flâneur — a map of the web's best reading

Anomaly Detection in SOC – Friend or Foe? | 2019-12-27 | Security Magazine

securitymagazine.com · 691 words · saved by 1 readers

There are lots of buzzwords floating around cybersecurity: machine learning, artificial intelligence, supervised and unsupervised learning … In many cases these advanced technologies are based on anomaly detection. This makes a lot of sense since it’s hard - even impossible - to anticipate an attacker’s behavior. Also, in many cases there is not enough classified data to distinguish between benign and malicious events. Various behavioral anomaly detection techniques are used in almost every aspect of cybersecurity. For example, anomaly detection is extensively used in UEBA (User and Entity Behavioral Analytics), NTA (Network Traffic Anomaly), Endpoint operational anomalies etc. An anomaly can mean things like : “Too many failed logins” in UEBA, “A lot of traffic sent from A to B” (where typically it sends much less) in NTA, a process that executes another process that looks like a statistical anomaly in endpoint protection etc. Anomalies can be strong indicators of malicious activity b

Cybersecurity Security Enterprise Services Security Leadership and Management Security & Business Resilience Security Education & Training Anomaly Detection in SOC – Friend or Foe? Lots of security vendors talk about integrating innovative techniques using Artificial Intelligence. In cybersecurity, this often boils down to supervised or unsupervised anomaly detection of measures attributes. However, in many cases there is a big gap between the identification of anomalies and transforming them into actionable data. By Haim Zlatokrilov December 27, 2019 There are lots of buzzwords floating aroun

Explore this link on the map →

related reading