Airlock Anomaly Shield Quick Start
The Quick Start provides a fast and guided way to set up and evaluate Airlock Anomaly Shield. It operates in log-only mode, allowing safe validation without impacting traffic.
Using the Quick Start
Quick Start prerequisites
- The Quick Start will only be shown if no AS applications are configured.
Use the Quick Start
- go to:
Application Firewall >> Anomaly Shield - Follow the instructions on the screen.
Next Steps
- The Log Viewer provides a GATEWAY Anomaly Shield dashboard that visualizes the activity of Anomaly Shield and its detection capabilities.
- The Quick Start configures all AS applications with data collection, detection and response and automated retraining.
- After 35 days, the Anomaly Shield will automatically retrain and activate all models. You should see a considerable increase in detection capabilities with these models.
- It is possible to modify the configuration created by Quick Start. See Airlock Anomaly Shield configuration for an overview of the manual configuration.
- Quick Start will work without a license in log-only mode. Enabling Anomaly Shield to execute actions requires a license.
Known limitations
To achieve the desired speed and ease of use, some trade-off had to be accepted as follows:
- Quick Start is designed for rapid initial setup and evaluation. It is not intended for configuring complex or production-specific scenarios.
- Effective model training requires at least 35 days of data. Initial models trained with limited data provide reduced accuracy but are automatically improved through retraining.
- Quick Start selects a limited set of mappings based on heuristics and does not support complex configurations (e.g. multiple mappings per application).
- Default triggers and rules are used and may be adjusted manually for advanced use cases.
Further information and links
- For a general introduction, see: Airlock Anomaly Shield
- For information about the manual configuration see Airlock Anomaly Shield configuration.
- For a brief example of setup, usage and operation, see: Logs, tuning and advanced configuration