Ranking security-log anomalies for the analyst queue

Learns what ordinary behaviour looks like for each account, host and service from the organisation's own logs, then surfaces the windows that depart from it — an account authenticating from a new country at an unusual hour, a host suddenly talking to hundreds of internal addresses — each presented with the baseline it broke and the published technique it resembles.

Effort
More than a few weeks
Skill level
Engineering skill required
Organisation size
Enterprise
Value
Risk reduced, Time saved

Tools named for this

  • A log pipeline that retains raw events, not only pre-aggregated counts
  • A baseline fitted per entity rather than one global threshold across the estate
  • A mapping from each alert to a published adversary technique, so the queue can be discussed in shared terms

What to check before you ship it in India

  • The direction of 28 April 2022 requires service providers, intermediaries, data centres, body corporate and Government organisations to enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days, within the Indian jurisdiction. A detection stack that ships events to an overseas platform and keeps ninety days of them fails on both limbs at once.
  • Authentication and proxy logs are a minute-by-minute record of identified employees. Section 8(5) requires reasonable security safeguards over personal data in the fiduciary's control, and a detection store every engineer can query for troubleshooting is where that obligation is quietly lost.

Sources

Every claim on this page traces to one of these, on the date it was read.