flâneur — a map of the web's best reading

Elevating Security Intelligence with Splunk UBA's Machine Learning Models | Splunk

splunk.com · 1,215 words · saved by 1 readers

One of the most challenging aspects of running an effective Security Operations Center (SOC) is how to account for the high volume of notable events that actually do not present a risk to business. These events often include common occurrences like users forgetting their passwords a ridiculous number of times or accessing systems at odd hours for valid reasons. Despite their benign nature, struggling to handle the volume of such potential threats may often overwhelm limited staff. An even greater challenge is detecting unknown threats, such as Advanced Persistent Threats (APTs) and Insider Threats, which are constantly evolving and difficult to detect with traditional rule-based approaches. Splunk User Behavior Analytics (UBA) tackles these challenges using unsupervised machine learning to profile normal behavior for each user and asset. It then identifies unusual behavior patterns across users, devices and applications that go beyond human-designed rules, effectively searching for unk

Elevating Security Intelligence with Splunk UBA's Machine Learning Models | Splunk Elevating Security Intelligence with Splunk UBA's Machine Learning Models Security March 19, 2024 Cui Lin https://www.youtube.com/embed/Ogu80gQxBho?si=PaXeScU52IDiY7GG One of the most challenging aspects of running an effective Security Operations Center (SOC) is how to account for the high volume of notable events that actually do not present a risk to business. These events often include common occurrences like users forgetting their passwords a ridiculous number of times or accessing systems at odd hours

Explore this link on the map →

related reading