Skip to content

Commit 72cbd55

Browse files
authored
Merge pull request #291231 from tarTech23/dynlear
Dynamic learning updates
2 parents 639482c + 34b4efa commit 72cbd55

File tree

2 files changed

+50
-28
lines changed

2 files changed

+50
-28
lines changed

articles/defender-for-iot/organizations/how-to-manage-individual-sensors.md

Lines changed: 18 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.topic: how-to
77

88
# Maintain OT network sensors from the sensor console
99

10-
This article describes extra OT sensor maintenance activities that you might perform outside of a larger deployment process.
10+
This article describes extra Operational Technology (OT) sensor maintenance activities that you might perform outside of a larger deployment process.
1111

1212
OT sensors can also be maintained from the OT sensor [CLI](cli-ot-sensor.md) or the [Azure portal](how-to-manage-sensors-on-the-cloud.md).
1313

@@ -17,7 +17,7 @@ OT sensors can also be maintained from the OT sensor [CLI](cli-ot-sensor.md) or
1717

1818
Before performing the procedures in this article, make sure that you have:
1919

20-
- An OT network sensor [installed](ot-deploy/install-software-ot-sensor.md), [configured, and activated](ot-deploy/activate-deploy-sensor.md) and [onboarded](onboard-sensors.md) to Defender for IoT in the Azure portal.
20+
- An OT network sensor [installed](ot-deploy/install-software-ot-sensor.md), [configured, and activated](ot-deploy/activate-deploy-sensor.md) and [onboarded](onboard-sensors.md) to Microsoft Defender for IoT in the Azure portal.
2121

2222
- Access to the OT sensor as an **Admin** user. Selected procedures and CLI access also requires a privileged user. For more information, see [On-premises users and roles for OT monitoring with Defender for IoT](roles-on-premises.md).
2323

@@ -216,31 +216,35 @@ You'd configured your OT sensor network configuring during [installation](ot-dep
216216

217217
1. Select **Save** to save your changes.
218218

219-
### Turn off learning mode manually
219+
## Turn off learning mode manually
220220

221-
A Microsoft Defender for IoT OT network sensor starts monitoring your network automatically as soon as it's connected to your network and you've [signed in](ot-deploy/activate-deploy-sensor.md#sign-in-to-the-sensor-console-and-change-the-default-password). Network devices start appearing in your [device inventory](device-inventory.md), and [alerts](alerts.md) are triggered for any security or operational incidents that occur in your network.
221+
An OT network sensor starts monitoring your network automatically as soon as it connects to your network and you [sign in](ot-deploy/activate-deploy-sensor.md#sign-in-to-the-sensor-console-and-change-the-default-password). Network devices start appearing in your [device inventory](device-inventory.md), and [alerts](alerts.md) are triggered for any security or operational incidents that occur in your network.
222222

223-
Initially, this activity happens in *learning* mode, which instructs your OT sensor to learn your network's usual activity, including the devices and protocols in your network, and the regular file transfers that occur between specific devices. Any regularly detected activity becomes your network's [baseline traffic](ot-deploy/create-learned-baseline.md).
223+
There are three stages to the monitoring process. For more information, see [overview of the multi stage monitoring process](ot-deploy/create-learned-baseline.md).
224224

225-
This procedure describes how to turn off learning mode manually when the current alerts accurately reflect your network activity.
225+
Two to six weeks after deploying your sensor the detection levels should accurately reflect your network activity. At this stage we recommend turning off learning mode.
226226

227227
**To turn off learning mode**:
228228

229229
1. Sign into your OT network sensor and select **System settings > Network monitoring > Detection engines and network modeling**.
230230

231-
1. Toggle off one or both of the following options:
231+
1. In **Network modeling**, toggle off **Learning**.
232232

233-
- **Learning**. Toggle off this option about two-six weeks after you've deployed your sensor, when you feel that the OT sensor detections accurately reflect your network activity.
233+
1. Select **OK** in the confirmation message, and then select **Close** to save your changes.
234234

235-
- **Smart IT Learning**. Keep this option toggled on to keep the number of *nondeterministic* alerts and notifications low.
236-
237-
Nondeterministic behavior includes changes that are the result of normal IT activity, such as DNS and HTTP requests. Toggling off the **Smart IT Learning** option can trigger many false positive policy violation alerts.
235+
Once learning mode is turned off, the sensor starts to generate **Policy Violation** alerts and this setting is now available by selecting **Support** in the side menu. We recommend leaving the mode settings for each alert to automatically update from dynamic to operational. For testing or other reasons, you could manually change the mode setting, however, this isn't recommended as it can produce a large number of alerts.
238236

