For VendorsBlog

UEBA - User and Entity Behavior Analytics

UEBA - User and Entity Behavior Analytics

Developments in UBA technology led Gartner to evolve the category to user and entity behavior analytics (UEBA). In September 2015, Gartner published the Market Guide for User and Entity Analytics by Vice President and Distinguished Analyst, Avivah Litan, that provided a thorough definition and explanation. UEBA was referred to in earlier Gartner reports but not in much depth. Expanding the definition from UBA includes devices, applications, servers, data, or anything with an IP address. It moves beyond the fraud-oriented UBA focus to a broader one encompassing "malicious and abusive behavior that otherwise went unnoticed by existing security monitoring systems, such as SIEM and DLP." The addition of "entity" reflects that devices may play a role in a network attack and may also be valuable in uncovering attack activity. "When end users have been compromised, malware can lay dormant and go undetected for months. Rather than trying to find where the outsider entered, UEBAs allow for quicker detection by using algorithms to detect insider threats."

Particularly in the computer security market, there are many vendors for UEBA applications. They can be "differentiated by whether they are designed to monitor on-premises or cloud-based software as a service (SaaS) applications; the methods in which they obtain the source data; the type of analytics they use (i.e., packaged analytics, user-driven or vendor-written), and the service delivery method (i.e., on-premises or a cloud-based)." According to the 2015 market guide released by Gartner, "the UEBA market grew substantially in 2015; UEBA vendors grew their customer base, market consolidation began, and Gartner client interest in UEBA and security analytics increased." The report further projected, "Over the next three years, leading UEBA platforms will become preferred systems for security operations and investigations at some of the organizations they serve. It will be—and in some cases already is—much easier to discover some security events and analyze individual offenders in UEBA than it is in many legacy security monitoring systems."

The most popular products in category UEBA - User and Entity Behavior Analytics All category products

Rapid7 insightIDR
7
14
IBM QRradar UBA
IBM
6
5
Palo Alto Networks LightCyber
1
7
Microsoft Advanced Threat Analytics
1
20
Forcepoint User and Entity Behavior Analytics (UEBA)
4
12
Forcepoint SureView Analytics
10
8
Amazon Pinpoint
5
5
Rhebo Industrial Protector
18
16
Dragos Industrial Cybersecurity Platform
5
0
Securonix Enterprise
2
3
Fortscale UEBA
17
2
DNIF User Behavior Analytics
2
8

Compare of products in the category UEBA - User and Entity Behavior Analytics

Please turn the screen for optimal content display

Compare: UEBA - User and Entity Behavior Analytics

Characteristics

Hadoop

Clouds

On-premises software

Advanced Analytics

Incident Response

Machine Learning

Deep Learning

Visibility into users via reports and dashboards

Near real-time alerts

Forensic Tools

Customizable notification

Role based reports

Threat Intelligence reports

Licensing model all based on identity

Technologies integration

Log collection from SaaS apps

Logs and User context data from Active directory

Logs from endpoint security solutions

Network flow/Packet data

Unstructured contextual data

Log collection from OS, apps, services

Meta data from electronic communications

Statistical models

Modelling based rules and signatures

Catching users with anomaly behavior on start by baselining model

System adaptation to user's dynamic role changes

  • N/A
  • N/A
  • N/A
  • N/A
  • Yes
  • N/A
  • Yes
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • Yes
  • Yes
  • N/A
  • Yes
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • N/A
  • Only HP UEBA
  • Yes
  • N/A
  • N/A
  • Yes
  • N/A
  • SIEM
  • IAM
  • DLP
  • SIEM
  • IAM
  • DLP
  • N/A
  • N/A
  • SIEM
  • N/A
  • N/A
  • IAM
  • DLP
  • SIEM
  • SIEM
  • DLP
  • SIEM
  • IAM
  • SIEM
  • SIEM
  • SIEM
  • IAM
  • SIEM
  • IAM
  • DLP
  • N/A
  • SIEM
  • IAM
  • DLP
  • SIEM
Found mistake? Write us.

Suppliers UEBA - User and Entity Behavior Analytics

Amazon Web Services
ARE...
  • ARE
  • AUS
  • BHR
  • BRA
  • CAN
  • CHE
  • CHN
  • DEU
  • ESP
  • FRA
  • GBR
  • IDN
  • IRL
  • ISR
  • IND
  • ITA
  • JPN
  • KOR
  • NZL
  • SWE
  • SGP
  • THA
  • USA
Rapid7
ARM...
  • ARM
  • AZE
  • GEO
  • KGZ
  • KAZ
  • MDA
  • TJK
  • TKM
  • UKR
  • UZB
Softprom (supplier)
ARM...
  • ARM
  • AUT
  • GEO
  • KAZ
  • MDA
  • UKR
ANYSOFT
UKR...
  • UKR
  • USA
Claroty
AUS...
  • AUS
  • DEU
  • GBR
  • ISR
  • KOR
  • SGP
  • USA
Nozomi Networks
ARE...
  • ARE
  • AUS
  • BRA
  • CAN
  • CHE
  • DEU
  • DNK
  • ESP
  • GBR
  • ITA
  • NLD
  • PRT
  • SGP
  • USA
CUJO
AUS...
  • AUS
  • BRA
  • CHN
  • FIN
  • GBR
  • HUN
  • LTU
  • MYS
  • PHL
  • USA
Eurotech
FRA...
  • FRA
  • GBR
  • ITA
  • JPN
  • USA
Netskope
AUS...
  • AUS
  • GBR
  • IND
  • NLD
  • SGP
  • USA
Cofense
ARE...
  • ARE
  • AUS
  • GBR
  • IRL
  • ISR
  • IND
  • PHL
  • USA
BioCatch
AUS...
  • AUS
  • BRA
  • GBR
  • ISR
  • IND
  • MEX
  • SGP
  • USA
Cleafy
BRA...
  • BRA
  • DEU
  • ESP
  • ITA
  • NLD
  • SVN
  • USA