Turkish Journal of Computer and Mathematics Education
Journal license

Journal

Turkish Journal of Computer and Mathematics Education


Volume
& Issue

Volume 15, Issue 1


Published
on


Pages

44-50


DOI

Article

Unveiling Hidden Threats with ML-Powered User and Entity Behavior Analytics (UEBA)


Authors

Avinash Gupta Desetty* Affiliation:
Splunk Engineer, New York Metropolitan Transportation Authority, New York, USA


Abstract

The ever-growing cost of cybercrime has created the need for proactive solutions for organizations seeking to protect their digital assets. While traditional security systems struggle to detect anomalies buried within vast datasets, new solutions like User and Entity Behavior Analytics (UEBA) emerge as a game-changer. By leveraging the power of machine learning, UEBA analyzes diverse data sources like user logins, file accesses, event logs, business context, external threat intelligence, and network activity, to unveil hidden threats most traditional methods could miss. The ability to analyze multiple data sources enables UEBA solutions to effectively detect malicious insiders, compromised users, Advanced Persistent Threats (APTs), and zero-day attacks. By using various analytics techniques like supervised learning, unsupervised learning, and statistical modeling, UEBA solutions can detect subtle anomalies that deviate from established behavior baselines. Despite the many benefits, UEBA solutions still have limitations like data quality concerns, high implementation costs, and the need for model maintenance. Integration with System Information and Event Management (SIEM) systems helps mitigate some of these challenges to further enhance UEBA's capabilities and provide a unified platform for threat identification and response. This paper provides a detailed insight into the capabilities of UEBA, its three pillars, significance, and limitations.


Keywords

User and Entity Behavior Analytics (UEBA), Cybersecurity, Machine Learning, Threat Detection, Anomaly Detection, and Data Analytics


Citation

Desetty, A. G. (2024). Unveiling hidden threats with ml-powered user and entity behavior analytics (UEBA). Turkish Journal of Computer and Mathematics Education, 15(1), 44–50.

Published by: Engineering Journals

Engineering Journals Logo