flâneur — a map of the web's best reading

Providing Conditions for Event Rarity

documentation.securonix.com · 26 words · saved by 1 readers

The Event Rarity algorithm identifies an entity's normal behavior based on the features selected and compares it with past behavior to detect the first time that a new type of transaction occurs. This policy learns from the repeated rare behavior of the user to distinguish new behavior from truly rare behavior. You can create the policy to run on datasources or for a functionality, and configure the number of days to observe the behavior to establish whether it is truly rare (i.e. it doesn't happen again within that number of days) or to determine the behavior was new for the entity and will be whitelisted (i.e. the behavior happens again within the number of days). Only behavior that is truly rare will be flagged as a violation. For What do you Want to Detect, choose Event Rarity. For Choose the Features for Generating Behavior, based on the policy, select the attributes Unified Defense SIEM will use to learn normal behavior. Behavior profiles are generated on a combination of the sel

, function (e) { // Prevent Chrome 76 and later from showing the mini-infobar e.preventDefault(); // Stash the event so it can be triggered later. window[

Explore this link on the map →

related reading