The policy violation detection engine
Any deviation from the learned baseline behavior or configured baseline behavior is detected by MDIoT and alerted on. In Figure 8.3, the Unauthorized Internet Connectivity Detected alert is seen, and from the name itself, we can understand that it is a breach of the baseline behavior, as the source is not authorized to communicate with the internet address:
Figure 8.3 – Example of a policy violation
We will learn more about the structure of the alerts and their components in detail in Chapter 9.