239-
1. In the confirmation message, select **OK**, and then select **Close** to save your changes.
237+
**Manually change a Policy Violations setting**:
238+
239+
1. In the main sensor menu, select **Support**. The **Engines** table shows the list of all the Defender for IoT alerts.
240+
241+
1. In the **Learning Mode** column, change the mode for any **Policy Violation** alert by selecting **Learning**, **Dynamic** or **Operational** from the dropdown box.
242+
243+
When selecting **Learning**, you must enter the length of time, in hours, to maintain this setting. Select **Submit**.
240244

241245
## Update a sensor's monitoring interfaces (configure ERSPAN)
242246

243-
You may want to change the interfaces used by your sensor to monitor traffic. You originally configured these details as part of your [initial sensor setup](ot-deploy/activate-deploy-sensor.md#define-the-interfaces-you-want-to-monitor), but may need to modify the settings as part of system maintenance, such as configuring ERSPAN monitoring.
247+
You might want to change the interfaces used by your sensor to monitor traffic. You originally configured these details as part of your [initial sensor setup](ot-deploy/activate-deploy-sensor.md#define-the-interfaces-you-want-to-monitor), but might need to modify the settings as part of system maintenance, such as configuring ERSPAN monitoring.
244248

245249
For more information, see [ERSPAN ports](best-practices/traffic-mirroring-methods.md#erspan-ports).
246250

@@ -255,7 +259,7 @@ For more information, see [ERSPAN ports](best-practices/traffic-mirroring-method
255259

256260
- Select the **Enable/Disable** toggle for any interfaces you want the sensor to monitor. You must have at least one interface enabled for each sensor.
257261

258-
If you're not sure about which interface to use, select the :::image type="icon" source="media/install-software-ot-sensor/blink-interface.png" border="false"::: **Blink physical interface LED** button to have the selected port blink on your machine.
262+
If you're not sure about which interface to use, select the :::image type="icon" source="media/install-software-ot-sensor/blink-interface.png" border="false"::: **Blink physical interface LED** button to have the selected port blink on your machine.
259263

260264
> [!TIP]
261265
> We recommend that you optimize performance on your sensor by configuring your settings to monitor only the interfaces that are actively in use.
@@ -274,7 +278,6 @@ For more information, see [ERSPAN ports](best-practices/traffic-mirroring-method
274278

275279
1. Select **Save** to save your changes. Your sensor software restarts to implement your changes.
276280

277-
278281
## Synchronize time zones on an OT sensor
279282

280283
You may want to configure your OT sensor with a specific time zone so that all users see the same times regardless of the user's location.

articles/defender-for-iot/organizations/ot-deploy/create-learned-baseline.md

Lines changed: 32 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -11,34 +11,53 @@ This article is one in a series of articles describing the [deployment path](../
1111

1212
:::image type="content" source="../media/deployment-paths/progress-fine-tuning-ot-monitoring.png" alt-text="Diagram of a progress bar with Fine-tune OT monitoring highlighted." border="false" lightbox="../media/deployment-paths/progress-fine-tuning-ot-monitoring.png":::
1313

14-
## Understand learning mode
14+
## Overview of the multi stage monitoring process
1515

16-
An OT network sensor starts monitoring your network automatically after it's connected to the network and you've [signed in](activate-deploy-sensor.md#sign-in-to-the-sensor-console-and-change-the-default-password). Network devices start appearing in your device inventory, and [alerts](../alerts.md) are triggered for any security or operational incidents that occur in your network.
16+
An OT network sensor starts monitoring your network automatically after it connects to the network and you [sign in](activate-deploy-sensor.md#sign-in-to-the-sensor-console-and-change-the-default-password). Network devices start appearing in your device inventory, and [alerts](../alerts.md) are triggered for any security or operational incidents that occur in your network.
1717

18-
Initially, this activity happens in *learning* mode, which instructs your OT sensor to learn your network's usual activity, including the devices and protocols in your network, and the regular file transfers that occur between specific devices. Any regularly detected activity becomes your network's baseline traffic.
18+
Defender for IoT employs a three stage monitoring process that learns your network's normal traffic behavior. These three stages ensure accurate detection while reducing unnecessary alerts, are:
1919

20-
> [!TIP]
21-
> Use your time in learning mode to triage your alerts and *Learn* those that you want to mark as authorized, expected activity. Learned traffic doesn't generate new alerts the next time the same traffic is detected.
22-
>
23-
> After learning mode is turned off, any activity that differs from your baseline data will trigger an alert.
20+
1. [Learning mode](#learning-mode)
21+
1. [Dynamic mode](#dynamic-mode)
22+
1. [Operational mode](#operational-mode)
2423

