SecuReporter - Device Health Anomaly Detection

Options
Zyxel_Claudia
Zyxel_Claudia Posts: 254 image  Zyxel Employee
Network Detective-New Adventure Badge Network Detective Badge First Comment Friend Collector
edited February 3 in Other Topics

What Is Device Health Anomaly Detection?

SecuReporter Device Health Anomaly Detection uses AI analysis to monitor and assess the operational health of your firewall. By comparing CPU usage, memory usage, and session usage against a baseline built from the previous week's data, it can detect unusual patterns that may indicate underlying issues or threats.

image.png

Key Benefits:

  • Automated AI Analysis: The system learns from at least 3 days of historical usage to set a behavioral baseline.
  • Proactive Alerts: It detects deviations from the norm and provides a detailed summary and recommended actions.
  • Performance Optimization: Helps administrators resolve potential performance issues before they escalate.

How It Works

  • Data Collection: After three days of operational data, the system begins training its model.
  • Hourly Checks: Every hour, it analyzes current usage patterns against the learned baseline.
  • Metric Comparison: The focus is on key health indicators: CPU, memory, and session usage.

When anomalies are detected—such as a sudden spike in memory usage—the system flags the incident and provides administrators with a quick overview and actionable guidance.

Sensitivity Levels You Can Control

To ensure flexibility, administrators can adjust anomaly sensitivity based on their needs:

image.png

Example: CPU Usage AI Analysis

image.png

Event Timeline

image.png

Insufficient Baseline Data

image.png