1
00:00:00,180 --> 00:00:01,012
In this lesson,

2
00:00:01,012 --> 00:00:03,870
we will cover user behavior analytics.

3
00:00:03,870 --> 00:00:06,420
User behavior analytics, or UBA,

4
00:00:06,420 --> 00:00:08,160
is an advanced cybersecurity strategy

5
00:00:08,160 --> 00:00:10,860
that leverages the power of big data and machine learning

6
00:00:10,860 --> 00:00:13,488
to analyze user behaviors and detect anomalies

7
00:00:13,488 --> 00:00:16,290
that may indicate potential security threats.

8
00:00:16,290 --> 00:00:19,050
As cybersecurity threats evolve, organizations are moving

9
00:00:19,050 --> 00:00:21,420
beyond traditional signature based detection methods,

10
00:00:21,420 --> 00:00:24,120
and instead are turning to user behavior analytics

11
00:00:24,120 --> 00:00:27,079
to create a more proactive defense posture.

12
00:00:27,079 --> 00:00:29,970
Now, depending on who you're talking to,

13
00:00:29,970 --> 00:00:32,700
you may hear many people call this type of technology

14
00:00:32,700 --> 00:00:34,230
user behavior analytics,

15
00:00:34,230 --> 00:00:36,000
again, also known as UBA,

16
00:00:36,000 --> 00:00:39,693
or user and entity behavior analytics, known as UEBA.

17
00:00:40,650 --> 00:00:42,900
Really, these technologies are very similar,

18
00:00:42,900 --> 00:00:46,200
but UEBA as the monitoring of entities

19
00:00:46,200 --> 00:00:48,900
to our user behavior analytics.

20
00:00:48,900 --> 00:00:50,430
When we are talking about entities,

21
00:00:50,430 --> 00:00:52,920
we're referring to things beyond your user accounts

22
00:00:52,920 --> 00:00:56,880
like your routers, servers, and endpoints in the network.

23
00:00:56,880 --> 00:01:00,840
Now, user behavior analytics is a rapidly evolving field

24
00:01:00,840 --> 00:01:04,319
that leverages big data to understand user behavior

25
00:01:04,319 --> 00:01:06,240
within system and networks.

26
00:01:06,240 --> 00:01:09,180
User behavior analytics collects data from various sources

27
00:01:09,180 --> 00:01:12,780
to identify patterns that represent typical user behavior.

28
00:01:12,780 --> 00:01:14,550
With user behavior analytics,

29
00:01:14,550 --> 00:01:16,860
our goal is to detect anomalous behavior

30
00:01:16,860 --> 00:01:19,710
or instances that deviate from these established patterns

31
00:01:19,710 --> 00:01:21,840
that could indicate potential security threats

32
00:01:21,840 --> 00:01:24,270
such as insider threats, compromised credentials,

33
00:01:24,270 --> 00:01:25,833
or external attacks.

34
00:01:26,670 --> 00:01:28,890
Our user behavior analytic systems

35
00:01:28,890 --> 00:01:30,720
utilize machine learning algorithms

36
00:01:30,720 --> 00:01:34,890
to learn and understand normal user behavior over time.

37
00:01:34,890 --> 00:01:37,020
As they learn what normal looks like,

38
00:01:37,020 --> 00:01:38,580
they will then begin to understand

39
00:01:38,580 --> 00:01:41,280
how to identify deviations that should be flagged

40
00:01:41,280 --> 00:01:44,910
for further investigation by a member of your security team.

41
00:01:44,910 --> 00:01:46,408
User behavior analytics systems

42
00:01:46,408 --> 00:01:48,750
are designed to collect and analyze data

43
00:01:48,750 --> 00:01:49,920
from various sources,

44
00:01:49,920 --> 00:01:52,080
including network traffic, user devices,

45
00:01:52,080 --> 00:01:53,640
and application logs.

46
00:01:53,640 --> 00:01:55,050
This data is then processed

47
00:01:55,050 --> 00:01:56,880
using advanced analytic techniques

48
00:01:56,880 --> 00:01:59,430
such as machine learning and statistical analysis

49
00:01:59,430 --> 00:02:02,550
to create a baseline of normal user behavior.

