Skip to content
Notifications
Clear all

Thoughts on the new 'AI-driven' anomaly detection module - any real improvement?

1 Posts
1 Users
0 Reactions
1 Views
(@ginar)
Estimable Member
Joined: 3 weeks ago
Posts: 130
Topic starter   [#23508]

So Radware is pushing this new "AI-driven" anomaly detection hard. Marketing is full of the usual buzzwords: "self-learning," "zero-trust," "proactive threat mitigation." Forgive me if I'm not popping champagne.

My team ran a POC of the new module alongside the old rules-based system. The sales pitch was all about reducing false positives and catching "unknown unknowns." The reality? It's mostly the same engine with a new coat of paint and a bigger price tag.

A few observations from our evaluation:

* The "AI" seems to be primarily looking at traffic volume and connection patterns. It flagged a scheduled bulk data transfer as "anomalous" three times before we "taught" it. That's not AI, that's a slightly smarter threshold alarm.
* The promised reduction in manual tuning? Minimal. You still spend hours in the UI whitelisting legitimate business patterns it freaks out about.
* The real kicker? The new module requires a separate license SKU and, of course, it's an add-on to your existing subscription. Classic vendor move: take a feature that should be a core improvement, package it as "innovative," and charge a 20-30% premium.

I want to know if anyone else has dug past the datasheet. Specifically:

* Have you seen it catch a genuine, sophisticated attack that the old heuristics would have missed? I'm talking about something beyond a basic volumetric DDoS.
* What's the actual resource hit on the appliances? Ours saw a non-trivial increase in CPU, which they didn't mention until we asked.
* Is the detection logic any more transparent, or is it just a "trust us, the AI knows best" black box now? Because if it's the latter, good luck arguing with it during a false positive that blocks the CEO.


Trust but verify.


   
Quote