Flyer
ArcSight Intelligence Behavioral Analytics
ArcSight Intelligence behavioral analytics gives you a new lens
through which to detect, investigate, and respond to threats that
may be hiding in your enterprise—before your data is stolen.
Using machine learning, ArcSight Intelligence Detect. Investigate. Respond.
by OpenText™ distills billions of events into
a prioritized list of high-quality security We use the To expose the
leads to focus and accelerate the efforts SECURITY DATA THREATS
of your security operations center (SOC). you already have you may already have
ArcSight Intelligence’s machine learning
models, combined with a highly intuitive user SIEM
ARCSIGHT
INTELLIGENCE
interface (UI), accelerate threat detection and Rules and Anomaly detection Orchestration
thresholds
investigation from weeks to minutes. DLP
Automation
+
Why ArcSight Intelligence EDR
Behaviors
Many organizations have important assets to Pattern Reporting
matching
protect, whether it is customer information, IAM 450+ models
intellectual property, critical infrastructure
controls, or all of the above. Unfortunately, Figure 1. ArcSight Intelligence views your existing security data through a new lens in order to identify hid-
existing approaches to protecting these den threats by looking for anomalous behavior. This produces high-quality threat leads, allowing your
security teams to respond and remediate quickly and effectively.
assets continuously fall short, leaving security
teams to contend with rigid, rules-based
analytics, fragmented security ecosystems, Using unsupervised machine learning—a type within log files and observe events that
and a never-ending barrage of alerts— of artificial intelligence (AI) that doesn’t need involve these entities to determine expected
most of which are false alarms. Meanwhile, labels—ArcSight Intelligence’s algorithms behavior—a measurement we call “unique
these teams are expected to flawlessly extract available entities (users, machines, normal.” As new information comes through
protect against critical threats like data IP addresses, servers, printers, etc.) from the analytics process, events are evaluated
exfiltration and unauthorized network access.
Threat Detection Use Cases
ArcSight Intelligence is uniquely positioned
to find the threats that matter for enterprises
with valuable data to protect, limited security ! !
or financial resources, and significant surface
area to monitor. Unlike other solutions, Insider Threat Data Breach Advanced Threat IP Theft
ArcSight Intelligence bypasses rules and • At-Risk employee • Data Staging • Compromised Account • Mooching
thresholds and instead assesses the potential • High-Risk Employees • Data Exfiltration • Internal Recon • Snooping
• Account Misuse • Email Exfiltration • Unusual Traffic • Interactions with dormant
risk of a user or entity in your enterprise • Privilege Account • Print Exfiltration • Abnormal Processes resources/files
based on mathematical probability and Misuse • USB Exfiltration • Unusual Applications • High Risk IP/Data Access
• Terminated Employee • Unusual data access • Infected Host • Lateral Movement
unsupervised machine learning models. Activity • Unusual uploads • Malicious Tunneling
This approach, combined with ArcSight • Bot Detection
Intelligence’s native big-data architecture, Figure 2. ArcSight Intelligence uses advanced mathematical algorithms to constantly mine billions of data
allows your security team to detect threats points and reveal indicators of insider threats, data breaches, advanced persistent threats (APT), IP theft,
with speed and at scale. and more.
1
against previously observed behavior to Viewing Risky Entities
assess potential risk. As a security practitioner, your primary
mechanism for interacting with ArcSight
With this process of baselining and scoring, Intelligence is the intuitive, web-based
ArcSight Intelligence boosts the efficiency dashboard. ArcSight Intelligence’s dashboard
and speed at which security teams allows users to quickly and easily determine
detect, triage, investigate, and respond which entities represent the greatest
to threats. ArcSight Intelligence’s output potential risk. As entities are identified,
risk assessments can be used to initiate the dashboard allows you to drill down
actions via automation, orchestration, and into results so that the potential risk can be
alerting solutions to execute faster-than- understood in the context of the generated Connect with Us
human actions as risks are found. ArcSight alerts and, if desired, the raw events that [Link]
Intelligence also provides downloadable produced them. The screenshots below
reports summarizing immediate show a drilldown from the list of riskiest
organizational risks. users down to the raw events.
1. View all entities within the enterprise with seen below the timeline view. They can entities are identified through statistically
analytics to display, grouped by entity type. be filtered by associated entities and determined peer groups.
The screenshot shows a list of users, with a types of risk and, because they display in
presentation that displays them in order of chronological order linked to the timeline
risk score from highest to lowest. view, it is simple to see a narrative of the
unfolding behavior in the context of
other events.
5. The raw events that triggered an alert
are only one click away. In addition to
seeing the actual contents of the log file
responsible for the analytics, users have
the ability to enter additional queries using
this interface.
2. When any entity is viewed, its risk score
over time is displayed in a timeline view.
This perspective shows not only the change
in risk score, but also broadly characterizes
4. Clicking on any of the alerts allows for
the types of behavior that drove it.
examination that shows the event in
context of the user’s baseline and other
relevant entities in the enterprise. The risk
associated with the alert is displayed,
and the model that triggered the alert is
described in detail. Note that the user’s
3. When viewing an entity, a display of the baseline is compared to both itself, as well
alerts associated with the entity can be as to other similar entities. These similar
Table 1. Screenshots of the ArcSight Intelligence dashboard showing navigation through the analytical results
OpenText Cybersecurity provides comprehensive security solutions for companies and partners of all sizes. From prevention, detection and response to recovery, investigation and compliance,
our unified end-to-end platform helps customers build cyber resilience via a holistic security portfolio. Powered by actionable insights from our real-time and contextual threat intelligence,
OpenText Cybersecurity customers benefit from high efficacy products, a compliant experience and simplified security to help manage business risk.
761-000012-003 | O | 05/23 | © 2023 Open Text