Umbra Wiki defense defense/D3-UBA
Back to wiki

D3-UBA — User Behavior Analysis

provenance: imported

D3-UBA: User Behavior Analysis

MITRE D3FEND countermeasure

What it does

User behavior analytics ("UBA") as defined by Gartner, is a cybersecurity process about detection of insider threats, targeted attacks, and financial fraud. UBA solutions look at patterns of human behavior, and then apply algorithms and statistical analysis to detect meaningful anomalies from those patterns-anomalies that indicate potential threats.' Instead of tracking devices or security events, UBA tracks a system's users. Big data platforms are increasing UBA functionality by allowing them to analyze petabytes worth of data to detect insider threats and advanced persistent threats.

Attacks this counters

No ATT&CK technique in this corpus maps to this countermeasure. D3FEND may map it to techniques outside the Enterprise matrix, or to ones MITRE has since revoked — absence here is about this corpus, not about the countermeasure.

Source