50
00:02:02,550 --> 00:02:04,440
Once this baseline is established,

51
00:02:04,440 --> 00:02:07,308
the user behavior analytic system will continuously monitor

52
00:02:07,308 --> 00:02:08,984
your organization's user activity

53
00:02:08,984 --> 00:02:11,009
while comparing it to the baseline

54
00:02:11,009 --> 00:02:13,290
to identify any anomalies.

55
00:02:13,290 --> 00:02:15,240
For example, if a user typically logs in

56
00:02:15,240 --> 00:02:17,100
during regular business hours

57
00:02:17,100 --> 00:02:19,680
but suddenly starts logging in late at night,

58
00:02:19,680 --> 00:02:22,050
this could be flagged as anomalous behavior.

59
00:02:22,050 --> 00:02:24,600
Now, this may or may not be malicious,

60
00:02:24,600 --> 00:02:26,662
but because a user is working late to finish a big project,

61
00:02:26,662 --> 00:02:29,040
which might be fine, but either way,

62
00:02:29,040 --> 00:02:31,500
this behavior is outside their normal behavior,

63
00:02:31,500 --> 00:02:32,850
so it will create an alert

64
00:02:32,850 --> 00:02:34,500
for the security team to review.

65
00:02:34,500 --> 00:02:35,820
If it is found to be malicious,

66
00:02:35,820 --> 00:02:37,290
then the account could be suspended

67
00:02:37,290 --> 00:02:40,020
and response actions undertaken.

68
00:02:40,020 --> 00:02:42,570
Similarly, if a user who usually accesses

69
00:02:42,570 --> 00:02:44,100
a specific set of files

70
00:02:44,100 --> 00:02:46,320
starts accessing a different set of files,

71
00:02:46,320 --> 00:02:48,570
this could also be flagged as suspicious.

72
00:02:48,570 --> 00:02:50,580
For example, if one of our instructors

73
00:02:50,580 --> 00:02:52,920
starts trying to access our human resource

74
00:02:52,920 --> 00:02:54,930
or financial data, that will be flagged,

75
00:02:54,930 --> 00:02:56,850
since they are normally not required

76
00:02:56,850 --> 00:02:58,680
to access the more sensitive areas

77
00:02:58,680 --> 00:03:00,557
of our organization's share drive.

78
00:03:00,557 --> 00:03:02,820
Now, as you can probably guess,

79
00:03:02,820 --> 00:03:04,170
there are a lot of benefits

80
00:03:04,170 --> 00:03:06,420
of using user behavior analytics tools,

81
00:03:06,420 --> 00:03:08,370
including early detection of threats,

82
00:03:08,370 --> 00:03:12,300
insider threat detection, and improved incident response.

83
00:03:12,300 --> 00:03:15,150
First, we have early detection of threats.

84
00:03:15,150 --> 00:03:16,710
User behavior analytics tools

85
00:03:16,710 --> 00:03:19,890
can be used to help organizations identify potential threats

86
00:03:19,890 --> 00:03:22,020
before they cause significant damage.

87
00:03:22,020 --> 00:03:24,480
By detecting anomalous behavior early,

88
00:03:24,480 --> 00:03:27,120
your organization can respond more quickly and effectively

89
00:03:27,120 --> 00:03:29,730
to prevent the spread of that given threat.

90
00:03:29,730 --> 00:03:31,560
For example, if one of our employees

91
00:03:31,560 --> 00:03:34,470
were to download a large amount of data from our servers,

92
00:03:34,470 --> 00:03:37,648
this could indicate a potential server exfiltration attempt.

93
00:03:37,648 --> 00:03:40,890
If we have a user behavior analytic system in place,

94
00:03:40,890 --> 00:03:42,678
it could flag this behavior as anomalous

95
00:03:42,678 --> 00:03:45,840
and alert our security team to a potential threat.

96
00:03:45,840 --> 00:03:48,210
If we instead relied on traditional detection methods

97
00:03:48,210 --> 00:03:51,510
like manual log analysis, this threat may go undetected

98
00:03:51,510 --> 00:03:53,760
for several days, weeks, or even months

99
00:03:53,760 --> 00:03:56,190
before a security team member identifies it.

100
00:03:56,190 --> 00:03:58,452
Second, we have insider threat detection.

101
00:03:58,452 --> 00:04:00,097
User behavior analytics tools

102
00:04:00,097 --> 00:04:03,630
are particularly effective at identifying insider threats,

103
00:04:03,630 --> 00:04:06,720
which are often some of the most difficult things to detect

104
00:04:06,720 --> 00:04:08,460
using traditional security measures.

