Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage Behaviour Analytics Configuration

Want to summarize with AI?

Log in

Describes Manage Behaviour Analytics Configuration in Cisco Secure Access. You can configure User and Entity Behavior Analytics (UEBA) detections for anomalous user activity in Cisco Secure Access.


You can configure User and Entity Behavior Analytics (UEBA) detections for anomalous user activity in Cisco Secure Access. Use behavior analytics to identify activity that differs from a user’s established patterns or from thresholds that you configure.

To view the configuration, go to: Connect > Users, Groups, and Endpoint Devices > Configuration management > Behaviour Analytics

You can enable or disable anomaly detection for all users, configure limits for operations by hours and minutes, and receive continuous rule updates. Detected anomalies are available to you for 30 days, even if you later disable detection. This setup allows you to proactively detect and respond to potential security threats by monitoring deviations from the configured user behaviour patterns.

Available analytics

Analytics What it detects Detection basis
DLP Violation Spike An unusual increase in Data Loss Prevention (DLP) policy violations for selected DLP rules or classifications. A fixed threshold or an AI-based user baseline calculated from the previous seven days.
File Operations Unusual bulk file uploads, downloads, and deletions. Manually configured thresholds or an AI-based baseline for each user and operation. AI analyzes recent user activity and can require up to seven days to learn normal patterns. You can configure the thresholds manually or using AI.
High-Risk Country File Activities File uploads to, or downloads from, countries that you designate as high-risk. Selected file activities and countries.
Impossible Travel Events from geographically distant locations within an unrealistic timeframe. Configured travel conditions.
Anomalous MCP Activity Unusual Model Context Protocol (MCP) activity, including potential injection activity or a sudden increase in requests. MCP activity patterns evaluated by Secure Access.
Unseen Location Activity User activity from a city or source IP address that was not observed for that user during the previous 30 days. A rolling 60-day user location history.
Note
The system starts to generate alerts only after seven days of configuration.
Traffic Spike and Destination Monitoring An unusual increase in requests to a specific destination or to any TOR relay. An AI-based user baseline calculated from the previous seven days and the minimum alerting threshold that you configure.
Note
The system starts to generate alerts only after seven days of configuration.
Behaviour Analytics Configuration interface image.

AI-based thresholds

For analytics that use artificial intelligence (AI), Secure Access compares current activity with a baseline learned for the individual user. The threshold that you enter is a minimum alerting level, not the user’s learned baseline.

Note
Secure Access generates an AI-based alert only when the activity is anomalous for the user and the activity meets the configured minimum threshold. A low minimum threshold does not force an alert when the activity is normal for the user. A high minimum threshold can suppress an otherwise anomalous event.

Configure Analytics for DLP Violation Spike

Use DLP Violation Spike to detect unusual increases in Data Loss Prevention policy violations. This feature detects any violation that matches selected DLP rules and selected DLP classifications.

Detection methods

Fixed-threshold detection

Secure Access generates an anomaly when the number of violations exceeds the count that you configure within the selected time period.

Artificial intelligence-based detection

Secure Access compares the current violation count with a baseline learned for the individual user from the previous seven days. The count that you configure is a minimum alerting threshold. It does not replace the learned baseline.

Note
With AI-based detection, both conditions must be met: the activity must be anomalous for the user, and the activity must meet the configured minimum threshold.

Threshold examples

Example Evaluation Outcome
Fixed threshold: 10 violations in 1 hour The user reaches 11 violations within 1 hour. Secure Access generates an anomaly.
AI baseline: 2 violations per hour; minimum threshold: 40 The user reaches 10 violations in 1 hour. The activity is unusual, but it is below the minimum threshold. Secure Access does not generate an anomaly.
AI baseline: 50 violations per hour; minimum threshold: 10 The user reaches 11 violations in 1 hour. The count is above the minimum, but it is not unusual for the user. Secure Access does not generate an anomaly solely because the count exceeded 10.

Procedure

To configure behaviour analytics for DLP Violation Spikes, perform the following steps.

Procedure

  1. Navigate to Connect > Users, Groups, and Endpoint Devices > Configuration management > Behaviour analytics.

  2. Click Edit on the DLP Violation Spike tile.

    The DLP Violation Spike 1 interface.

    The edit side panel appears.

  3. Turn on the Status toggle.

    The DLP Violation Spike 2 interface.
  4. For AI-based detection, enable the Auto calculate DLP violations using AI option and enter the minimum violation count and time period for the required violation types.

