your behalf by the TEHTRIS XDR platform : each of its components is involved in gathering clean, complete, and reliable information. The UEBA then simply uses this data through its algorithms to cover detection use cases. It is imperative to collect data from a variety of sources; the TEHTRIS XDR Platform has been deployed in over 100 countries and can interface with existing security solutions on the market, giving it a vast scope of operation and the ability to process large volumes of activity.

Regular updates

The Machine Learning algorithms need to be regularly reviewed, adjusted, and sometimes corrected to best align with the data being processed, as well as with the constant evolution of the information system and the behavior of the company and its users. The health crisis was a glaring example: algorithms that were not adapted to the situation no longer perceived the environment correctly and generated false detections. Updating scenarios, collected data, and algorithms is therefore a key to success.

The hyper-automation of the TEHTRIS XDR platform offers this advantage as well. The relevance of its detection algorithms allows for real-time decision-making.

Enriching correlation and contextualization

As we have just seen, regular updates are important because context and current events evolve, and scoring must evolve accordingly. This scoring impacts threat detection. With every behavioral deviation, the system adds to the risk score of a specific user or machine. The more unusual the behavior, the higher the risk score. Aggregation happens automatically; as soon as the score reaches a certain level, the analyst is notified and can take action. Without this context, data is far less useful and can lead to false positives.

For more details, discover the TEHTRIS XDR platform: https://tehtris.com/fr/produits/xdr-extended-detection-response/

Discover the product

Request a demo

Adopting a holistic approach to cybersecurity

A comprehensive approach to security is once again the most appropriate. You must be able to combine behavioral analysis,aided by machine learning, and, on the other hand, automation via XDR technology.

While an effective and responsive cybersecurity defense strategy focused on real-time attack detection is important, such an approach alone is insufficient. It is also necessary to invest in a proactive solution, focus on how an attack might occur, and automate neutralization. TEHTRIS is working toward this goal, continuing its commitment to innovation, which remains at the very heart of our DNA.

Security is an everyday challenge. It is therefore imperative for companies to focus on their most critical assets. To do this, they must adopt a comprehensive view of their information systems and the associated risks. This holistic approach to cybersecurity, based on risk management, requires a very clear definition of detection and anticipation strategies.

This global approach relies primarily on the ability to identify and classify a company's critical data in order to define risks and the scenarios needed to address them. Adopting and implementing the right tools and techniques is the key to a perfect cyber defense posture, which is exactly what TEHTRIS understood years ago: develop a complete and reliable ecosystem capable of collecting, analyzing, and correlating all available security information to produce contextualized, immediately actionable alerts. With the XDR Platform, TEHTRIS is shifting the cybersecurity paradigm, which until now had been confined to infrastructure issues.

The TEHTRIS XDR Platform takes into account all of a company's activities, from perimeter infrastructure in legacy domains to the most remote infrastructure, such as the cloud and its multitude of applications.

For more details on our offerings, please do not hesitate to contact us.

Contact us

[1] Gartner-Avivah Litan-Market Guide for User and Entity Behavior Analytics Published 22 September 2015

Continue reading
Blog
Contactez Tehtris
Nos équipes vous recontacteront au plus vite afin d'échanger sur vos challenges cyber et évaluer comment nous pouvons vous accompagner pour les adresser.
Tehtris EDR : conçu, développé et opéré en Europe
Voir nos preuves
Derniers articles
See all