Alerting & Integration
The NFO DDoS Detector transforms passive monitoring into an active defense system. By leveraging the Confidence Score assigned to every event, you can automate your response to threats and ensure high-confidence attacks are acted on before they impact services.
Confidence-Based Alerting Strategy
We recommend a tiered approach to alerting to reduce noise in your SOC:
- High confidence (90–100%): Trigger immediate automated actions. Multiple Experts have confirmed an attack. Integration with a SOAR platform or firewall API is recommended at this tier
- Medium confidence (50–89%): Generate a ticket (for example in ServiceNow or Jira). These events represent significant anomalies that require a human analyst to determine whether the cause is a flash crowd or a sophisticated attack
- Low confidence (< 50%): Log for historical analysis only. No active notification required