Ranking security-log anomalies for the analyst queue
Learns what ordinary behaviour looks like for each account, host and service from the organisation's own logs, then surfaces the windows that depart from it — an account authenticating from a new country at an unusual hour, a host suddenly talking to hundreds of internal addresses — each presented with the baseline it broke and the published technique it resembles.
- Effort
- More than a few weeks
- Skill level
- Engineering skill required
- Organisation size
- Enterprise
- Value
- Risk reduced, Time saved
Tools named for this
- A log pipeline that retains raw events, not only pre-aggregated counts
- A baseline fitted per entity rather than one global threshold across the estate
- A mapping from each alert to a published adversary technique, so the queue can be discussed in shared terms
What to check before you ship it in India
- The direction of 28 April 2022 requires service providers, intermediaries, data centres, body corporate and Government organisations to enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days, within the Indian jurisdiction. A detection stack that ships events to an overseas platform and keeps ninety days of them fails on both limbs at once.
- Authentication and proxy logs are a minute-by-minute record of identified employees. Section 8(5) requires reasonable security safeguards over personal data in the fiduciary's control, and a detection store every engineer can query for troubleshooting is where that obligation is quietly lost.
Sources
Every claim on this page traces to one of these, on the date it was read.
- Outside the Closed World: On Using Machine Learning For Network Intrusion Detection · Sommer and Paxson, ICSI / Lawrence Berkeley National Laboratory / UC Berkeley, IEEE Symposium on Security and Privacy 2010 · how it is done · read 2026-09-01
- MITRE ATT&CK knowledge base · The MITRE Corporation · that this is done · read 2026-09-01
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) — most obligations commence 13 May 2027 under the DPDP Rules 2025 — s.8(5) · Ministry of Electronics and Information Technology · a rule · read 2026-09-01
- CERT-In Directions No. 20(3)/2022-CERT-In under sub-section (6) of section 70B of the Information Technology Act, 2000, dated 28 April 2022 — direction (iv) · Indian Computer Emergency Response Team (CERT-In), Ministry of Electronics and Information Technology · a rule · read 2026-09-01