flâneur — a map of the web's best reading

Behavior-Based Policy Example - Activity Outler

documentation.securonix.com · 26 words · saved by 1 readers

This behavior-based policy detects when a user uploads an abnormally high volume of data compared to their normal behavior. Behavior-based policies build a baseline for the volume of bytes out by transaction on web proxy for the account. The following example is the abnormal amount of data uploads to external storage sites policy. Go to Menu > Analytics > Policy Violations. Click > Create Policy. Under Define Policy, specify the following: For Functionality, choose Web Proxy. Under Define Risk and Threat, specify the following: Threat Indicator: Data egress via network uploads What actions should be taken when this policy is violated?: Some possible further analysis/triage steps to consider: Some possible remediation steps after further analysis/triage: Click Save & Next. Select Spike in Volume/Amount. Under Choose the Features for Generatomng Behavior, select bytesout [Bytes_Sent] and transactionstring1 [Transaction]. For Behavior Name, enter "Total bytes transmitted to external site

, function (e) { // Prevent Chrome 76 and later from showing the mini-infobar e.preventDefault(); // Stash the event so it can be triggered later. window[

Explore this link on the map →

related reading