{"id":13329,"date":"2023-11-28T12:16:24","date_gmt":"2023-11-28T06:16:24","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=13329"},"modified":"2023-12-05T10:57:19","modified_gmt":"2023-12-05T04:57:19","slug":"the-importance-of-log-monitoring-in-anomalous-behavior-analytics","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/the-importance-of-log-monitoring-in-anomalous-behavior-analytics\/","title":{"rendered":"THE IMPORTANCE OF LOG MONITORING IN ANOMALOUS BEHAVIOR ANALYTICS"},"content":{"rendered":"<div class=\"elementor-element elementor-element-b43a3a7 elementor-widget elementor-widget-image\" data-id=\"b43a3a7\" data-element_type=\"widget\" data-settings=\"{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}\" data-widget_type=\"image.default\">\n<div class=\"elementor-widget-container\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-13343 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/11\/vss-1-1.jpeg\" alt=\"\" width=\"947\" height=\"710\" \/><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-45bd6919 elementor-widget elementor-widget-theme-post-content\" data-id=\"45bd6919\" data-element_type=\"widget\" data-settings=\"{&quot;ekit_adv_tooltip_content&quot;:&quot;Tooltip Content.&quot;,&quot;ekit_adv_tooltip_enable&quot;:&quot;yes&quot;,&quot;ekit_we_effect_on&quot;:&quot;none&quot;,&quot;ekit_adv_tooltip_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;ekit_adv_tooltip_position&quot;:&quot;top&quot;,&quot;ekit_adv_tooltip_animation&quot;:&quot;fade&quot;,&quot;ekit_adv_tooltip_arrow&quot;:1,&quot;ekit_adv_tooltip_trigger&quot;:&quot;mouseenter&quot;,&quot;ekit_adv_tooltip_width&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"theme-post-content.default\" aria-describedby=\"tippy-1\">\n<div class=\"elementor-widget-container\">\n<p>&nbsp;<\/p>\n<p><em>Anomalous behavior analytics is one of the many advantages that big data analytics brings to the table. What role does log monitoring have in this process, and how does it work together with behavioral analytics?<\/em><\/p>\n<p>Behavior analytics is a powerful tool in intrusion detection and prevention, using typical user behavior insights to detect suspicious activity. What role does log monitoring have in this process, and how does it work together with behavioral analytics?<\/p>\n<p>&nbsp;<\/p>\n<p><strong>WHAT IS BEHAVIORAL ANALYTICS?<\/strong><\/p>\n<p><a href=\"https:\/\/searchsecurity.techtarget.com\/definition\/user-behavior-analytics-UBA\">User behavior analysis (UBA)<\/a>\u00a0is the cybersecurity process of detecting insider threats, targeted attacks, and financial fraud. \u00a0How does UBA work? It analyzes human behavior based on a large data sample and uses analytics to detect behavior patterns. Any behavior that differs from the pattern signals a potential threat, which the person in charge of IT security should address right away. One of the critical aspects of incident response is the response time. If you don\u2019t react quickly enough, the intruder can steal or damage your data and disrupt your organization\u2019s operations.<\/p>\n<p>Prevention is a more efficient and more affordable option than troubleshooting. This is why it is crucial to invest in a tool that helps utilize the insights gained from anomalous behavior analytics in the fastest and most meaningful way. Log monitoring tools are a great way to speed up and automate incident response either by providing behavioral analytics as one of the features or by easily integrating with another analytics tool.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>HOW CAN LOG MANAGEMENT ENHANCE BEHAVIORAL ANALYTICS? \u00a0<\/strong><\/p>\n<p>Let\u2019s take a step back and talk about big data. With data science on the rise, we keep hearing about machine learning, AI, and big data, but what does it have to do with log management? Big data refers to large data sets \u2013 just like those stored in a large number of log files. It is hard to analyze big data using traditional methods because of its size. This is why a large part of data science is dedicated to\u00a0<a href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S1877050916002568\">big data analysis<\/a>.<\/p>\n<p>The data stored in logs is a potential gold mine of information. If processed correctly, this data can tell you the weak points of your environment so you can improve overall security. It can help you make business decisions and learn more about your customers, and it can also predict how those customers will act in future interactions. But for this to prove successful, you need two things \u2013 quality data and quality analysis. We can safely assume that behavioral analytics is the type of quality analysis we need. But what about the data?<\/p>\n<p>The importance of log management lies in providing quality data. First of all, log management ensures a centralized approach \u2013 collecting logs from different sources into one place. Secondly, for you to analyze data, it needs to come in a uniform format. Initially, this was not the case. For example, router logs look differently than system logs. A log management tool takes care of this with a unified format. In the case of Graylog, logs are stored in\u00a0<a href=\"https:\/\/www.graylog.org\/features\/gelf\">Graylog Extended Log Format (GELF)<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>USING LOG MONITORING AND BEHAVIOR ANALYTICS TO IMPROVE CYBERSECURITY<\/strong><\/p>\n<p>As mentioned before, user behavior analysis determines typical user behavior. Every action that stands out from this pattern signals a potential threat. By detecting a suspicious activity as soon as it happens, log monitoring helps detect threats and attacks before they occur. Most log management software offers several ways to keep you alert \u2013 via mobile phone, desktop notifications, \u00a0or email.<\/p>\n<p>There are five phases of intrusion in every cyber attack: reconnaissance, initial exploitation, establish persistence, move laterally, collect, exfil, and exploit. There are different security strategies for each stage, depending on how far the attacker has penetrated. To learn more about how to use log management software, read our post on\u00a0<a href=\"https:\/\/www.graylog.org\/post\/cyber-security-understanding-the-5-phases-of-intrusion\">Cybersecurity: Understanding the 5 Phases of Intrusion<\/a>.<\/p>\n<p>In case that, despite monitoring, a security breach occurs, early detection provides better damage control. If your IT environment has been rendered non-operational, early detection helps decrease downtime by letting you take action as soon as possible and restore the system. This is especially important if you provide a service where significant downtime may lead to high customer churn. Also, log management shouldn\u2019t be limited to computers. There are more and more cyber attacks on IoT devices because they are very vulnerable to hackers. If your environment has IoT devices, you can read our blog post on\u00a0<a href=\"https:\/\/www.graylog.org\/post\/improving-iot-security-with-log-management\">improving IoT security with log management<\/a>.<\/p>\n<p>Anomalous behavior analytics is one of the many advantages that big data analytics brings to the table. It is growing more reliable and effective with data science development, which is why you should consider getting a quality log monitoring and data analysis tool.<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p>Source:\u00a0<a href=\"https:\/\/graylog.org\/post\/the-importance-of-log-monitoring-in-anomalous-behavior-analytics\/\">https:\/\/graylog.org\/post\/the-importance-of-log-monitoring-in-anomalous-behavior-analytics\/<\/a><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>","protected":false},"excerpt":{"rendered":"<p>Anomalous behavior analytics is one of the many advantages that big data analytics brings to the table. What role does log monitoring have in this process, and how does it work together with behavioral analytics?<\/p>","protected":false},"author":11,"featured_media":13343,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-13329","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13329","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=13329"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13329\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/13343"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=13329"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=13329"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=13329"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}