科研速览 · Science Skim继续刷下去 · Keep skimming →
2026-07-31· Anomaly detection

Detection Engineering and Anomaly Detection

Jason Edwards

原始摘要(英文原文)· Original abstract
This chapter presents detection engineering as a managed capability built for reliability, accountability, and measurable outcomes rather than rule volume. It explains how effective detections start with real threat behaviors and translate those behaviors into observable signals grounded in dependable telemetry. Readers will learn how correlation and context transform isolated events into actionable alerts that drive consistent triage decisions under real operational constraints. The chapter emphasizes quality over quantity by showing how to tune detections to reduce false positives without creating blind spots. It details practical ways to measure detection quality through responder outcomes, actionability, and telemetry health, including how “unknown” dispositions often reveal missing context or data pipeline issues. It also explains why detection gaps persist and how change-driven breakage quietly erodes monitoring posture when dependencies are not explicitly managed and continuously validated. Finally, the chapter covers anomaly detection and AI/ML as powerful but imperfect tools that must be governed and operationalized. It explains modeling choices, telemetry prerequisites, and the importance of human-in-the-loop approval boundaries, drift management, and explainable output to prevent false confidence and maintain auditability. Documentation and versioning are positioned as essential practices that make detection logic reviewable, reversible, and defensible during incidents and after-action analysis.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Detection Engineering and Anomaly Detection — 科研速览 Science Skim