Software Secure Workload
Activity Configure

Rule Severities and Network Anomaly Scores

The Network Anomaly Score is computed similarly to the Forensics Score. For each Workload we compute a Network Anomaly Score. The Network Anomaly Score of a Workload is derived from the Network Anomaly Events observed on that Workload based on the profiles that are enabled for this scope. A score of 100 means no Network Anomaly Events were observed via configured rules in enabled profiles. A score of 0 means there is a Network Anomaly Event detected that requires immediate action.

  • A Network Anomaly Event with the severity REQUIRES IMMEDIATE ACTION reduces the Score for the entire Scope to 0.

  • A Network Anomaly Event with the severity CRITICAL reduces workload’s score with the impact of 10.

  • A Network Anomaly Event with the severity HIGH reduces workload’s score with the impact of 5.

  • A Network Anomaly Event with the severity MEDIUM reduces workload’s score with the impact of 3.

  • A Network Anomaly Event with the severity LOW doesn’t contribute to the Network Anomaly Score. This is recommended for new rules where the quality of the signal is still being tuned and is likely to be noisy.

For each workload, the total impact score is aggregated every 5 minutes to compute the score of that workload within those 5 minutes.

For workloads without Network Anomaly enabled sensor types, the Network Anomaly scores are N/A.