Behavior Tagging

BAS/CS™ behavior tagging provides broad behavioral groupings to categorize the types of events sensors may generate. This method of event tagging allows for flexibility in sensor capability selection. Vendor proprietary event analytics are mapped to a BAS/CS™ Event (BE) tag, standardizing how correlative analytics can be performed across diverse sensor event data. There are two main BE categories: Host and Network events.

Host Events

Host events focus on the events that would be generated from within a host.

Network Events

Network events focus on events generated from network communications.

Correlation Rules

BAS/CS™ Alerts are defined as a collection of correlations of BE. Each BAS/CS™ Correlation Rule consists of an alert logic statement, which provides the logical relationship between the BE using AND (&&) and OR (||) expressions. Each of these logical expressions are used to query the BE data in a SIEM, and if the logical expression returns TRUE, for the given time range and aggregation field (typically the event source hostname), then an alert is raised.