    The DLP Violation Spike 3 interface.
    Note
    Secure Access uses the previous seven days of user activity to establish a user-specific baseline.
    Note
    The alert threshold value is optional and can be any number between 0 and 10000.
  5. Select Apply a single threshold to all DLP violations to select a single threshold for all DLP violations.

    The DLP Violation Spike 4 interface.
    1. Select one or both the Violation types and set the Allowed limit along with the Time frame.

  6. To set threshold limit for each DLP violation separately, select the required DLP violation type and then select the required violations from the drop-down list.

  7. Enter the allowed violation count for the selected DLP violations and the respective time frames.

    The DLP Violation Spike 6 interface.
    Note
    The threshold time frame must be between five minutes and 24 hours.
  8. Click + Add DLP rule threshold to add threshold limit for another DLP rule.

  9. Click + Add DLP classification threshold to add threshold limit for another DLP classification.

  10. Click Save.

    Note
    When AI mode is enabled, repeated alerts for the same user are suppressed for 60 minutes. When configured manually, repeated alerts for the same user are suppressed for the configured time frame.

Configure Analytics for File Operations with AI

To configure behaviour analytics for file operations with AI, perform the following steps.

Procedure

  1. Navigate to Connect > Users, Groups, and Endpoint Devices > Configuration management > Behaviour analytics.

  2. Click Edit on the File Operations tile.

    The Ueba Fo 1 interface.

    The edit side panel appears.

  3. Click the Status toggle to enable it.

    The Ueba Fo 2 interface.
  4. Enable the Auto calculate bulk operation anomalies using AI option to use AI to analyze and set the optimal threshold for each operation for each user.

    The Ueba Fo 3 interface.

    Once enabled, Cisco Secure Access learns normal file activity patterns and generates alerts for anomalous bulk file operations.

    Note
    The AI learning period can take up to 7 days before the first alert is generated.
    Note
    When AI mode is enabled, repeated alerts for the same user are suppressed for 60 minutes.
  5. Select the required file operation names.

  6. You can enter the file count that you want to allow for each operation and the time frames respectively.

    The Ueba Fo 4 interface.
    Note
    The alert threshold acts as a minimum activity level for generating an alert. If activity is anomalous but stays below the threshold, no alert is generated.
    Note
    The alert threshold value is optional and can be any number between 0 and 10000.
  7. Click Save.


Configure Analytics for File Operations Manually

To configure behaviour analytics for file operations manually, perform the following steps.

Procedure

  1. Navigate to Connect > Users, Groups, and Endpoint Devices > Configuration management > Behaviour analytics.

  2. Click Edit on the File Operations tile.

    The Ueba Fo 1 interface.

    The edit side panel appears.

  3. Click the Status toggle to enable it.

    The Ueba Fo 2 interface.
  4. Set the file operation thresholds:

    1. Click the Delete checkbox, and then enter the maximum number of deleted files and the duration in the respective fields.

    2. Click the Download checkbox, and then enter the maximum number of downloaded files and the duration in the respective fields.

    3. Click the Upload checkbox, and then enter the maximum number of uploaded files and the duration in the respective fields.

    The Ueba Fo 5 1 interface.
    Note
    The threshold file count must be five or more.
    Note
    The threshold time frame must be between five minutes and 24 hours.
  5. Click Save.

    Note
    When manual thresholds are used, repeated alerts for the same user are suppressed for the configured time frame.

Configure Analytics for High-Risk Country File Activities

To configure behavior analytics for uploads to and downloads from high-risk countries, perform the following steps.

Procedure

  1. Navigate to Connect > Users, Groups, and Endpoint Devices > Configuration management > Behaviour analytics.

  2. Click Edit on the High-Risk Country File Activities tile.

    The Ueba Thr 1 1 interface.

    The edit side panel appears.

  3. Click the Status toggle to enable it.

  4. Select the required file activities from the following optons:

    • Upload files to high-risk countries – Enable analytics for upload activity to the selected high-risk country.

    • Download files from high-risk countries – Enable analytics for download activity from the selected high-risk country.

  5. Select the high-risk countries from the drop-down list.

    The Ueba Thr 2 1 interface.
    Note
    You can select as many countries as required.
  6. Click Save.

    Note
    Repeated alerts for the same user are suppressed for 60 minutes.

Configure Analytics for Impossible Travel

To configure behaviour analytics parameters, perform these steps.

Procedure

  1. Navigate to Connect > Users, Groups, and Endpoint Devices > Configuration management > Behaviour analytics.

  2. Click Edit on the Impossible Travel tile.

    The Ueba Imp Tra 1 interface.

    The edit side panel appears.

