Anomaly Detection
Anomaly detection identifies deviations from the usual behaviour of accounts, devices, or network traffic and reports them for review.
Anomaly detection identifies deviations from the normal behaviour of a system, account, or network. It finds unusual activities for which no fixed detection rule exists yet.
How it works
A system first learns what normal behaviour is over a period of time. This can be a server's typical data volume or an account's usual login times. It can also be the normal connections made by a device. The system then continuously compares current activity against this established baseline. Significant deviations are reported as anomalies. This process uses statistical methods and machine learning.
For example, a file server usually transfers a few gigabytes daily to the internet. One night, it suddenly sends 80 GB to an unknown cloud storage provider. No existing rule recognises this destination address. Anomaly detection flags the deviation, helping the SOC to discover an ongoing data exfiltration.
What to look out for
- Not every anomaly indicates an attack. Month-end accounting, updates, and new projects can all alter normal behaviour.
- The initial learning phase requires time. More noise, or irrelevant alerts, may be generated during this period.
- Combine anomalies with other signals before taking direct action.
- Analysts must be able to understand why an activity was flagged as suspicious.
- If a system learns in an already compromised environment, it may treat the attacker as normal.
Relevance for the SOC
Anomaly detection is particularly useful for identities, network traffic, and data flows. It complements rule-based detection, which identifies known patterns of attack. Together, both methods can cover a wider range of attack vectors.
Typical mistakes
A common mistake is deploying anomaly detection with very high expectations. It is then often disabled due to a high volume of false positives. A phased rollout for a few well-defined use cases is a better approach. Another error is failing to retrain the system after major changes, such as a migration to the cloud.
Switzerland and regulation
When analysing employee behavioural data, the revFADP (revised Federal Act on Data Protection) applies. Swiss labour law also contains relevant provisions. The purpose and scope of monitoring must be proportionate. Both must also be communicated transparently to employees.
How we implement it
We use anomaly detection mainly for identities and network traffic, for instance through NDR. We investigate any suspicious activities in context with other signals before taking action.