You set one IDS scan-signature threshold estate-wide — why does that hide an intruder on your noisiest segment?
answer
- the number means nothing without a baseline
- segments differ by orders of magnitude
- one value is wrong in one of two directions
- widest margin sits under the loudest segment
- stale thresholds still look healthy
basics
~10 sA threshold is a number relative to a baseline, and campus segments differ by orders of magnitude. One value high enough to survive the noisiest segment sets a bar an intruder simply stays under.
solid answer
~50 sThresholds only mean anything relative to what a segment normally does. A test lab and a print VLAN generate wildly different volumes of the same scan-like behaviour, so a single estate-wide number can only be wrong in one of two directions: set low enough to catch the quiet segments and the lab floods you; set high enough to survive the lab and you have published a speed limit that hides anyone patient, on every segment, and the margin is widest on the loud ones. Per-segment thresholds fix the arithmetic and buy a maintenance bill: a value per segment, each with a baseline that was true on the day it was measured, each needing re-measurement when a lab is rebuilt or a range is re-purposed for lecture-theatre wireless. Unowned per-segment values rot exactly like unowned suppressions — the difference is that a stale threshold looks healthy, because alerts are still arriving.
go deeper
Know that a detection threshold is a number relative to what is normal for a place, and that a print VLAN and a test lab are not normal in the same way.
Explain both failure directions of a single global value — flooding the noisy segment or setting an estate-wide bar an adversary stays under — and where the margin is widest.
Show how you would measure baselines per segment, what compensating visibility you keep where the bar has to be high, and how you keep several numbers honest without them silently going stale.
Be ready to argue for a small number of defensible tiers over per-VLAN precision nobody maintains, and to say who owns re-measurement when the estate changes shape.
## A threshold is a claim about a baseline Any numeric tuning on a sensor — "alert only after twenty of these in a minute" — encodes an assumption: *normal here is below twenty*. That assumption is local. On a campus, the segments behind the wiring closets do not resemble each other at all. A print VLAN sees a handful of predictable flows. A test lab spends its day doing things that look, to a scan signature, exactly like reconnaissance. A lecture theatre is empty for eight weeks and then hosts four hundred devices at once. A single number cannot be simultaneously true about all of them. ## Which way it fails Set the number low enough to be meaningful on the quiet segments, and the lab produces a flood. The flood is what triggers the next mistake: someone widens a suppression, and now the whole thing is invisible rather than merely loud. Set it high enough to survive the lab, and you have made an estate-wide announcement about how much activity is free. An adversary does not need to know the number to benefit from it; anyone working slowly is under it. Worse, the margin between the bar and a given segment's real baseline is *largest on the noisy segments* — the lab has a high bar and, if the intruder is standing on a quiet host inside the lab range, a great deal of room beneath it. The place with the most tolerance is the place with the least scrutiny. ## What per-segment tuning actually buys and costs Moving to per-segment values makes each number a claim about a place you can defend: | Segment | Normal for a scan-like signature | A defensible threshold | | --- | --- | --- | | print VLAN | near zero | very low; almost anything is interesting | | test lab | continuous, high | high, and paired with a compensating view | | lecture theatre | zero, then bursty on the hour | low, with the burst window understood | | scanner source | enormous, weekly | scoped exception, not a global number | The cost is real and it is the reason people avoid it. You now own a set of numbers rather than one. Each was measured against a baseline that was true on a particular day. Baselines move for entirely non-security reasons: the lab is rebuilt, the print range is re-purposed for wireless clients, a new building comes online, the weekly scan changes its schedule. Nothing in the sensor announces that a baseline has drifted. And the failure mode of a stale threshold is quieter than the failure mode of a stale suppression. A suppression at least declares itself as an exception in a file. A threshold that has drifted out of usefulness still produces alerts, so the dashboard looks alive while the number underneath it no longer means what its author intended. ## Holding it honestly A few practices make this survivable rather than an ever-growing spreadsheet: - **Name a segment owner, not a value owner.** The person who can tell you the lab's baseline changed is the person who rebuilt the lab. Tie the threshold to that relationship. - **Give every number a measured origin.** Record what the baseline was, when it was measured, and over what window. A number without a provenance cannot be re-argued, only inherited. - **Set a re-measure trigger, not only a date.** Address-plan changes, new buildings and re-purposed ranges should force a review whether or not the calendar says so. - **Keep a compensating view on the segments with the highest bars.** If the lab has to tolerate a lot, keep its raw matches somewhere at lower severity so the tolerance is recoverable when you need to look backwards. - **Prefer fewer, coarser tiers over per-VLAN artistry.** Three defensible tiers that people maintain beat forty precise numbers nobody re-measures. ## The line to hold in an interview The wrong answer is "we raised the threshold until the noise stopped". That sentence describes buying quiet with coverage at an unknown exchange rate, estate-wide, in one move. The right answer says what the number is relative to, where that relationship is different, and what it costs — in review time and in ownership — to keep several numbers honest instead of one dishonest one.
- How do you set the first per-segment number without weeks of baselining?Run the signature in a non-acting, observe-only mode for a representative period per segment — including the weekly scan window and, for a lecture theatre, a term week — and take the numbers from that. Publish them as provisional with a re-measure date. A provisional number with a measured origin beats a confident number with none.
- A lab is rebuilt and its traffic profile changes completely. What tells you the threshold is now wrong?Nothing, unless you arranged for it. That is why the review trigger should be the change itself — address-plan and segment changes force a re-measure — and why keeping the discarded counts visible matters: a sudden change in how much a threshold is absorbing is the signal that its baseline moved.
- Why not just suppress the scan signature on the lab segment entirely?Because the lab is a segment an intruder would happily work from, and a suppression there leaves no residue at all. If the lab genuinely cannot carry the signature, keep the matches at reduced severity or on a sensor without the exception, so the tolerance is recoverable rather than a hole.
saying these in an interview costs you the question
- Raises the threshold until the noise stops
- Treats one estate-wide number as a neutral default
- Cannot say what baseline the number was measured against
- Assumes alerts arriving means the tuning is still valid
- Adds per-segment values with no re-measure trigger