UEBA: 의심스러운 액세스에 이은 데이터 유출

QRadar® User Entity Behavior Analytics (UEBA) 앱은 특정 동작 이상 항목에 대한 규칙을 기반으로 하는 유스 케이스를 지원합니다.

UEBA: 의심스러운 액세스에 이은 데이터 유출

기본적으로 사용 가능

False

senseVaule 기본값

15

기본값 senseValueSource

15

기본값 senseValueDestination

15

설명

데이터 유출 시도가 수행된 비정상적, 제한된 또는 금지된 위치에서의 액세스를 발견합니다.

지원 룰

  • BB:UBA : Common Event Filters
  • BB:UBA : Data Exfiltration
  • UBA : User Access from Restricted Location
  • UBA : User Access from Prohibited Location
  • UBA : User Geography, Access from Unusual Locations

필수 구성

다음 룰을 사용으로 설정하십시오.
  • UBA : User Access from Restricted Location
  • UBA : User Access from Prohibited Location
  • UBA : User Geography, Access from Unusual Locations

로그 소스 유형

Cisco Stealthwatch(이벤트 ID: 45)

IBM Security Trusteer Apex Advanced Malware Protection (이벤트 ID: ConnectionCreate.Connection_Test, CerberusNG.ent_create_remote_thread, ConnectionCreate.in_suspend_state, ConnectionCreate.orphant_thread_connect, close.file_inspection, processcreate.file_inspection)

Skyhigh Networks Cloud Security Platform(이벤트 ID: 10003, 10004)