사용자 정의 모델 작성

사용자 정의 모델을 작성하여 시간당 개인에 대한 숫자 기능을 측정하고 기준선을 설정할 수 있습니다.

시작하기 전에

각 모델 템플리트에 대한 다음 모델 세부사항을 검토하십시오.

이 태스크에 대한 정보

학습된 동작 및 사용자에 대한 실제 데이터를 검토할 수 있도록 사용자 정의 모델을 작성할 수 있습니다. 기준선 동작에서 중요한 변경사항이 발견되면 사용자의 위험성 점수가 높아진다는 경보를 받게 됩니다. 작성할 수 있는 모델의 예제에는 사용자가 다운로드하는 데이터의 양, 사용자가 실행하는 애플리케이션의 수 또는 사용자가 시간당 전송하는 이메일 수 표시 등이 포함될 수 있습니다.

주의: 설정을 구성하거나 수정한 후 데이터를 수집하고 초기 모델을 빌드하며 사용자에 대한 초기 결과를 보는 데 최소 1시간이 소요됩니다.

활성 사용자는 지속적으로 모니터링됩니다. 사용자가 28일 동안 활동이 없는 경우 사용자 및 사용자의 데이터는 모델에서 제거됩니다. 사용자가 다시 활성 상태가 되면 새 사용자로 리턴됩니다.

프로시저

  1. 탐색 메뉴 ( 탐색 메뉴 아이콘 ) 에서 관리를 클릭하십시오.
  2. > 사용자 엔터티 분석 > Machine Learning 설정을 클릭합니다.
  3. Machine Learning 설정 페이지에서 모델 작성을 클릭하십시오.
  4. 모델 정의 탭에서 템플리트를 선택하여 AQL 필드를 채우거나 사용자 정의 AQL 조회를 작성할 수 있습니다.
  5. 다음을 클릭하십시오.
    사용자 정의 모델 설정 화면
  6. 일반 설정 탭에서 이름 및 설명을 입력하십시오.
  7. 감지 이벤트의 위험 값 필드에 감지 이벤트가 트리거될 때 사용자의 위험 점수를 증가시킬 양을 입력하십시오. 기본값은 5입니다.
  8. 위험 값의 크기를 조정하려면 전환을 사용으로 설정하십시오. 사용으로 설정되면 기본 위험 값에 인수(1 - 10 범위)가 곱해집니다. 이 인수는 단순히 사용자가 예상 작동에서 벗어난 사실이 아니라 사용자가 예상 작동에서 벗어난 정도에 의해 판별됩니다.
  9. 이상 항목을 트리거하기 위한 신뢰구간 필드에 이상 항목 이벤트를 트리거하기 전에 기계 학습 알고리즘의 신뢰도에 대한 백분율을 입력하십시오. 기본값은 0.95입니다.
  10. 데이터 보존 기간 필드에서 모델 데이터를 저장할 일 수를 설정하십시오. 기본값은 30입니다.
  11. 사용자 세부사항 페이지에 그래프 표시 전환은 기본적으로 사용 안함으로 설정되어 있습니다. 사용자 세부사항 페이지에 사용자 정의 모델 그래프를 표시하려는 경우 전환을 클릭하십시오.
  12. 선택사항: AQL 검색 필터 필드에서 AQL 필터를 추가하여 분석이 QRadar에서 조회하는 데이터의 범위를 좁힐 수 있습니다. AQL 조회를 사용하여 필터링하면 분석 대상인 사용자 수나 분석 유형을 줄일 수 있습니다. 구성을 저장하기 전에 조회를 검토하고 결과를 확인할 수 있도록 조회 유효성 검증을 클릭하여 QRadar에서 전체 AQL 조회를 실행하십시오.
    중요: AQL 필터를 수정하는 경우 기존 모델은 올바르지 않은 것으로 표시된 후 다시 빌드됩니다. 다시 빌드하는 데 걸리는 시간은 수정된 필터에 의해 리턴되는 데이터 양에 따라 다릅니다.
    특정 로그 소스, 네트워크 이름 또는 특정 사용자가 포함된 참조 세트를 필터링할 수 있습니다. 다음 예제를 참조하십시오.
    • REFERENCESETCONTAINS('Important People', username)
    • LOGSOURCETYPENAME(devicetype) in ('Linux OS', 'Blue Coat SG Appliance', 'Microsoft Windows Security Event Log')
    • INCIDR('172.16.0.0/12', sourceip) or INCIDR('10.0.0.0/8', sourceip) or INCIDR('192.168.0.0/16', sourceip)
    자세한 정보는 Ariel Query Language를 참조하십시오.
  13. 저장을 클릭하십시오.
    모델 작성을 위한 일반 설정 탭