25-
For more information, see [Microsoft Defender for IoT alerts](../alerts.md).
24+
### Summary of the monitoring stages
25+
26+
| Mode | Purpose | Trigger alerts | User actions needed |
27+
| --- | --- | --- | --- |
28+
| **[Learning](#learning-mode)** | Builds a baseline of normal network traffic | Malware alerts, anomaly alerts, operational alerts, protocol violation alerts | Turn off manually after 2–6 weeks or when baseline reflects accurate network activity |
29+
| **[Dynamic](#dynamic-mode)** | Refines the baseline while gradually introducing Policy Violations alerts to ensure accuracy and reduce alert noise | Policy Violation alerts are introduced | Optional: Adjust settings for specific scenarios (e.g. during POCs) |
30+
| **[Operational](#operational-mode)** | Monitors all network traffic with a stable baseline, triggering all alerts to reflect deviations or suspicious activity | All types of alerts | None. Automatically transitions when baseline stabilizes |
31+
32+
### Learning mode
33+
34+
Initially, the sensor runs in *learning* mode to monitor all of your network traffic and build a baseline of all normal traffic patterns. This baseline includes all of the devices and protocols in your network, and the regular file transfers that occur between devices. This process normally takes between 2 and 6 weeks, depending on your network size and complexity. Additionally, any devices discovered later enter learning mode for 7 days in order to establish their network traffic baseline.
35+
36+
In learning mode, the sensor monitors and protects your environment by triggering relevant security alerts, such as malware, anomaly and operational alerts. However, Policy Violation alerts, which indicate deviations from the baseline, aren't triggered while the system is in learning mode.
2637

27-
### Learn mode timeline
38+
### Dynamic mode
2839

29-
Creating your baseline of OT alerts can take anywhere from a few days to several weeks, depending on your network size and complexity. We recommend that after 2-6 weeks, you manually change the Learning mode to Dynamic mode when the daily number of alerts decreases to a manageable level. In dynamic mode Defender for IoT continues to monitor the network for suspicious traffic, trigger alerts, and also automatically moves an alert category to operational mode if that alert isn't triggered for a specific length of time.
40+
Once the discovery process and network traffic are stable, you should manually turn off learning mode. At this point, the sensor transitions to dynamic mode. In dynamic mode the sensor continues to monitor your network, validating and refining the baseline. The sensor assesses each alert category and scenario individually, dynamically changing them to operational mode when their baselines are confirmed to be accurate. Alternatively, if the sensor detects significant changes in traffic, it might automatically extend the learning mode for specific alerts or scenarios.
3041

31-
In operational mode all alerts produced are listed in the inventory and must be remediated by following the actions listed in the alert details pane. If the alert was triggered by safe network traffic you'll need to use the **Learn** button to add this traffic to the baseline list so that the sensor doesn't produce an alert for this in the future.
42+
In dynamic mode, Policy Violation alerts are gradually introduced and start to appear in the alert inventory.
43+
44+
### Operational mode
45+
46+
Once the sensor identifies that the baseline is stable and complete it automatically transitions into operational mode, monitoring all of the network traffic and triggering all alert types.
47+
48+
The **Learn** action becomes relevant after learning mode is turned off, when the scenario transitions to operational mode, and you wish to mark specific operations as authorized or expected activity. Once learned, similar activity won't generate new alerts in the future.
3249

3350
[Turn off learning mode manually](../how-to-manage-individual-sensors.md#turn-off-learning-mode-manually) when the level of alerts accurately reflect your network activity.
3451

52+
For more information, see [Microsoft Defender for IoT alerts](../alerts.md).
53+
3554
## Prerequisites
3655

3756
You can perform the procedures in this article from the Azure portal or an OT sensor.
3857

3958
Before you start, make sure that you have:
4059

41-
- An OT sensor [installed](install-software-ot-sensor.md), [configured, and activated](activate-deploy-sensor.md), with alerts being triggered by detected traffic.
60+
- An OT sensor [installed](install-software-ot-sensor.md), [configured, and activated](activate-deploy-sensor.md), with alerts triggered by detected traffic.
4261

4362
- Access to your OT sensor as **Security Analyst** or **Admin** user. For more information, see [On-premises users and roles for OT monitoring with Defender for IoT](../roles-on-premises.md).
4463

@@ -57,7 +76,7 @@ For more information, see [View and manage alerts on your OT sensor](../how-to-v
5776
> [!div class="step-by-step"]
5877
> [« Verify and update your detected device inventory](update-device-inventory.md)
5978
60-
After learning mode is turned off, you've moved from *learning* mode to *operation* mode. Continue with any of the following:
79+
After learning mode is turned off, and you move from *learning* mode to *operation* mode continue with any of the following:
6180

6281
- [Visualize Microsoft Defender for IoT data with Azure Monitor workbooks](../workbooks.md)
6382
- [View and manage alerts from the Azure portal](../how-to-manage-cloud-alerts.md)

0 commit comments

Comments
 (0)