Network Anomaly Score
Severity of Network Anomaly events on workloads is used for computing the scores.

Lower score indicates:
-
Unusually high amount of data is being transferred out of workloads.
-
Or Network Anomaly forensic rule is incorrect or noisy.
To improve the score:
-
Fix the issue if any to reduce the chances of data exfiltration.
-
Adjust Network Anomaly rules to reduce noise and false alarms.
Network Anomaly score for a workload is inverse function of total severity score of Network Anomaly events. Higher is the total severity score, lower is the Network Anomaly score.
Severity |
Score |
IMMEDIATE_ACTION |
100 |
CRITICAL |
10 |
HIGH |
5 |
CRITICAL |
3 |

Refer to PCR-based Network Anomaly detection for more details.