  3. Click the Status toggle to enable it.

    The Ueba Imp Tra 2 interface.
  4. Click Save.

    Note
    Repeated alerts for the same user are suppressed for 60 minutes.
    Note
    The system generates an alert only if the location is not visited by the user in the preceding seven days.

Configure Analytics for Anomalous MCP Activities

Anomalous MCP Activities detects Model Context Protocol (MCP) activity that differs from expected patterns. Examples include potential injection activity and a sudden increase in MCP requests.

To configure behaviour analytics for anomalous MCP activity, perform the following steps.

Procedure

  1. Navigate to Connect > Users, Groups, and Endpoint Devices > Configuration management > Behaviour Analytics.

  2. On the Anomalous MCP Activities tile, select Edit.

  3. Turn on the Status toggle.

    The Anomalous Mcp Activities 1 interface.
  4. Select Save.

    Note
    Repeated alerts for the same user are suppressed for 60 minutes.

Secure Access begins monitoring MCP activity. To receive notifications, create a behavior analytics alert rule for anomalous MCP activity.

Configure Analytics for Unseen Location Activities

Secure Access maintains a rolling 60-day location history for each user when Unseen Location Activities is enabled. Activity can be identified as anomalous when the city or source IP address is not present in that user’s history.

Note
The system starts to generate alerts only after seven days of configuration.

To configure behaviour analytics for unseen location activities, perform the following steps.

Procedure

  1. Navigate to Connect > Users, Groups, and Endpoint Devices > Configuration management > Behaviour Analytics.

  2. On the Unseen Location Activity tile, select Edit.

  3. Turn on the Status toggle.

    The Unseen Location Activity 1 interface.
  4. Select Save.

    Note
    Repeated alerts for the same user are suppressed for 60 minutes.

Secure Access evaluates user locations against the preceding 60 days of location history. To receive notifications, create a behavior analytics alert rule for unseen location activity.

Configure Analytics for Traffic Spike and Destination Monitoring

The Traffic Spike and Destination Monitoring detects the following activity:

  • An unusually high number of requests to any TOR relay.

  • An unusually high number of requests to a specific destination.

Secure Access compares current activity with a user-specific baseline calculated from the previous seven days. The threshold that you enter is the minimum activity level at which an AI-based anomaly can generate an alert.

Activity must be anomalous for the user and meet the configured minimum threshold. Exceeding the minimum threshold does not generate an alert when the activity is normal for the user.

To configure behaviour analytics for traffic spikes, perform the following steps.

Procedure

  1. Navigate to Connect > Users, Groups, and Endpoint Devices > Configuration management > Behaviour Analytics.

  2. Click Edit on the Traffic Spike and Destination Monitoring tile.

  3. Turn on the Status toggle.

  4. Select the intended target type that you want to configure.

    • Select TOR traffic for requests to any TOR Relay.

    • Select Destination to monitor requests to a specific domain, application, or category.

  5. Enter the minimum request count per hour as the Alert threshold for the selected target type.

    The Traffic Spike and Destination Monitoring 1 interface.
    Note
    The alert threshold value is optional and can be any number between 0 and 10000.
  6. Select Save.

    Note
    Repeated alerts for the same user are suppressed for 60 minutes.

Secure Access compares request activity with the user’s recent baseline. To receive notifications, create a behavior analytics alert rule for each traffic spike type that you enable.

UEBA Scope

  • UEBA supports only Secure Internet Access traffic paths and does not support Secure Private Access.

  • UEBA analyzes only events that are associated with Active Directory (AD) users as it profiles user behavior.

  • The following table lists the supported Secure Internet Access configurations and user sources.

    Access type Supported user source
    Proxy auto-configuration (PAC) file (registered network) AD user
    Roaming Module (Umbrella) AD user
    Remote access VPN (RAVPN) to the internet AD user; all analytics except Impossible Travel
    Branch to the internet (remote tunnel or IPsec tunnel) AD user; web traffic only
    Zero Trust Access (ZTA) TIA AD user; web traffic only
  • For bulk file operations, UEBA supports uploads, downloads, and deletions only for a limited set of file-sharing applications.

  • UEBA analyzes all configured DLP rules and classifications to detect spikes in DLP violations.


Known Issues

The following issues are known and will be addressed in future releases.

  • When you view bulk file action anomalies in User and Entity Behavior Analysis event details, the file name might appear as unspecified in some cases.

  • The View more in Events link at the bottom of UEBA events list pane redirects to the Events page . But it shows all events by the user during past 10 minutes time window of latest anomalous event. It does not show the exact anomalous events in Events page table.