Monday, November 24, 2025
  • Login
No Result
View All Result
Authentic Press Network News | APN News
  • News
    • National
    • International
    • States
    • Views
    • Crime & Corruption
    • Headlines
    • Breaking News
    • Canada’s privacy commissioner launches investigation over the use of facial recognition technology
  • Business
    • Banking
    • Finance
    • Economy
    • Be an informer to I-T dept; earn up to Rs 5 crore
    • Markets
  • Tech & Industry
    • Tech
    • Auto
    • Information Technology
    • Telecom
    • Oil & Natural Gas
    • Gravitational wave event likely signaled birth of black hole
  • Entertainment
    • Malayalam Film
    • Media
    • Music
    • Shawn Mendes Released Highly Anticipated Self-Titled Album Today
    • Youth
      • Fashion
      • Kids
      • Life Style
  • Education
    • Campus News
    • ITM University, Gurgaon Student Palash Chhabra Represents Varsity at Google Student Ambassador Summit
  • Health
    • Medical News
    • Maharshi Shushruta, The Great Grandfather of Surgery!
  • Tourism
    • Travel
    • Food&Beverages
    • “Keraliya Ayurveda is Credible and Authentic”
    • Hospitality
  • Sports
  • Editor’s column
  • Magazine
  • News
    • National
    • International
    • States
    • Views
    • Crime & Corruption
    • Headlines
    • Breaking News
    • Canada’s privacy commissioner launches investigation over the use of facial recognition technology
  • Business
    • Banking
    • Finance
    • Economy
    • Be an informer to I-T dept; earn up to Rs 5 crore
    • Markets
  • Tech & Industry
    • Tech
    • Auto
    • Information Technology
    • Telecom
    • Oil & Natural Gas
    • Gravitational wave event likely signaled birth of black hole
  • Entertainment
    • Malayalam Film
    • Media
    • Music
    • Shawn Mendes Released Highly Anticipated Self-Titled Album Today
    • Youth
      • Fashion
      • Kids
      • Life Style
  • Education
    • Campus News
    • ITM University, Gurgaon Student Palash Chhabra Represents Varsity at Google Student Ambassador Summit
  • Health
    • Medical News
    • Maharshi Shushruta, The Great Grandfather of Surgery!
  • Tourism
    • Travel
    • Food&Beverages
    • “Keraliya Ayurveda is Credible and Authentic”
    • Hospitality
  • Sports
  • Editor’s column
  • Magazine
No Result
View All Result
Authentic Press Network News | APN News
No Result
View All Result
Home Corporate News

Shifting Gears from IOCs to IOBs

by NS
December 17, 2020
in Corporate News
0
0
SHARES
38
VIEWS
Share on FacebookShare on Twitter

I recently had the pleasure of speaking at GovWare 2020 about a topic that will become increasingly important for a growing number of organizations: shifting from the traditional and well-known Indicators of Compromise (IOCs) model to one that’s driven by Indicators of Behavior (IOBs). This does not mean that IOCs will go away-they still serve a purpose-but the new way of working that we’re all adapting to requires a new approach.

Limitations of IOCs

The after-the-fact nature of IOCs is one of their clearest limitations. They are documentation artifacts (hash of a file, reputation of an IP, known-bad URLs, in-memory footprint, etc) based on an isolated action after it has occurred. Too often still, their 1:1 mapping where an IOC triggers an alert which is then triaged by a Security Operations Center analyst to review or take action on leads to alert overload. Even though advanced SIEMs, UEBAs, and threat intelligence platforms can help reduce a handful of false positives through automation, they still occur at excessively high rates.

Besides the sheer volume, the bigger challenge is that IOCs are derived from actions that occur in isolation, lacking context. As standalone events, IOCs remain difficult to assign a priority to, and are even more difficult to keep updated and current. Assuming security teams are able to handle those challenges, what’s the life span of an IOC? How and when does an IOC expire? How much “noise” is there in threat intelligence feeds?

Another key limitation: IOCs were designed for an infrastructure security-centric world. And the world has been changing for years. The current pandemic accelerated this change as organizations now struggle to secure hybrid IT environments: your corporate “network” is now made of thousands of “branch offices of one” as employees work-from-home. That is why we believe users are the new perimeter, not the network anymore, and also that data gravity changed the information protection game. In this reality, IOCs simply fall short.

