A Quiet Day Is Not a Secure Network: Multi-Timescale Evidence from a Single Enterprise Security Gateway
Files
Date
Authors
Supervisor
Item type
Degree name
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
Security dashboards summarise large event streams into convenient hourly, daily, weekly, and monthly views, but aggregation can change what analysts see and therefore what they prioritise. This case study examines four overlapping Check Point Quantum Spark 1530 reports from a single enterprise edge gateway: 1 h, 24 h, 7 days, and 30 days, each ending on or near 15 September 2023. We reconstruct traffic series, normalise volumes by duration, compare application concentration, reconcile summary and detailed tables, and separate control-confirmed events from unadjudicated indicators. The one hour window corresponded to a duration-normalised 10.10 GB/day, 2.86 times the 30-day rate of 3.53 GB/day, whereas the 24 h and seven-day rates were 3.86 and 3.51 GB/day. Top five application concentration declined monotonically from 88.8% at one hour to 17.5% at 30 days. The hourly and daily summaries reported zero Anti-Bot, Anti-Virus, and intrusion-prevention events. Yet, the seven-day report contained 15,641 IPS incidents and four Anti-Virus events, and the 30-day report contained 136,057 IPS incidents, 28 Anti-Virus events, and two Anti-Bot events. Reconciliation also exposed non-additive rounded totals, partial-bin coverage, conflicting high-risk-application counts, and a weekly QUIC session count larger than its 30-day counterpart. An alignment-controlled comparison of the exactly nested 7-day/30-day pair showed nearly identical traffic rates in the final week and the preceding 23 days (3.51 versus 3.54 GB/day). In contrast, a containment bound showed that part of the apparent collapse in leading-application dominance reflects vendor reporting logic rather than aggregation. Within the limits of this single-gateway case study, the results indicate that short windows are useful for burst triage but unsafe as stand-alone evidence of security state. We propose, but do not yet validate, a multi-timescale workflow for converting vendor telemetry into cyber-risk intelligence through alignment, normalisation, reconciliation, corroboration, and explicit confidence labels.

