Five lessons I learned from building anomaly-based threat detection | by Alex Teixeira | Detect FYI
This is a short one for inspiring those planning or already adventuring with anomaly detection as part of their use cases backlog. Anomaly-based detection is the process of comparing definitions of what activity is considered normal against observed events to identify significant deviations. Above definition is from Security Controls Evaluation, Testing, and Assessment Handbook (2016) and that process seems to perfectly fit the challenges we face in Threat Detection: What is abnormal or anomalous in your environment? To get there you first need to figure out what normal is. Legit activity is happening every-single-second. That's a fact. Most logs or network packets are very likely related to expected activity (BAU). We simply can't state the same from actual, successful attacks! They will happen less often. Wait, what about that constant beaconing traffic (C2)? Well, it was new at some point. So that is one opportunity for us, defenders. So what about building a dataset representing wh
Five lessons I learned from building anomaly-based threat detection Alex Teixeira 4 min read · Aug 30, 2023 -- 2 Listen Share This is a short one for inspiring those planning or already adventuring with anomaly detection as part of their use cases backlog. Anomaly-based detection is the process of comparing definitions of what activity is considered normal against observed events to identify significant deviations . Above definition is from Security Controls Evaluation, Testing, and Assessment Handbook (2016) and that process seems to perfectly fit the challenges we face in Threat Detection: D
related reading
- Use customizable anomalies to detect threats in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- Mediumdetect.fyi
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Dealing with Noisy Behavioral Analytics in Detection Engineering | CMU Software Engineering Instituteinsights.sei.cmu.edu
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Securonix Documentationdocumentation.securonix.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Anomaly Detection in SOC – Friend or Foe? | 2019-12-27 | Security Magazinesecuritymagazine.com
- Intrusion Detection | Computer Securitytextbook.cs161.org
- Evolving Your SIEM Detection Rules: A Journey from Simple to Sophisticated | Databricks Blogdatabricks.com
- Best practices for creating custom detection rules with Datadog Cloud SIEM | Datadogdatadoghq.com