OpenText brings decades of expertise to help you unlock data, connect people and processes, and fuel AI with trust
Unify data seamlessly across your enterprise to eliminate silos, improve collaboration, and reduce risks
Get AI-ready and transform your data into structured, accessible, optimized information
Meet regulatory and compliance requirements and protect your information throughout its lifecycle
OpenText helps people manage content, automate work, use AI, and collaborate to boost productivity
See how thousands of companies around the world are succeeding with innovative solutions from OpenText™
Our people are our greatest asset; they are the life of the OpenText brand and values
Learn how we aspire to advance societal goals and accelerate positive change
Find a highly skilled OpenText partner with the right solution to enable digital transformation
Explore scalable and flexible deployment options for global organizations of any size
Local control. Global scale. Trusted AI
Your cloud, your control
Free up resources, optimize performance and rapidly address issues
Run anywhere and scale globally in the public cloud of your choice
See information in new ways
AI that understands your business, your data, and your goals
Say hello to faster decisions. Your secure personal AI assistant is ready to get to work
Gain better insights with generative AI for supply chains
Power work with AI content management and an intelligent AI content assistant
Improve your security posture with AI cybersecurity and agile threat detection
Enable faster app delivery, development, and automated software testing
Elevate customer communications and experiences for customer success
Empower users, service agents, and IT staff to find the answers they need
See information in new ways
AI that understands your business, your data, and your goals
Say hello to faster decisions. Your secure personal AI assistant is ready to get to work
Gain better insights with generative AI for supply chains
Power work with AI content management and an intelligent AI content assistant
Improve your security posture with AI cybersecurity and agile threat detection
Enable faster app delivery, development, and automated software testing
Elevate customer communications and experiences for customer success
Empower users, service agents, and IT staff to find the answers they need
Predict, act, and win with real-time analytics on a smarter data platform
Give users access to the answers they need, faster and easier, with multi-repository AI-based search that lets you contextualize everything from clicks to conversations
Connect once, reach anything with a secure B2B integration platform
Reimagine knowledge with AI-ready content management solutions
Supercharge intelligent workspaces with AI to modernize work
Integrated cybersecurity solutions for enterprise protection
Purpose built data protection and security solutions
Reinvent threat hunting to improve security posture with the power of agile AI
Ship better software—faster—with AI-driven DevOps automation, testing, and quality
Reimagine conversations with unforgettable customer experiences
Get the clarity needed to cut the cost and complexity of IT operations
Redefine Tier 1 business support functions with self-service capabilities from private generative AI
Build custom applications using proven OpenText Information Management technology
Build it your way with OpenText Cloud APIs that create the real-time information flows that enable custom applications and workflows
Protect what matters, recover when it counts
Get greater visibility and sharper insights from AI-driven information management. Ready to see how?
Break free from silos, streamline processes, and improve customer experiences with secure information management for AI
Improve efficiency, security, and customer satisfaction with OpenText
Run processes faster and with less risk
Achieve digital transformation with guidance from certified experts
Modernize your information management with certified experts
Unlock the full potential of your information management solution
Turn support into your strategic advantage
Extend IT teams with certified OpenText application experts
Discover training options to help users of all skill levels effectively adopt and use OpenText products
Modernize your information management with certified experts
Unlock the full potential of your information management solution
Turn support into your strategic advantage
Extend IT teams with certified OpenText application experts
Discover training options to help users of all skill levels effectively adopt and use OpenText products
Information is the heartbeat of every organization. We build information management software so you can build the future
OpenText partners with leading cloud infrastructure providers to offer the flexibility to run OpenText solutions anywhere
OpenText partners with top enterprise app providers to unlock unstructured content for better business insights
Discover flexible and innovative offerings designed to add value to OpenText solutions
Discover the resources available to support and grow Partner capabilities
Get expert product and service support to accelerate issue resolution and keep business flows running efficiently
Explore detailed services and consulting presentations, briefs, documentation and other resources
User and Entity Behavior Analytics (UEBA) is a type of cyber security solution that uses machine learning (ML), deep learning, and statistical analysis to identify the normal behavior patterns of users and entities (e.g., hosts, applications, network traffic, and data repositories) on corporate networks or computer systems. When anomalies or deviations from those behavior patterns are detected and a risk score passes a designated threshold, a UEBA solution alerts security operations center (SOC) teams on whether a potential threat or cyber-attack is in progress.
