Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Can Next-Gen SIEM Solve UEBA’s Catch-22?
Articles

Can Next-Gen SIEM Solve UEBA’s Catch-22?

ISBuzz TeamBy ISBuzz TeamJanuary 30, 2018Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In corporate cybersecurity, UEBA (user and entity behavior analytics) systems are starting to look more like a stray bullet than a magic bullet.

Glowing endorsements marked the rise of UEBA tools, which analyze users’ actions and network activity to detect cyberthreats. “Over the next three years, leading UEBA platforms will become preferred systems for security operations and investigations at some of the organizations they serve,” Gartner and industry analyst Avivah Litan proclaimed in 2015.

UEBA systems are built on an admittedly strong premise. As they were in 2015, when UEBA took the security world by storm, insider threats continue to be businesses’ top cybersecurity challenge. UEBA’s proponents point to this as evidence that activity monitoring, not perimeter defense, is the way to catch cyber threats. Because every perimeter is eventually breached, they argue, security teams should instead pay attention to the actions of users inside the system.

By early this year, however, Litan had changed her view. Although she noted that the UEBA market has been doubling every year, she couldn’t see it gaining traction. As Litan pointed out, UEBA systems’ best features are being swallowed by their bigger brother, the SIEM (security information and event management) market. Unlike UEBA tools, SIEM systems detect cyberthreats by monitoring the network perimeter for suspicious activity.

But there’s another, more fundamental reason why UEBA never caught on, and it holds important implications for what may fill UEBA systems’ little-worn shoes.

 

Why UEBA Couldn’t Cut It

UEBA faces a catch-22. Such systems must be tuned by those with deep domain expertise. But only large enterprises, which are often disconnected from their own employees’ processes and workflows, can afford to purchase, implement, and maintain UEBA tools.

The result? Poorly configured UEBA systems that flag innocent users as threats. Then, sick of false positives, enterprise security teams stop using UEBA. Unfortunately, I’ve heard this story from multiple UEBA practitioners.

False positives happen because legitimate users sometimes take odd but harmless actions. Modeling capricious behavior is a fundamental IT problem. How does a non-human differentiate between the user who deleted 50 documents because the files are truly unneeded and the user who deleted them because he’s being malicious?

To their credit, UEBA vendors saw this problem coming. Their first line of attack was machine learning, but it wasn’t enough. They responded by increasing context, information about users, and accessed systems. This helped, but it was too laborious to be practical, and employees took issue with UEBA systems scooping up their social media data.

False positives aren’t just wrong; they’re expensive. Vetting suspicious activity takes time and diverts resources from actual problems. It doesn’t take many false alarms for an enterprise to look elsewhere for cybersecurity software.

If UEBA Isn’t the Answer, What Is?

As Litan predicted, SIEM vendors are already poaching UEBA’s strengths for an emerging class of systems, currently called “next-gen SIEM.” These tools don’t fit neatly into either the UEBA or SIEM categories, instead marrying each group’s best ideas and strong threat detection tools into a new, more powerful package.

Built by startups like empow and SS8 and established vendors such as Rapid7, RSA, and Symantec, next-gen SIEM systems take an “all above the above” approach to addressing UEBA’s problems.

To reduce training time, next-gen SIEM tools are preprogrammed with activity patterns captured over the past decade. In addition, they use supervised machine learning to establish a baseline of user activity for the given organization. To be fair, UEBA tools use machine learning to establish baseline activity, too, but those that I’ve seen are simplistic in their approach.

To contextually separate merely unusual from malicious activity, next-gen SIEM tools add proprietary data feeds on top of the perimeter, system, and log data of SIEM systems. Next-gen systems further reduce false negatives by using deep learning to refine their frameworks for differentiating between odd and aberrant activity. And because deep learning models learn without human input of parameters, they’re an ideal way to reduce personnel costs.

Of course, all this sounds great on paper. But because next-gen SIEM tools are so new, their approach is frankly faith-based. It remains to be seen whether they’ll have enough context and sufficiently powerful learning models to cut training time and false positives without producing false negatives.

Although UEBA hasn’t lived up to its hype, it has indisputably driven cybersecurity innovation. Next-gen SIEM systems, meanwhile, have yet to prove themselves, but they’re a promising answer to what has so far proved an intractable problem.

Next-gen SIEM may prove more successful than UEBA, but the truth is that it isn’t a magic bullet for cybersecurity, either. Every system — SIEM, UEBA, or otherwise — is built for today’s use cases, and it inevitably falls short when applied to tomorrow’s.

Still, UEBA isn’t working, and doing nothing is not an option. Next-gen SIEM represents just one route to a more secure environment; every enterprise must find its own. In cybersecurity, the only wrong answer is to not try at all.

[su_box title=”About Aziz Gilani” style=”noise” box_color=”#336588″][short_info id=’104285′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}