Kaspersky Machine Learning for Anomaly Detection

About incidents detected by an ML model element based on a diagnostic rule

An ML model can include one or more elements based on diagnostic rules. Each diagnostic rule results in the following values being obtained that are calculated at each point in time:

  • Value 0. The diagnostic rule was not triggered or applied at this moment.
  • Value 1. The diagnostic rule was triggered at this moment.
  • Intermediate values from 0 to 1 are possible in individual cases. The diagnostic rule was partially triggered at this moment.

Once the result surpasses the threshold set for the diagnostic rule, which is generally equal to one, the element based on the diagnostic rule records an event. For each incident registered by the diagnostic rule, Kaspersky MLAD automatically creates a Tags for incident #<incident ID> preset. This preset can be selected under History when you click the incident date and time in the incidents table. This preset contains the value obtained as a result of the work of the diagnostic rule, as well as the tags included in this rule.