Numbers you can re-derive
The product's central promise is a number. So the measurement code ships with the platform, and this page also says what the result does not prove.
Definitions first
No attack event in its evidence
An alert is false if none of the events in its evidence is labelled as an attack.
False ÷ all alerts
The same measure as the industry figure, “40% or more of alerts are false”: alerts an analyst had to look at.
An attack with no alert at all
A labelled attack that produced no alert.
The same detectors without context or linking
One alert per signal, deduplicated by rule and host per minute. What is compared is the architecture, not the rule set.
An attack-free period is replayed first so the platform can learn what normal looks like. Nothing raised during it is counted, for either approach.
CICIDS2017: 2.2 million network flows
Network flows from the Canadian Institute for Cybersecurity, with the corrected KU Leuven labels (Engelen, Rimmer, Joosen, IEEE CNS 2022). Neither the data nor the labels are ours. About 550,000 flows a day.
| Day | SENTINEL AI: alerts | SENTINEL AI: false | Conventional: alerts | Conventional: false |
|---|---|---|---|---|
| Tuesday | 2 | 0% | 210 | 41.9% |
| Wednesday | 1 | 0% | 63 | 38.1% |
| Thursday | 2 | 0% | 71 | 49.3% |
| Friday | 4 | 0% | 85 | 48.2% |
| Four days | 9 | 0% | 429 | 43.8% |
Found
- FTP-Patator
- SSH-Patator
- PortScan
- DDoS
- Botnet
- DoS Slowloris
- DoS GoldenEye
- DoS Hulk
- DoS Slowhttptest
- Infiltration-PortScan
Not found
- Heartbleed
- Web attacks: brute force, XSS, SQL injection
- Infiltration
Why they were missed
This dataset holds only flow statistics: packet and byte counts, timings, TCP flags. No HTTP request lines, no TLS records, no process data. SQL injection and XSS live in the request body: the platform recognises them, but it needs the web server or WAF log. A rule that guessed Heartbleed from the shape of a flow fired on every ordinary HTTPS download, so it was removed rather than shipped.
Hard legitimate traffic
A model public agency: domain controllers, file and database servers, a portal, backup, a vulnerability scanner, 36 workstations, 35 accounts. Eight labelled attack scenarios are woven into a working day.
What this does not prove
The legitimate noise comes from a fixed catalogue of about ten patterns, and the detectors and the data were written by the same author. It is a floor check: the platform survives the noise that breaks conventional tools. That is why the independent data above exists.
What one server takes
Five minutes, 16 concurrent collectors, batches of 200 events, telemetry shaped like a real Windows estate, 2% of it shaped like an intrusion so the linking and scoring layers do real work.
AMD Ryzen 7 7435HS, 8 cores, 16 GB, NVMe, SQLite in WAL mode. The load generator ran on the same machine and took processor time from the platform, so these figures are a floor.
What the result does not say
Nine alerts is a small sample
A single mistake would have moved the false alarm rate to 10%. The result shows the architecture does not generate routine noise; it does not pin the rate down precisely. A longer deployment on live traffic will.
Recall on this data is incomplete
Some attacks were not found, and they are exactly the ones whose evidence is absent from network flows. Read the false alarm rate as strong and the recall on this dataset as incomplete.
The platform sees only what it is sent
An attack that leaves no trace in the connected telemetry will not be found. That is why a pilot starts by choosing the sources.
One author wrote the model and the detectors
Hence the identical results across runs. It is an argument for independent data, and for a pilot on yours.
Defects we fixed
Each was found by running against real data, not by reading code. Here are the three most telling.
One cause was counted four times
“This is a helpdesk technician” explained four observations but was added up as four discoveries. It was the largest source of false alarms on routine IT work. Evidence sharing an explanation is now counted once.
The engine slowed down when the attack was loudest
A port scan put thousands of signals into one case, and the case was re-scored on each one. Throughput fell from 20,000 to 180 events a second. Fixed.
A rule was removed, not shipped
A detector that fired on every HTTPS file download warned nobody about anything. It taught analysts to stop reading alerts.
The commands to repeat every measurement ship with the product.
Test it on your own data
A pilot runs on one server inside your network. You see what the platform finds there, and how many alerts stop reaching your analysts.
Request a pilot →