105
00:04:08,460 --> 00:04:10,200
By analyzing user behavior,

106
00:04:10,200 --> 00:04:12,930
our UBA tools can identify suspicious activities

107
00:04:12,930 --> 00:04:15,089
that may indicate an insider threat.

108
00:04:15,089 --> 00:04:18,269
A good example of an insider threat may be an employee

109
00:04:18,269 --> 00:04:19,200
who started to access

110
00:04:19,200 --> 00:04:20,940
your organization's sensitive information,

111
00:04:20,940 --> 00:04:22,567
even though, again, they typically do not need

112
00:04:22,567 --> 00:04:24,930
that kind of information to do their job.

113
00:04:24,930 --> 00:04:26,220
With a UBA system,

114
00:04:26,220 --> 00:04:27,822
this activity could be quickly identified

115
00:04:27,822 --> 00:04:31,402
as unusual behavior and our security team will be alerted.

116
00:04:31,402 --> 00:04:34,320
Third, we have improved incident responses.

117
00:04:34,320 --> 00:04:37,125
By providing detailed information about user behavior,

118
00:04:37,125 --> 00:04:40,230
our user behavior analytics tools can help our security team

119
00:04:40,230 --> 00:04:42,480
to respond more effectively to incidents.

120
00:04:42,480 --> 00:04:44,700
For example, if the system is able to detect

121
00:04:44,700 --> 00:04:46,980
that a user's credentials have been compromised,

122
00:04:46,980 --> 00:04:48,638
the security team can quickly take steps

123
00:04:48,638 --> 00:04:49,834
to secure the account,

124
00:04:49,834 --> 00:04:52,452
or the UBA tool may even be able

125
00:04:52,452 --> 00:04:54,958
to log out the user account automatically

126
00:04:54,958 --> 00:04:56,910
and then alert the security team

127
00:04:56,910 --> 00:04:59,409
to investigate the potential compromise.

128
00:04:59,409 --> 00:05:01,830
Another example might be if a user account

129
00:05:01,830 --> 00:05:03,540
suddenly starts performing actions

130
00:05:03,540 --> 00:05:05,100
that it doesn't typically perform.

131
00:05:05,100 --> 00:05:07,350
This could indicate that the account has been compromised.

132
00:05:07,350 --> 00:05:08,970
In this case, the user's account

133
00:05:08,970 --> 00:05:11,160
might typically only read data

134
00:05:11,160 --> 00:05:13,378
but now is suddenly trying to modify or delete data,

135
00:05:13,378 --> 00:05:15,960
in which case your user behavior analytics system

136
00:05:15,960 --> 00:05:17,412
would flag this anomalous behavior

137
00:05:17,412 --> 00:05:20,430
that should be investigated by your security team.

138
00:05:20,430 --> 00:05:23,975
So remember, user behavior analytics is a powerful tool

139
00:05:23,975 --> 00:05:26,160
for detecting potential security threats

140
00:05:26,160 --> 00:05:28,170
by identifying anomalous behavior

141
00:05:28,170 --> 00:05:30,150
that may indicate a threat.

142
00:05:30,150 --> 00:05:34,260
You may hear this technology called UBA or UEBA.

143
00:05:34,260 --> 00:05:36,480
User behavior analytics, or UBA,

144
00:05:36,480 --> 00:05:38,040
is an advanced cybersecurity strategy

145
00:05:38,040 --> 00:05:40,350
that leverages the power of big data and machine learning

146
00:05:40,350 --> 00:05:43,290
to analyze user behaviors and detect anomalies

147
00:05:43,290 --> 00:05:46,048
that may indicate potential security threats.

148
00:05:46,048 --> 00:05:48,993
When we call it UEBA, we are referring to

149
00:05:48,993 --> 00:05:51,540
user and entity behavior analytics,

150
00:05:51,540 --> 00:05:53,820
and we add in the monitoring of entities

151
00:05:53,820 --> 00:05:55,530
to our user behavior analytics.

152
00:05:55,530 --> 00:05:58,560
So, we are not just including our user accounts

153
00:05:58,560 --> 00:06:02,040
but also devices or entities like your routers, servers,

154
00:06:02,040 --> 00:06:03,933
and endpoints in the network as well.

