A SOC team implemented a new ML-based UEBA platform 3 months ago. The system generates 800-1,200 alerts per day. The three-person tier-1 analyst team was previously handling 80 alerts per day from their rule-based system. After 3 months, analyst morale has plummeted - 94% of investigated UEBA alerts turn out to be benign (employee working late, VPN from a new coffee shop, accessing a new file share for a project).
A SOC analyst is reviewing alerts from an ML-based UEBA (User and Entity Behavior Analytics) system. The system flagged 847 events in the past 24 hours, but the analyst's previous experience suggests most will be false positives. What is the primary challenge this illustrates with ML-based security detection?
- A.UEBA systems are not capable of correlating events across multiple users; model monitoring is needed only for online-learning systems, since a frozen model's accuracy cannot change after deployment
- B.The false positive economics problem: high false positive rates waste analyst time, cause alert fatigue, and may lead analysts to ignore genuine alerts mixed in with the noise