UEBA is an essential tool in a modern organization’s cyber security stack, especially as many legacy tools are quickly becoming obsolete. As cyber criminals and hackers become more sophisticated, they can more easily bypass traditional perimeter defense systems such as secure web gateways (SWGs), firewalls, and other intrusion prevention tools.
If you’re unfamiliar with UEBA, this guide is here to help you break it down. Below, we will discuss just what UEBA security is, how it works, the difference between User Behavior Analytics (UBA) and UEBA, and UEBA best practices.
Many legacy cyber security tools identified behavior pattern anomalies or deviations using just statistical analysis and user-defined correlation rules. While these tools are effective at thwarting known threats, they are obsolete when it comes to unknown or zero-day attacks and insider threats. With UEBA security, however, SOC teams can automatically detect unordinary behaviors across entire corporate networks or computer systems without relying on user-defined rules or patterns.
UEBA combines the power of ML, deep learning, and statistical analysis to provide SOC teams with more comprehensive threat detection software—allowing organizations to automatically detect complex attacks across multiple users and entities. In addition, a UEBA solution can group together data in logs and reports, as well as analyze information in files and packets.
UEBA works by collecting information about normal user and entity behavior patterns from system logs. Then, it applies intelligent statistical analysis methods to interpret each dataset and establish baselines of these behavior patterns. Establishing behavior pattern baselines is key to UEBA, as this allows the system to detect potential cyber-attacks or threats.
With a UEBA solution, current user and entity behaviors are continuously compared to their individual baselines. The UEBA cyber threat intelligence software then calculates risk scores and identifies if any behavior pattern anomalies or deviations are risky. If a risk score surpasses a certain limit, the UEBA system will alert SOC team members.
For example, if a user regularly downloads 5 MB of files each day and then suddenly begins to download gigabytes worth of files, a UEBA solution would identify this user behavior pattern deviation and alert IT of a possible security threat.
According to Gartner, a UEBA solution is defined by three core attributes:
Defined by Gartner, User Behavior Analytics (UBA) was the precursor to UEBA—as it was a cybersecurity tool that strictly analyzed user behavior patterns on networks or computer systems. While UBA solutions still applied advanced analytics to identify behavior pattern anomalies, they were unable to analyze other entities—such as routers, servers, and endpoints.
Gartner later updated the definition of UBA and created UEBA—which included the behavioral analysis of both users and entities (either individually or in peer groups). UEBA solutions are more powerful than UBA solutions, as they use ML and deep learning to recognize complex attacks—such as insider threats (e.g., data exfiltration), advanced persistent threats, or zero-day attacks—across individuals, devices, and networks (including cloud-based networks) rather than relying on user-defined correlation rules.
As a rule of thumb, UEBA tools should not replace pre-existing cyber security tools or monitoring systems, such as CASBs or Intrusion Detection Systems (IDS). Instead, UEBA should be incorporated into your overall security stack to enhance your organization's overarching security posture. Other UEBA best practices include:
When it comes to advanced User and Entity Behavior Analytics, CyberRes (a Micro Focus line of business) Arcsight Intelligence can help your organization stay protected against complex cyber threats. Providing a contextualized view of both user and entity behavior patterns within your enterprise, our supercharged UEBA tool provides your SOC team with comprehensive tools to visualize and investigate threats—such as insider threats and APTs—before it’s too late.
In addition, our anomaly detection models don’t expect the same behavior patterns from every user or entity—which means you won’t have to deal with a flood of false-positive alerts. Using ArcSight Intelligence, our software establishes a clear delineation between unusual behavior and real threats by utilizing mathematical probability and unsupervised ML to identify cyber threats more accurately.
If you’re ready to see how ArcSight Intelligence utilizes a UEBA solution to help your SOC team quickly uncover hidden threats in your enterprise network, feel free to request a demo today.
Proactively detect insider risks, novel attacks, and advanced persistent threats
Speed threat detection and response with real-time correlation and native SOAR
Defend with precision, secure with confidence
Accelerate threat detection with insightful, actionable security insights
Find and respond to cyber threats that matter
OpenText ThreatHub Research shows you what’s threatening your organization, and what you can do about it. Made by CISO’s, meant for CISO’s, OpenText ThreatHub Research helps you strengthen your cyber resilience and strategically secure your digital value chain