Anomaly Detection in SOC – Friend or Foe? | 2019-12-27 | Security Magazine
There are lots of buzzwords floating around cybersecurity: machine learning, artificial intelligence, supervised and unsupervised learning … In many cases these advanced technologies are based on anomaly detection. This makes a lot of sense since it’s hard - even impossible - to anticipate an attacker’s behavior. Also, in many cases there is not enough classified data to distinguish between benign and malicious events. Various behavioral anomaly detection techniques are used in almost every aspect of cybersecurity. For example, anomaly detection is extensively used in UEBA (User and Entity Behavioral Analytics), NTA (Network Traffic Anomaly), Endpoint operational anomalies etc. An anomaly can mean things like : “Too many failed logins” in UEBA, “A lot of traffic sent from A to B” (where typically it sends much less) in NTA, a process that executes another process that looks like a statistical anomaly in endpoint protection etc. Anomalies can be strong indicators of malicious activity b
Cybersecurity Security Enterprise Services Security Leadership and Management Security & Business Resilience Security Education & Training Anomaly Detection in SOC – Friend or Foe? Lots of security vendors talk about integrating innovative techniques using Artificial Intelligence. In cybersecurity, this often boils down to supervised or unsupervised anomaly detection of measures attributes. However, in many cases there is a big gap between the identification of anomalies and transforming them into actionable data. By Haim Zlatokrilov December 27, 2019 There are lots of buzzwords floating aroun
Explore this link on the map →related reading
- A gentle introduction to mechanistic anomaly detection — LessWronglesswrong.com
- Use customizable anomalies to detect threats in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Elevating Security Intelligence with Splunk UBA's Machine Learning Models | Splunksplunk.com
- Evolving Your SIEM Detection Rules: A Journey from Simple to Sophisticated | Databricks Blogdatabricks.com
- Behavior Analytics in Your Security Data Lake Just Got Way Easieromeronsecurity.com
- Intrusion Detection | Computer Securitytextbook.cs161.org
- Fundamentals to Security Alert Automation: SOAR Your Own Way | by Ryan G. Cox | Mediummedium.com
- Mediumdetect.fyi
- A gentle introduction to mechanistic anomaly detection — LessWronglesswrong.com