UEBA: 의심스러운 액세스에 이은 데이터 유출
QRadar® User Entity Behavior Analytics (UEBA) 앱은 특정 동작 이상 항목에 대한 규칙을 기반으로 하는 유스 케이스를 지원합니다.
UEBA: 의심스러운 액세스에 이은 데이터 유출
기본적으로 사용 가능
False
senseVaule 기본값
15
기본값 senseValueSource
15
기본값 senseValueDestination
15
설명
데이터 유출 시도가 수행된 비정상적, 제한된 또는 금지된 위치에서의 액세스를 발견합니다.
지원 룰
- BB:UBA : Common Event Filters
- BB:UBA : Data Exfiltration
- UBA : User Access from Restricted Location
- UBA : User Access from Prohibited Location
- UBA : User Geography, Access from Unusual Locations
필수 구성
다음 룰을 사용으로 설정하십시오.
- UBA : User Access from Restricted Location
- UBA : User Access from Prohibited Location
- UBA : User Geography, Access from Unusual Locations
로그 소스 유형
Cisco Stealthwatch(이벤트 ID: 45)
IBM Security Trusteer Apex Advanced Malware Protection (이벤트 ID: ConnectionCreate.Connection_Test, CerberusNG.ent_create_remote_thread, ConnectionCreate.in_suspend_state, ConnectionCreate.orphant_thread_connect, close.file_inspection, processcreate.file_inspection)
Skyhigh Networks Cloud Security Platform(이벤트 ID: 10003, 10004)