The benefits of machine learning and UEBA

1 May 2019 Information Security

The cost of cybercrime is rapidly outpacing our ability to keep up. While Gartner predicts worldwide spending on information security to reach $124 billion this year, security researchers also estimate that the cost of cybercrime will exceed $2 trillion in that same time, outpacing security spending by over 16 times.

Doros Hadjizenonos
Doros Hadjizenonos

The vast majority of malware simply targets known vulnerabilities, while botnets now remain undetected inside targeted organisations for an average of nearly 12 days. The problem in many cases is one of resources. The rapid expansion of the attack surface through digital transformation and the unprecedented adoption of BYOD and IoT devices, combined with the growing sophistication of attacks and widening security skills gap has overwhelmed many security teams.

To address this challenge, organisations are turning to things like machine learning (ML) to fill their security gaps. The question is whether machine learning can add new value to the realm of cybersecurity?

Detection and prevention

Most organisations are currently operating with the standard cybersecurity kit. Their wiring closets are filled with devices that tout security policies that vendors claim can detect and prevent the latest threats by way of signature-based detection, canned policies, or even user-defined configurations. Sensors in this category – and experts estimate that organisations may have solutions from as many as 70 different security vendors inside their network – include firewalls, data loss prevention (DLP) systems, intrusion prevention systems (IPS) and web content filters (WCF).

In addition, many of these devices operate in complete isolation, unable to share or correlate threat intelligence or respond to threats in any sort of cohesive or coordinated strategy. As a result, even monitoring these appliances requires an extra layer of sensors – along with additional security team members to manage them and hand-correlate their syslog events.

Machine learning - what it is

Machine learning (ML) is a subset of AI. AI and ML can augment our human capabilities by allowing us to carve through large datasets and spot patterns of behaviour, or signals in the noise, that would be all but impossible for humans to do. This provides a force multiple, enabling your existing human talent to spot unusual behaviour automated behavioural analytics, or UEBA (user entity behaviour analytics) tools. Mundane tasks can also be automated with ML, allowing scarce cybersecurity personnel resources to focus on higher value tasks.

UEBA: providing the big picture

ML and AI are based on big data, and their efficiency and accuracy gets better the more data you throw at them. What’s important, however, is that you are collecting the right data. That’s where UEBA systems come in. Combining accurate and essential user behavioural data with machine learning allows you to more accurately monitor your users on an endpoint-by-endpoint basis, providing you with deep visibility into what they get up to on a regular basis.

Once a baseline of normal behaviour is established, any time a user does something that the UEBA system considers outside of normal, the cybersecurity ops team is alerted. If a user’s legitimate activity is flagged as anomalous, which can happen frequently during the initial learning stages, your analysts can simply tag the activity as routine and the UEBA system’s machine learning integrates that data and goes back to business as usual. As machine learning reduces such false positives, any time a user strays from normal behaviour those notifications become more urgent.

The benefits of combining ML and UEBA

Using machine learning alongside user behaviour data provides a level of security proactivity that is not possible when relying on traditional signature-based prevention and detection systems. This is due to the fact that you’re able to detect subtle changes in behaviour that’s tough to do with signatures. It’s simply not possible to configure a system with every single rule permutation to detect all attacks.

Detecting low-level reconnaissance activity using UEBA and machine learning is far more likely to set off your Spidey-senses than combining machine learning with traditional signature-based detection measures. This provides a huge advantage, making it a lot harder for attackers to circumvent control by flying under any rules-based radar.

The benefits to using a UEBA security solution built on a machine learning platform are many. As their ability to baseline network activity is refined, they can not only detect anomalous changes in behaviour, but that information can also enable proactivity by identifying and preventing certain behaviours before the occur. And since machine learning solutions generally provide their own care and feeding, minus a few tweaks here and there, overhead to manage them is reduced to a minimum.

But perhaps most importantly, machine learning is coming on the scene at a very opportune time because the number of analysts required to sift through data by hand to identify threats is rapidly outpacing the number of professionals currently available. By removing the human from a task that they’re not especially suited to, they are free to focus on those areas where they can add value, such as further developing your cybersecurity practice.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Prompt injection is the new phishing
Information Security Security Services & Risk Management
AI security is heading in an uncomfortable direction following Microsoft’s research showing how prompt injection can be chained to remote code execution vulnerabilities in AI agent frameworks, including work involving Semantic Kernel

Read more...
Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.