ResearchJuly 18, 20266 min readSISKO Research
Detecting the unknown: anomaly over signature
The vast majority of security tools rely on signatures: a constantly updated database of known threats. The problem is structural, against a new, targeted or slightly modified attack, they are blind.
BALLA flips the problem. Instead of learning what a threat looks like, it learns what normal looks like for each machine: which programs run, at what hours, towards which networks, in what sequences. Any significant deviation becomes a signal.
This shift, from signature to anomaly, is what makes it possible to catch an attack even without having seen it before. It also makes detection personal: a server's normal is not a designer workstation's normal.