Transcript
Cyber threats are evolving constantly, with attack patterns shifting based on new vulnerabilities and tactics. So to stay ahead, analysts need timely and accurate alerts to remain aware of potential threats. However, static thresholds that trigger alerts based on a fixed limit often lead to false positives or missed threats. So a rigid threshold may fail to detect a slow, stealthy attack or trigger unnecessary alerts for normal fluctuations. And this is where adaptive or smart thresholds come in. So what are smart thresholds? Smart thresholds dynamically adjust alert conditions based on real-time analysis and historical data. And unlike static thresholds, they continuously learn from system activity, adapting to changes in user behavior, network traffic, and application usage. This approach enhances threat detection while reducing false positives and negatives. So here's how it works. The solution establishes a baseline of normal activity, adjusts dynamically to deviations, then detects anomalies against this baseline. It triggers alerts only when deviations indicate potential threats. It utilizes machine learning to recognize patterns. It then incorporates a feedback loop to refine accuracy over time. Now let me demonstrate this feature using Event Log Analyzer, which is also a component of Lock360. Account lockouts are a common occurrence in any organization, especially during periodic password update cycles. But during these windows, the number of failed login attempts can skyrocket, which overwhelm the security team with alerts that are mostly harmless. With Lock360's smart threshold feature, you can filter out these expected spikes and focus only on anomalies that truly need investigation. Now let me walk you through how to set it up. Go to the Alerts tab and click Add Alert Profile. Set the alert profile name as Abnormal Account Lockouts, or name it as you see it fit. Set the severity to Critical or Troubled, depending on your organization's risk policy. Choose the appropriate log source, then choose Account Lockout from the predefined alert criteria. This ensures the alert is tied to real-time account lockout events captured from SQL Server logs. Modify the alert message to provide more context, if needed. Now it's time to set the threshold. Instead of setting a fixed number of lockouts, select the Smart Threshold option. Lock360 will utilize machine learning to analyze historical account lockout patterns for each user and adjust the threshold dynamically. For example, if a user typically experiences 0-1 lockouts a month and suddenly hits 5 lockouts in 10 minutes, Lock360 will flag it. But if dozens of users are being locked out during a known password reset period, the system will adjust the threshold to allow for more lockouts, preventing a flood of alerts. You can specify the timeframe for monitoring, ensuring that Smart Threshold learns the baseline activity for that period. Finally, click Save Profile. Lock360 will now start learning from historical data, refining thresholds per user or peer group, and ensuring alerts are contextually relevant. By using Smart Thresholds during periods like organization-wide password resets, Lock360 ensures that your security team isn't bogged down by alert noise and instead remains focused on identifying real threats like targeted account compromise or insider misuse. If you'd like to know more about Lock360 and how it works, please contact our technical experts today.