Learn about user activity detection in NetApp Ransomware Resilience
User activity detection in NetApp Ransomware Resilience helps you identify and stop suspicious user behavior, including data breaches and large-scale deletions.
NetApp Ransomware Resilience provides AI-driven detection that monitors for suspicious user behavior. Sharp increases in read activity or unusual access patterns can indicate malicious intent. Once detected, Ransomware Resilience automatically generates alerts in the NetApp Console, by email, and in configured security ecosystems such as SIEM.
With user behavior detection and alerting, Ransomware Resilience alerts you to suspicious patterns and to data breach and data destruction attempts. In each alert, Ransomware Resilience identifies a user whom you can block.
Ransomware Resilience detects suspicious user activity by analyzing user activity events generated by FPolicy in ONTAP. To collect user activity data, you need to deploy one or more user activity agents. A user activity agent is a Linux server or VM with connectivity to devices in your tenant.
|
|
User activity detection is currently not supported for SAN workloads. You can use user activity detection with NAS workloads in Amazon FSx for NetApp ONTAP, Cloud Volumes ONTAP, and ONTAP. |
User activity forensics
Ransomware Resilience offers forensics for user behaviors: lists and graphs that show when suspicious activity occurred and when notifications were sent out. These detail the frequency of suspicious activity on files, directories, volumes, and workloads over time to help chart the events. You can also observe the appearance of new file extensions.
.
You can compare suspicious activity with a view of all activity. In the all activity view, you can observe read, write, rename, move, create, and delete events in addition to access change and access denied events.
.
Components
There are three key components in Ransomware Resilience user behavior detection.
-
The user activity agent is an executable environment for data collectors. You must configure the user activity agent.
-
The data collector shares user activity events with Ransomware Resilience. The data collector is created automatically when you enable a ransomware protection strategy with user behavior detection.
-
The user directory connector enables mapping between usernames and user IDs, creating greater clarity when responding to suspicious user behavior. You must configure the user directory connector.
Ransomware Resilience and Data Infrastructure Insights
Ransomware Resilience's user behavior detection is an integration with Data Infrastructure Insights (DII) Workload Security and uses DII endpoints. You don't need any DII configuration to enable user behavior detection in Ransomware Resilience. To enable user behavior detection, create the required agent and collectors and enable the appropriate ransomware protection strategy.
If you're already using NetApp Data Infrastructure Insights (DII) Workload Security, use the same Workload Security agents for Ransomware Resilience. You don't need to deploy separate Workload Security agents for Ransomware Resilience. However, using the same Workload Security agents requires a pairing relationship between the Ransomware Resilience Console organization and the DII Storage Workload Security tenant. Contact your account representative to enable this pairing.