Forcepoint’s Goals with IOBs

An IOB is the way a user, device or account conducts itself. Our teams designed dozens and dozens of IOBs with the clear goal of addressing IOC’s shortcomings. For IOBs, both the context and the timeline (the “killchain” equivalent) are key. IOBs focus on understanding the context around how your employees interact with the organization’s data and systems over time in a much broader way. With them, context for example means understanding a user’s typical behavior, the timeframe, applications used, the actions they are taking and the outcome they are trying to achieve.

Risk Scores are Key

Controlling and monitoring application and data access is only one part of it. IOBs also factor in actions in context of each other to produce an overall risk score. Typical employee behaviors like accessing approved applications and data shares won’t adversely impact a user’s risk score. But risky behaviors like taking a screenshot of confidential documents, shared in a zoom session, to save on a USB key or a cloud storage service, or printing those same critical documents at home will negatively impact a person’s score.

Our risk computation engine is key to make IOBs effective. Each IOB defines a base risk contribution along with a decay over time, and depending on further context, the risk contribution can adapt. All of this is in service of getting to a key outcome-true risk adaptive protection for users. IOBs enable a shift from a reactive reality to a proactive one. IOBs and the dynamic risk scores they power allow security leaders to anticipate malicious activities like data exfil, compromised user credentials or other insider threats. Most importantly, they help security teams stay left of breach.

NS

NS

Next Post

Does Health Insurance Cover People With Disabilities?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent News

India’s MSMEs Should Prioritize Manufacturing and Local Supply Chain Development: Nivruti Rai, Invest India

India’s MSMEs Should Prioritize Manufacturing and Local Supply Chain Development: Nivruti Rai, Invest India

November 24, 2025
Olympian Suma Shirur Wins Sports Coach of the Year (Female) Award at FICCI Turf 2025

Olympian Suma Shirur Wins Sports Coach of the Year (Female) Award at FICCI Turf 2025

November 24, 2025
St. Jude India ChildCare Centres Inaugurates India’s Largest Childhood Cancer Sanctuary in Kharghar

St. Jude India ChildCare Centres Inaugurates India’s Largest Childhood Cancer Sanctuary in Kharghar

November 24, 2025
India Emerges as the World Leader in the field of Living Donor Liver Transplantation by Performing the Highest Number in the world

India Emerges as the World Leader in the field of Living Donor Liver Transplantation by Performing the Highest Number in the world

November 24, 2025
Sikkim Chief Minister Attended Swearing-In Ceremony of New Bihar Leadership

Sikkim Chief Minister Attended Swearing-In Ceremony of New Bihar Leadership

November 24, 2025

APNNEWS owned by a Group of Journalists is a 24 X 7 news portal spearheaded by veteran journalist Suresh Kumar.

Facebook Twitter Youtube

Categories

  • Corporate News
  • Finance
  • Tech & Industry
  • Education
  • Health
  • Life Style
  • Real Estate
  • Sports
  • Entertainment
  • New Products
  • Environment
  • Religion

Company

  • About Us
  • Terms of Service
  • Disclaimer
  • Contact Us
  • APN NEWS RSS
  • Advertise with Us
  • Your Ad Choices

APNNEWS owned by a Group of Journalists is a 24 X 7 news portal spearheaded by veteran journalist Suresh Kumar.

Facebook X-twitter Youtube
  • About Us
  • Terms of Service
  • Your Ad Choices
  • Advertise with Us
  • Contact Us
  • Disclaimer

© 2024 APN NEWS, All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • News
    • National
    • International
    • States
    • Views
    • Crime & Corruption
    • Headlines
    • Breaking News
    • Canada’s privacy commissioner launches investigation over the use of facial recognition technology
  • Business
    • Banking
    • Finance
    • Economy
    • Be an informer to I-T dept; earn up to Rs 5 crore
    • Markets
  • Tech & Industry
    • Tech
    • Auto
    • Information Technology
    • Telecom
    • Oil & Natural Gas
    • Gravitational wave event likely signaled birth of black hole
  • Entertainment
    • Malayalam Film
    • Media
    • Music
    • Shawn Mendes Released Highly Anticipated Self-Titled Album Today
    • Youth
      • Fashion
      • Kids
      • Life Style
  • Education
    • Campus News
    • ITM University, Gurgaon Student Palash Chhabra Represents Varsity at Google Student Ambassador Summit
  • Health
    • Medical News
    • Maharshi Shushruta, The Great Grandfather of Surgery!
  • Tourism
    • Travel
    • Food&Beverages
    • “Keraliya Ayurveda is Credible and Authentic”
    • Hospitality
  • Sports
  • Editor’s column
  • Magazine

© 2024 APN NEWS, All Rights Reserved.