<link rel="stylesheet" href="styles.cf390c6bfbe7555f.css">
Repository logo

A Quiet Day Is Not a Secure Network: Multi-Timescale Evidence from a Single Enterprise Security Gateway

Loading...
Thumbnail Image

Files

Size: 2.61 MB, File format: Adobe PDF

Authors

Hasan, Md Rajib

Alani, Noor HS

Sarkar, Nurul I

Supervisor

Degree name

Journal Title

Journal ISSN

Volume Title

Publisher

MDPI AG

Abstract

Security dashboards summarise large event streams into convenient hourly, daily, weekly, and monthly views, but aggregation can change what analysts see and therefore what they prioritise. This case study examines four overlapping Check Point Quantum Spark 1530 reports from a single enterprise edge gateway: 1 h, 24 h, 7 days, and 30 days, each ending on or near 15 September 2023. We reconstruct traffic series, normalise volumes by duration, compare application concentration, reconcile summary and detailed tables, and separate control-confirmed events from unadjudicated indicators. The one hour window corresponded to a duration-normalised 10.10 GB/day, 2.86 times the 30-day rate of 3.53 GB/day, whereas the 24 h and seven-day rates were 3.86 and 3.51 GB/day. Top five application concentration declined monotonically from 88.8% at one hour to 17.5% at 30 days. The hourly and daily summaries reported zero Anti-Bot, Anti-Virus, and intrusion-prevention events. Yet, the seven-day report contained 15,641 IPS incidents and four Anti-Virus events, and the 30-day report contained 136,057 IPS incidents, 28 Anti-Virus events, and two Anti-Bot events. Reconciliation also exposed non-additive rounded totals, partial-bin coverage, conflicting high-risk-application counts, and a weekly QUIC session count larger than its 30-day counterpart. An alignment-controlled comparison of the exactly nested 7-day/30-day pair showed nearly identical traffic rates in the final week and the preceding 23 days (3.51 versus 3.54 GB/day). In contrast, a containment bound showed that part of the apparent collapse in leading-application dominance reflects vendor reporting logic rather than aggregation. Within the limits of this single-gateway case study, the results indicate that short windows are useful for burst triage but unsafe as stand-alone evidence of security state. We propose, but do not yet validate, a multi-timescale workflow for converting vendor telemetry into cyber-risk intelligence through alignment, normalisation, reconciliation, corroboration, and explicit confidence labels.

Description

Keywords

0906 Electrical and Electronic Engineering, 4009 Electronics, sensors and digital hardware, network telemetry, cyber-risk intelligence, temporal aggregation, security operations, intrusion prevention, dashboard consistency, risk observability, traffic analysis

Source

Electronics, MDPI, ISSN: 2079-9292 (Print); 2079-9292 (Online), MDPI AG, 15, 1-29. doi: 10.3390/electronics15194570

Rights statement

Copyright: © 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article.

Endorsement

Review

Supplemented By

Referenced By

Creative Commons license

Except where otherwise noted, this item's license is described as Creative Commons Attribution (CC BY) license.