This page was machine-translated and may differ from the original. View original

Kaspersky Launches UEBA-Based SIEM Solution

Google 우선 소스Published2025.10.22 14:16



Machine learning-based behavioral analysis minimizes false positives and improves security response speed
Global cybersecurity firm Kaspersky has announced 'Kaspersky SIEM,' a security threat detection solution equipped with User and Entity Behavior Analysis (UEBA) rule sets. Going beyond simple threat detection, this solution focuses on strengthening security posture and enhancing corporate operational efficiency and risk management capabilities through real-time anomaly identification and the minimization of false positives.

User and Entity Behavior Analytics (UEBA) is an intelligent security analysis technique introduced to overcome the limitations of existing signature-based detection methods. By learning the typical behavioral patterns of users and systems through machine learning, it automatically detects and alerts to abnormal activities, thereby effectively responding to sophisticated attacks such as credential theft, lateral movement, and fileless malware.

Kaspersky has designed this UEBA rule set to detect anomalies in real time across various security areas, including authentication and access protection, DNS-based data leakage detection, monitoring suspicious network activity, blocking malicious processes, and VPN monitoring. In particular, the behavioral deviation-based risk scoring feature reduces the workload of security teams and provides an environment where they can focus on actual threats.

Ilya Markelov, Head of the Integrated Platform Product Family at Kaspersky, emphasized, “In a constantly changing cyber environment, UEBA rule sets are a core technology for enhancing security,” adding that “it enables the creation of business value beyond technical detection.”

Lee Hyo-eun, Country Manager for Korea, stated, “Kaspersky’s UEBA technology is a game changer that helps Korean companies grow even amidst digital risks,” adding that “it supports not only enhanced security but also operational efficiency and compliance.”

Kaspersky SIEM solutions enable strategic security operations while making the most of existing infrastructure and personnel, and are expected to contribute to elevating cybersecurity from a mere technical function into a core corporate asset.

More details can be found on the official Kaspersky website.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
명세환 기자
명세환 기자