Blueprint: Build the Best in Cyber Defense cover image

Strategy 7: Select and Collect the Right Data

Blueprint: Build the Best in Cyber Defense

00:00

How to Limit the Effects of Anomaly Detections

Not every anomaly is an attack. Your anomaly based detections are going to be probably generating more false positives than your signatures unless your signatures are terrible. And so how do you decide when you have a kind of alert like out of hours login, you know, again from a new PC where a lot of times it is going to be a false positive? What can people do to limit the effects of that? Well not just saying, wow, I give up and turn it off. Is there some kind of strategy you can use to tune those things to where it's reasonable, but they're not overtuned?

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app