Adaptive Behavioral Anomaly Detection: Integrating UEBA and EDR for Real-Time Mitigation of Threats and Insider Risks
Abstract
: This research presents a comprehensive hybrid security system integrating User and Entity Behavior Analytics (UEBA) with Endpoint Detection and Response (EDR) capabilities to address sophisticated cyber threats including Advanced Persistent Threats (APTs) and insider attacks. The proposed architecture leverages the Elastic Stack (ELK) platform to provide real-time behavioral anomaly detection through statistical baseline modeling and machine learning techniques. The system employs personalized Isolation Forest models combined with statistical baselines using mean ± 2 σ methodology to establish normal operational boundaries across 293 individualized behavioral profiles. Evaluation on 9,754 security events over a 30-day monitoring period demonstrates the system’s effectiveness, achieving 95% confidence intervals in baseline predictions while maintaining operational efficiency. The integrated approach addresses critical industry bottlenecks through intelligent log prioritization, reducing network bandwidth consumption by 75% and false positive rates by 86%. Key findings reveal distinct temporal patterns in anomaly distribution, with peak detections during week-ends and business hours (9 AM - 2 PM). The system successfully identified 485 anomalies across multiple log types, with taskscheduler (13.45%), WMI (11.50%), and process logs (9.89%) showing highest anomaly rates. This research validates the feasibility of cost-effective, scalable threat detection by fusing EDR visibility with UEBA behavioral intelligence, providing a practical framework for enterprise security operations.