Under the hood
Most solutions rely on a single model, and that model either misses too many threats or raises too many false alarms. BALLA takes the opposite stance: a stack of specialised, complementary layers, where each has one responsibility, defined interfaces, and covers the others' blind spots. It is this depth of defence that simultaneously reduces missed threats and false alarms.
Online, signature-free learning that spots statistical deviation the instant it happens. The first line of defence against the unknown.
Compares each activity to the machine's and role's own profile, calibrated over 14 days. A server's normal is not a designer's.
Reads the chain of actions and catches the abuse of trusted tools, like Word spawning PowerShell to download a payload.
Trained on analyst corrections, it separates true threats from unusual-but-legitimate behaviour, and sharpens with every use.
Picks the best response under strict guardrails, never on critical systems without sign-off. Driven by reinforcement learning, it improves with every incident.
Unlike an impossible-to-understand black box, BALLA justifies every decision: the XAI / SHAP method shows exactly which factors weighed in, and by how much. This transparency matters on two counts, team trust, since they see why an alert was raised, and GDPR compliance (Article 22) on automated decisions.
Attack reconstruction
An attack is almost never an isolated event, but a sequence. BALLA reconstructs it end-to-end and, with BALLA-LLM, reveals in plain language the MITRE ATT&CK techniques used.
Which program launched which other, the causal root of the chain.
Same file, same address, same fingerprint across several endpoints.
Consistency with the logical flow of an attack per ATT&CK.
“A phishing email delivered an encoded PowerShell script that dumped credentials, spread over SMB to 3 endpoints, opened a command-and-control beacon, then triggered encryption. A typical human-operated ransomware pattern.”
Progression along MITRE ATT&CK
BALLA-LLM highlights the ATT&CK techniques that recur most across incidents, to anticipate the likely next move.
Performance
In cybersecurity, speed isn't a luxury: it's the difference between blocking an attack and suffering it. Here are the production targets we aim for and measure continuously, from decision time to false-alarm rate.