Data Insight enables you to monitor malicious activity in your storage environment. Data Insight profiles all users by assigning a risk-score to every configured user. It displays the riskiness of a user in terms of a numerical score that ranges from 0 to 100. Higher the risk score of a user, higher is the perceived risk posed by the user.
The risk score places each user at a relative distance from other users and orders them in accordance with how risky a user is in comparison to other users.
A risky user typically displays anomalies such as:
The fraction of the total number of data sources that a user has permissions on. (Access)
Abrupt deviation in activity pattern where deviation on activity on sensitive files is given more weightage. (Anomaly)
Abnormal increase in number of alerts against the user. (Alerts)
Note that the user risk score is computed by considering the individual scores of different parameters for the last 15 days by default. The user risk score is calculated on a daily basis and stored for the last 180 days.
The risk score assigned to a user helps you do the following:
Identify potentially malicious users.
Review the permissions that are granted to the users.
Review if a risky user is a custodian on any storage resource.
Review the top active and sensitive data that is being accessed by the risky user.
Add a user with a high risk score to a watchlist to enable you to closely monitor the user's activities.
Data Insight computes the risk-score for a user based on the weighted sum of individual scores of the following parameters.
Table: Components for computing user risk score
Note that Data Insight assigns a default priority to these parameters when calculating their weighted sum.
The User Risk Dossier provides the next level of details of the factors that contribute towards the user risk score.