Kaspersky Machine Learning for Anomaly Detection

About elements of an ML model based on a diagnostic rule

Diagnostic rules describe previously known behavioral traits of the monitored asset that are considered anomalies. Diagnostic rules must be formalized and calculated based on available telemetry data for the object.

Examples of diagnostic rules:

  • The level of tag A has changed abruptly (criterion for the behavior of the Step change tag).
  • Over the past 12 hours, tag B has trended upward, tag C has trended downward, and tag D has not shown any clear dynamics.
  • The value of tag X fell below 2800 after it previously rose higher than 2900.