애플리케이션 이벤트

프로시저

  • 이벤트 이름: UBA : Custom Analytic Anomaly
  • senseValue = 5
  • 필수 구성: 시스템은 애플리케이션의 QRadar 상위 레벨 카테고리가 있는 이벤트를 모니터합니다.
  • 로그 소스 유형: APC UPS, Apache HTTP Server, Application Security DbProtect, Array Networks SSL VPN Access Gateways, Aruba ClearPass Policy Manager, Aruba Mobility Controller, Avaya VPN Gateway, Barracuda Web Application Firewall, Barracuda Web Filter, Blue Coat Web Security Service, BlueCat Networks Adonis, CRE System, Centrify Infrastructure Services, Check Point, Cilasoft QJRN/400, Cisco Call Manager, Cisco CatOS for Catalyst Switches, Cisco FireSIGHT Management Center, Cisco IOS, Cisco Identity Services Engine, Cisco Intrusion Prevention System (IPS), Cisco IronPort, Cisco Meraki, Cisco Nexus, Cisco PIX Firewall, Cisco Stealthwatch, Cisco Umbrella, Cisco Wireless Services Module (WiSM), Citrix Access Gateway, Citrix NetScaler, Custom Rule Engine, Cyber-Ark Vault, DG Technology MEAS, EMC VMWare, Event CRE Injected, Extreme Matrix K/N/S Series Switch, Extreme Stackable and Standalone Switches, F5 Networks BIG-IP AFM, F5 Networks BIG-IP ASM, F5 Networks BIG-IP LTM, Fidelis XPS, FireEye, Flow Classification Engine, Flow Device Type, Forcepoint Sidewinder, Forcepoint V Series, Fortinet FortiGate Security Gateway, FreeRADIUS, H3C Comware Platform, Huawei S Series Switch, HyTrust CloudControl, IBM AIX Audit, IBM AIX Server, IBM DB2, IBM DataPower, IBM Lotus Domino, IBM Proventia Network Intrusion Prevention System (IPS), IBM Resource Access Control Facility (RACF), IBM Security Directory Server, IBM Tivoli Access Manager for e-business, IBM i, IBM z/OS, ISC BIND, Imperva SecureSphere, Infoblox NIOS, Juniper Junos OS Platform, Juniper MX Series Ethernet Services Router, Juniper Networks AVT, Juniper Networks Firewall and VPN, Juniper Networks Intrusion Detection and Prevention (IDP), Juniper WirelessLAN, Kisco Information Systems SafeNet/i, Linux DHCP Server, McAfee Network Security Platform, McAfee Web Gateway, Metainfo MetaIP, Microsoft DHCP Server, Microsoft DNS Debug, Microsoft Exchange Server, Microsoft IIS, Microsoft Office 365, Microsoft Operations Manager, Microsoft Windows Security Event Log, Motorola SymbolAP, NGINX HTTP Server, Nortel Contivity VPN Switch, Nortel VPN Gateway, OS Services Qidmap, OSSEC, ObserveIT, Okta, Open LDAP Software, OpenBSD OS, Oracle BEA WebLogic, Oracle Database Listener, PostFix MailTransferAgent, ProFTPD Server, Proofpoint Enterprise Protection/Enterprise Privacy, Pulse Secure Pulse Connect Secure, RSA Authentication Manager, Radware DefensePro, SSH CryptoAuditor, Skyhigh Networks Cloud Security Platform, Solaris Operating System Authentication Messages, Solaris Operating System DHCP Logs, SonicWALL SonicOS, Sophos Astaro Security Gateway, Sophos Web Security Appliance, Squid Web Proxy, Starent Networks Home Agent (HA), Stonesoft Management Center, Sun ONE LDAP, Symantec Critical System Protection, Symantec Encryption Management Server, Symantec Endpoint Protection, TippingPoint Intrusion Prevention System (IPS), Top Layer IPS, Trend InterScan VirusWall, Trend Micro Deep Security, Universal DSM, Venustech Venusense Security Platform, Verdasys Digital Guardian, WatchGuard Fireware OS, genua genugate, iT-CUBE agileSI

SourceIP

프로시저

  • 이벤트 이름: UBA : Custom Analytic Anomaly
  • sensevalue: 5
  • 로그 소스 유형: 이벤트의 소스 IP 및 사용자 이름을 포함하는 로그 소스

대상 포트

프로시저

  • 이벤트 이름: UBA : Custom Analytic Anomaly
  • sensevalue: 5
  • 로그 소스 유형: 이벤트의 대상 포트 및 사용자 이름을 포함하는 로그 소스

Office 파일 액세스

프로시저

  • 이벤트 이름: UBA : Custom Analytic Anomaly
  • sensevalue: 5
  • 필수 구성: 시스템은 QRadar 이벤트 이름에 단어 "file"이 포함된 이벤트를 모니터합니다.
  • 로그 소스 유형: Microsoft Office 365

AWS 액세스

프로시저

  • 이벤트 이름: UBA : Custom Analytic Anomaly
  • sensevalue: 5
  • 필수 구성: 시스템은 QRadar 이벤트 이름에 단어 "bucket"이 포함된 이벤트를 모니터합니다.
  • 로그 소스 유형: Amazon AWS Cloudtrail

프로세스

프로시저

  • 이벤트 이름: UBA : Custom Analytic Anomaly
  • sensevalue: 5
  • 필수 구성: 사용자 정의 이벤트 특성 'Process'가 원하는 로그 소스 유형에 있어야 합니다.
  • 로그 소스 유형: Microsoft Windows Security Event Log; Linux OS

웹 사이트

프로시저

  • 이벤트 이름: UBA : Custom Analytic Anomaly
  • sensevalue: 5
  • 지원 룰: 'UBA : Browsed to Entertainment Website', 'UBA : Browsed to LifeStyle Website', 'UBA : Browsed to Business/Service Website', 'UBA : Browsed to Communications Website'
  • 필수 구성: 사용자 정의 이벤트 특성 'Web Category'가 원하는 로그 소스 유형에 있어야 합니다.
  • 로그 소스 유형: Blue Coat SG Appliance, Cisco IronPort, McAfee Web Gateway, Check Point, Squid Web Proxy, Palo Alto PA Series; Forcepoint V Series, Fortinet FortiGate Security Gateway

위험 IP

프로시저

  • 이벤트 이름: UBA : Custom Analytic Anomaly
  • sensevalue: 5
  • 필수 구성: 관리 설정 > 시스템 설정에서 " X-Force Threat Intelligence 피드 사용" 을 예로 설정하십시오.
  • 로그 소스 유형: 사용자 이름이 있는 이벤트의 로그 소스.