Загрузка...

Beyond Static Thresholds: Statistical Analysis for Anomaly Detection in High-Volume Log Sources

Security Operation Centers commonly rely on static thresholds within a detection to indicate anomalous behavior. As these thresholds are generated at a specific point in time, they fail to adapt to fluctuations in log volumes and quickly become stale, resulting in false positive alerts and manual tuning overhead. A rolling average based on standard deviation bounds can be used to generate dynamic thresholds that reduce false positive alerts, though limitations exist regarding sustained low-intensity attacks.

Видео Beyond Static Thresholds: Statistical Analysis for Anomaly Detection in High-Volume Log Sources канала Chris Fulton - NYU
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять