Frequently Asked Questions
UEBA Anomaly Detection
How is UEBA different from SIEM?
- While SIEM analyzes and collects device-centric logs, UEBA learns the behavioral patterns of users and entities (PCs, servers, accounts) using AI to
detect insider threats. It is specialized in detecting internal data breaches and account takeovers, which are much harder to catch than external hacking attempts.
What types of anomalous behaviors can be detected?
A. Types of detectable behaviors
- Access during abnormal hours / Access from abnormal countries
- Mass file downloads / Bulk email sending
- Unauthorized system access / Suspected account sharing
- Unauthorized data exfiltration by departing employees
- Internal movement of infected accounts (Lateral Movement)
Should it be implemented with SIEM, or is standalone deployment possible?
- Standalone deployment of UEBA is possible, but integration with SIEM allows for even more powerful detection.
UEBA utilizes the various logs collected by SIEM for behavior analysis, enabling more precise risk profiling.
API integration is also possible in existing third-party SIEM environments.
Aren't there many false positives?
- SecureLayer UEBA continuously reduces false positives with its AI-based Continual Learning feature.
Even a single piece of feedback data is immediately reflected in the learning process, and the actual false positive rate of eyeCloudAI has decreased from 94.8% to 5.2%.
Technical support for optimization is also provided during the initial operation period.
Are there any compliance issues related to personal data collection?
- When operating UEBA, compliance with relevant laws such as the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection is necessary.
SecureLayer provides guidelines for compliance, including employee consent procedures, data minimization principles, and access rights management.
We recommend implementing this alongside legal/internal regulation reviews.