In this section:
- What is a threshold value?
- How are threshold values computed?
- What are Behavior Analytics alerts?
- What are Risk Scores and how are they calculated?
- Risk Score calculation scenarios
- How is the Risk Score calculated when the group threshold is greater than zero and the individual threshold is zero?
- How is the Risk Score calculated when the group threshold is zero and the individual threshold is greater than zero?
- How is the Risk Score calculated when the group threshold is zero and the individual threshold is also zero?
- How are Behavior Analytics alerts prioritized?
- When is a Behavior Analytics alert notification sent?
What is a threshold value?
Threshold values mark the transition point between normal behavior and potentially malicious activity. They're computed by looking at hundreds and thousands of individual and group transactions over time. There are two types of threshold value:
Individual thresholds: iManage Threat Manager statistically computes an individual threshold for each activity of a particular user.
Group/Peer Group threshold: iManage Threat Manager statistically computes a group/peer group threshold value for each activity of the group/peer group. This is pertinent because there may be groups that exhibit behavior that is very different from the general population—for example, the Litigation Practice group and/or the Intellectual Property practice group. (A Peer Group consists of all the users in a given scope.)
How are threshold values computed?
The default thresholds for each activity (for example, mail, print, export, and so on) are computed as a multiple of Standard Deviations (SD) away from the mean. This applies to both individual and group threshold values.
What are Behavior Analytics alerts?
A Behavior Analytics alert is a warning that informs you of users displaying potentially suspicious behavior. iManage Threat Manager generates a Behavior Analytics alert when a user’s activity count on a given day exceeds the group/peer group threshold value (of that user’s group) for an activity.
What are Risk Scores and how are they calculated?
Risk Scores are numerical values assigned to users when they exceed both their group threshold and individual threshold for an activity. A user must exceed the group threshold and individual threshold for an activity before a Risk Score is computed for that activity. This numerical Risk Score value is calculated based on the number of standard deviations by which a person has exceeded their individual mean. This ensures that a high-intensity attack gets prioritized based on the extent to which the individual behaves differently from their typical behavior. The greater the variation, the higher the score.
Risk Score is calculated for every activity where the user has exceeded both their group threshold and individual threshold. The user's total Risk Score is a total of their Risk Scores across all activities. Risk scores of up to 999 display numerically; higher values use K, M, and B terminology, and are rounded to the nearest decimal, for example a risk score of 1051 will display as 1.1k.
NOTE: If there's a need to ignore the impact that peer-group behavior has on the generation of alerts for a particular rule, you can configure the rule so that group thresholds are ignored. When group thresholds are ignored, alerts are prioritized based on deviations from a user's normal behavior only. This can help improve accuracy in detecting anomalous behavior in privileged accounts. By default, however, group thresholds aren't ignored.
For more information on the specific types of rules to which iManage recommends that group thresholds are ignored, refer to iManage Threat Manager Best Practices Guide.
Risk Score calculation scenarios
The following scenarios show how the Risk Score is calculated based on different combinations of the group and individual thresholds.
How is the Risk Score calculated when the group threshold is greater than zero and the individual threshold is zero?
In this situation, we raise an alert when the user's activity exceeds the group threshold. As the individual has never exhibited this behavior before, but their peer group has, we score the alert (for any such activity) based on the deviation of the user's activity from the peer group baseline behavior.
How is the Risk Score calculated when the group threshold is zero and the individual threshold is greater than zero?
A group threshold of zero means that the user's peer group hasn't performed such activity before, based on historical analysis. In such a situation, if the user's activity exceeds the group threshold (zero), an alert is raised and a score is generated based on the deviation from the user's normal.
How is the Risk Score calculated when the group threshold is zero and the individual threshold is also zero?
A group threshold of zero and an individual threshold of zero means that neither the user nor the user's peer group has performed such activity before, based on historical analysis. Clearly, such an event is an anomaly and therefore an Urgent alert is raised.
NOTE: For more information on how Risk Scores are calculated, contact iManage support.
How are Behavior Analytics alerts prioritized?
The higher the total risk score across activities, the higher the priority, and in turn, the higher the user will be listed in the Behavior Analytics alert reports.
When is a Behavior Analytics alert notification sent?
When creating a Behavior Analytics alert rule, you can set a minimum security level for notifications. A notification is sent only when a new alert meets or exceeds this level. Behavior Analytics notifications include an Open Alert link that opens the corresponding alert in Alert Details for investigation.
Example:
A rule is scheduled to run continuously every five hours, starting at 5:00 AM, with alerts triggered for severity Elevated and above.
At 5:00 AM, user A reaches Elevated, generating an alert and sending a notification.
At 10:00 AM, user A remains at Elevated, so no notification is sent.
At 3:00 PM, user A moves to High, generating a new alert and notification.
Later runs that day send no further notifications unless the severity rises again.
NOTE: This example applies only when the rule runs on a continuous schedule.
If Scope Changes are enabled, a notification is sent each time the rule’s scope changes.