ArticleslgStudy

science

User activity monitoring

User activity monitoring is a science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand User activity monitoring rather than just read about it. In short: In the field of information security, user activity monitoring (UAM) or user activity analysis (UAA) is the monitoring and recording of user actions. UAM captures user actions, including the use of applications, windows opened, system commands executed, checkboxes clicked, text entered/edited, URLs visited and nearly every other on-screen event to protect data by ensuring that employees and contractors are staying w…

Key takeaways

  • User activity monitoring belongs to science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect User activity monitoring to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of User activity monitoring from memory before moving on to harder problems.

Reference excerpt

In the field of information security, user activity monitoring (UAM) or user activity analysis (UAA) is the monitoring and recording of user actions. UAM captures user actions, including the use of applications, windows opened, system commands executed, checkboxes clicked, text entered/edited, URLs visited and nearly every other on-screen event to protect data by ensuring that employees and contractors are staying within their assigned tasks, and posing no risk to the organization. User activity monitoring software can deliver video-like playback of user activity and process the videos into user activity logs that keep step-by-step records of user actions that can be searched and analyzed to investigate any out-of-scope activities.

Background The need for UAM rose due to the increase in security incidents that directly or indirectly involve user credentials, exposing company information or sensitive files. In 2014, there were 761 data breaches in the United States, resulting in over 83 million exposed customer and employee records. With 76% of these breaches resulting from weak or exploited user credentials, UAM has become a significant component of IT infrastructure. The main populations of users that UAM aims to mitigate risks with are:

Contractors Contractors are used in organizations to complete information technology operational tasks. Remote vendors that have access to company data are risks. Even with no malicious intent, an external user like a contractor is a major security liability.

Users 70% of regular business users admitted to having access to more data than necessary. Generalized accounts give regular business users access to classified company data. This makes insider threats a reality for any business that uses generalized accounts.

IT users Administrator accounts are heavily monitored due to the high-profile nature of their access. However, current log tools can generate “log fatigue” on these admin accounts. Log fatigue is the overwhelming sensation of trying to handle a vast amount of logs on an account as a result of too many user actions. Harmful user actions can easily be overlooked with thousands of user actions being compiled every day.

Overall risk According to the Verizon Data Breach Incident Report, “The first step in protecting your data is in knowing where it is and who has access to it.”

Components Most companies that use UAM usually separate the necessary aspects of UAM into three major components.

Visual forensics Visual forensics involves creating a visual summary of potentially hazardous user activity. Each user action is logged, and recorded. Once a user session is completed, UAM has created both a written record and a visual record, whether it be screen captures or video of exactly what a user has done. This written record differs from that of a SIEM or logging tool, because it captures data at a user-level not at a system level –providing plain English logs rather than SysLogs (originally created for debugging purposes). These textual logs are paired with the corresponding screen-captures or video summaries. Using these corresponding logs and images, the visual forensics component of UAM allows for organizations to search for exact user actions in case of a security incident. In the case of a security threat, i.e. a data breach, Visual forensics are used to show exactly what a user did, and everything leading up to the incident. Visual Forensics can also be used to provide evidence to any law enforcement that investigate the intrusion.

User activity alerting User activity alerting serves the purpose of notifying whoever operates the UAM solution to a mishap or misstep concerning company information. Real-time alerting enables the console administrator to be notified the moment an error or intrusion occurs. Alerts are aggregated for each user to provide a user risk profile and threat ranking. Alerting is customizable based on combinations of users, actions, time, location, and access method. Alerts can be triggered simply such as opening an application, or entering a certain keyword or web address. Alerts can also be customized based on user actions within an application, such as deleting or creating a user and executing specific commands.

User behavior analytics User behavior analytics add an additional layer of protection that will help security professionals keep an eye on the weakest link in the chain. By monitoring user behavior, with the help of dedicated software that analyzes exactly what the user does during their session, security professionals can attach a risk factor to the specific users and/or groups, and immediately be alerted with a red flag warning when a high-risk user does something that can be interpreted as a high-risk action such as exporting confidential customer information, performing large database queries that are out of the scope of their role, accessing resources that they shouldn't be accessing and so forth.

Features

Capturing activity UAM collects user data by recording activity by every user on applications, web pages and internal systems and databases. UAM spans all access levels and access strategies (RDP, SSH, Telnet, ICA, direct console login, etc.). Some UAM solutions pair with Citrix and VMware environments.

User activity logs UAM solutions transcribe all documented activities into user activity logs. UAM logs match up with video-playbacks of concurrent actions. Some examples of items logged are names of applications run, titles of pages opened, URLs, text (typed, edited, copied/pasted), commands, and scripts.

Video-like playback UAM uses screen recording technology that captures individual user actions. Each video-like playback is saved and accompanied by a user activity log. Playbacks differ from traditional video playback to screen scraping, which is the compiling of sequential screen shots into a video-like replay. The user activity logs combined with the video-like playback provides a searchable summary of all user actions. This enables companies to not only read, but also view exactly what a particular user did on company systems.

… excerpt ends here. Continue reading the full article.

Worked examples

Example 1 — a first encounter with User activity monitoring

Start with the simplest possible case. Write down what User activity monitoring claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to User activity monitoring before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about User activity monitoring ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of User activity monitoring

In research
User activity monitoring appears in science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses User activity monitoring in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
User activity monitoring is common in secondary-school and first-year university syllabi. It links to neighbouring topics Crime prevention, Data security, National security, so understanding it makes those chapters shorter.
In everyday life
Look for User activity monitoring outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.
Ask Teacher Smith questions about this articleOpens your AI tutor with a question about “User activity monitoring” →

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study User activity monitoring in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what User activity monitoring means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain User activity monitoring out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is User activity monitoring in simple terms?

In the field of information security, user activity monitoring (UAM) or user activity analysis (UAA) is the monitoring and recording of user actions. UAM captures user actions, including the use of applications, windows opened, system commands executed, checkboxes clicked, text entered/edited, URLs…

Why does User activity monitoring matter?

Because it connects several science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study User activity monitoring?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on User activity monitoring.

Tags

  • Crime prevention
  • Data security
  • National security
  • Online analytical processing
  • Regulatory compliance
  • Secure communication
  • Social information processing

Keep exploring