Product
Behavioural Baseline Engine
Valystrum’s Behavioural Baseline Engine learns what “normal” looks like for every asset, metric, and relationship in your environment. By establishing statistical baselines and propagating anomalies through the security graph, Valystrum detects subtle threats that rule-based systems miss, reducing false positives and surfacing genuine risks.
behavioural baselineanomaly detectionemasecurity analyticsvalystrum
Key Features
- EMA per Asset-Metric: Exponential moving average (EMA) models for every asset and metric, capturing normal behaviour over time.
- Anomaly Propagation: Detected anomalies are propagated through the graph, identifying compound risks and correlated events.
- Real-Time Scoring: Every new observation is scored against the baseline, with configurable thresholds for alerting.
- Contextual Adjustments: Scores are adjusted for contextual factors (e.g., maintenance windows, known changes) to reduce noise.
- Dual Time-Horizon Modelling: Short-term and long-term baselines detect both sudden and gradual behavioural shifts.
Competitive Differentiators
- Graph-Based Propagation: Anomalies are not isolated, they propagate through the living graph, surfacing compound risks.
- Entity-Specific Baselines: Models are tailored to each asset, route, and identity, not just global thresholds.
- Context-Aware Scoring: Adjusts for external factors, reducing alert fatigue.
- Continuous Learning: Baselines self-update as environments evolve, ensuring ongoing accuracy.
See how it works against your estate.
A 30-minute walkthrough against a sandbox of your scale, with one of our governance engineers.
Related