You can configure baseline learning to obtain the baseline values of the services of the Zone by learning cycle and generate learning results based on the learning task.
The basic policies of the Zone have been configured and deployed on the associated devices. For details, see Configuring a Defense Mode.
Devices associated with the Zone have been bound to collectors. For details, see Associating the Collector with the devices.
Current Threshold indicates the current threshold of a policy; Baseline indicates the traffic volume learned using baseline learning; Suggestion indicates the recommended threshold calculated based on the current threshold and baseline. The recommended threshold changes to the current threshold once being delivered to the device. The recommended threshold is calculated as follows:
When the defense threshold is configured: recommended threshold = current threshold x current threshold weight + (baseline value x tolerance value) x (1 - current threshold weight)
When the defense threshold is not configured: recommended threshold = baseline value x tolerance value
Baseline packet rate < 5000 pps, baseline bandwidth < 20 Mbit/s, or baseline connection count < 5000: tolerance value = 200%
5000 pps ≤ baseline packet rate < 30,000 pps, 20 Mbit/s ≤ baseline bandwidth < 100 Mbit/s, or 5000 ≤ baseline connection count < 30,000: tolerance value = 180%
30,000 pps ≤ baseline packet rate < 100,000 pps, 100 Mbit/s ≤ baseline bandwidth < 300 Mbit/s, or 30,000 ≤ baseline connection count < 100,000: tolerance value = 160%
100,000 pps ≤ baseline packet rate < 300,000 pps, 300 Mbit/s ≤ baseline bandwidth < 1 Gbit/s, or 100,000 ≤ baseline connection count < 300,000: tolerance value = 140%
300,000 pps ≤ baseline packet rate < 12,000,000 pps, 1 Gbit/s ≤ baseline bandwidth < 10 Gbit/s, or 300,000 ≤ baseline connection count < 12,000,000: tolerance value = 120%
False positive occurs due to the threshold that is too low. Therefore, set the packet rate, bandwidth value, and connection count to 500 pps, 5 Mbit/s, and 500 respectively, when their recommended values are smaller than given values.
| Parameter | Description |
|---|---|
Name |
Indicates the name of a baseline learning task. |
Learning Cycle (Days) |
Indicates the learning cycle of a baseline learning task. After a task starts, the learning result is updated every 5 minutes. The learning result is applied to the defense policy only after such a learning cycle ends. |
Current Threshold Weight |
Indicates the proportion of the current value to all recommended values in this calculation. |
Start Time |
Indicates the start time of a baseline learning task, which falls into NowTime and DefineTime.
|
End Time |
Indicates the end time of a baseline learning task, which falls into ManualStop and DefineTime.
NOTE:
If End Time is later than Learning Cycle, after a learning period ends, the device automatically enters the next learning period till End Time. |
Take effect automatically |
|
If a service is created, the traffic that matches the service is separately learned, and the traffic that does not match the service are to be learned as a whole. The learning results are applied to the defense policies of the created service and the default defense policies. If no service is created, all traffic is learned as a whole and the learning result is applied to the default defense policy.
The NFA2000V does not support service or baseline learning.
After baseline learning is enabled, click Stop to stop baseline learning.
To modify the parameters of the learning task, stop baseline learning first.
When the baseline learning periods of multiple Zones are set to be the same, select all Zones that need to have baseline learning enabled and click
to set baseline learning in batches. For the parameter
description, see Table 2.
| Parameter | Description |
|---|---|
The total number of selected Zone |
Indicates the number of all Zones that need to have baseline learning enabled. |
The total number of enabled baseline learning task |
Indicates the number of Zones that already have baseline learning enabled. |
Start Time |
Indicates the start time of a baseline learning task. |
End Time |
Indicates the end time of a baseline learning task. |
Learning Cycle (Days) |
Indicates the learning cycle of a baseline learning task. After a task starts, the learning result is updated every 5 minutes. The learning result is applied to the defense policy only after such a learning cycle ends. |
Current Threshold Weight |
Indicates the proportion of the current value to all recommended values in this calculation. |
Take effect automatically |
|
Stop enabled baseline learning task |
Terminates enabled baseline learning tasks. |
Manual apply suggestion |
Applies baseline learning results to defense policies.
|
Before the first learning cycle ends, baseline learning result from the start time to the current time is displayed. After the first learning period elapses, baseline traffic learning result of the last learning cycle is displayed.
in the Detail column to view the historical traffic curve for baseline learning in the last year and change Current Threshold.After Take effect automatically and Always Effective are selected in a baseline learning task, the system automatically applies the recommended values to defense policies after the baseline learning period ends.
The baseline learning result takes effect only after the corresponding defense item is enabled in defense policies.
When the confirmation mode of baseline learning is automatic, service traffic learning result is automatically applied to the defense policy of the Zone and deployed on devices.
When the automatic confirmation mode is not selected for baseline learning, service traffic learning result needs to be confirmed manually. For details, see Applying Baseline Learning Results.