4B. Analyse and Query logs and SIEM data obj 3.1 Flashcards
Heuristic-based analysis
A method that uses feature comparisons and likenesses rather than specific signature matching to identify whether the target of observation is malicious.
Behaviour-based analysis
A network monitoring system that detects changes in normal operating activity and identifies abnormal activity. Uses heuristics to generate a statistical model of what the baseline looks like
Anomaly-based analysis
the process of defining an expected outcome or pattern to events, and then identifying any events that do not follow these patterns
Trend analysis
process of detecting patterns within a dataset over time and using those patterns to make predictions about future events. Can help to judge that specific events over time are related and possibly indicate that an attack is imminent
awk
The feature awk is a scripting engine geared toward modifying and extracting data from files or data streams, which can be useful in preparing data for analysis