Network Detection New Host Access

The Network Detection - New Host Access insight displays anomalies where a device accesses a new host using a suspicious protocol. It helps administrators to reduce noise from single-dimension alerts, identify high-risk behaviors, and take actions to safeguard the network. For each client, the baseline for historical data uploads is first established over a 30-day period. Based on the client-specific baseline, this feature automatically detects and flags abnormally large data uploads. If no anomaly is detected, this insight is not displayed in the Insights page.

To access the insight, complete the following steps:

  1. Access the Insights page. For more information, see Accessing Insights Page.

  2. Click the Network Detection - New Host Access tile.

    Figure 1: Network Detection - New Host Access Insight

    The Network Detection - New Host Access metrics displays the client information where the anomaly was triggered.

  3. Select the client to see more details.

    Figure 2: Behavior Mapping

    In the Behavior Mapping chart, you can view the details of the anomaly. Hover over the chart to see each destination's share of historical traffic and anomalies.

    Note:

    A few destinations are pre-populated for the baseline. The triangle next to the destination denotes the anomaly.

    The Host Access table lists all the anomalies detected for the client. You can view the details of the anomaly:

    • Source Role—Displays the role assigned to the client.

    • Destination—Displays the destination IP address that the source tried to access.

    • Usage—Displays the value of uploaded data.

      Note:

      Only abnormal data with a file size of 10 KB and above will trigger this anomaly.

    • Date—Displays the date when the anomaly was detected.