<link rel="stylesheet" href="styles.cf390c6bfbe7555f.css">
Repository logo

A Quiet Day Is Not a Secure Network: Multi-Timescale Evidence from a Single Enterprise Security Gateway

aut.relation.articlenumber4570
aut.relation.endpage29
aut.relation.journalElectronics, MDPI
aut.relation.pages29
aut.relation.startpage1
aut.relation.volume15
dc.contributor.authorHasan, Md Rajib
dc.contributor.authorAlani, Noor HS
dc.contributor.authorSarkar, Nurul I
dc.date.accessioned2026-10-08T21:13:27Z
dc.date.issued2026-10-08
dc.description.abstractSecurity dashboards summarise large event streams into convenient hourly, daily, weekly, and monthly views, but aggregation can change what analysts see and therefore what they prioritise. This case study examines four overlapping Check Point Quantum Spark 1530 reports from a single enterprise edge gateway: 1 h, 24 h, 7 days, and 30 days, each ending on or near 15 September 2023. We reconstruct traffic series, normalise volumes by duration, compare application concentration, reconcile summary and detailed tables, and separate control-confirmed events from unadjudicated indicators. The one hour window corresponded to a duration-normalised 10.10 GB/day, 2.86 times the 30-day rate of 3.53 GB/day, whereas the 24 h and seven-day rates were 3.86 and 3.51 GB/day. Top five application concentration declined monotonically from 88.8% at one hour to 17.5% at 30 days. The hourly and daily summaries reported zero Anti-Bot, Anti-Virus, and intrusion-prevention events. Yet, the seven-day report contained 15,641 IPS incidents and four Anti-Virus events, and the 30-day report contained 136,057 IPS incidents, 28 Anti-Virus events, and two Anti-Bot events. Reconciliation also exposed non-additive rounded totals, partial-bin coverage, conflicting high-risk-application counts, and a weekly QUIC session count larger than its 30-day counterpart. An alignment-controlled comparison of the exactly nested 7-day/30-day pair showed nearly identical traffic rates in the final week and the preceding 23 days (3.51 versus 3.54 GB/day). In contrast, a containment bound showed that part of the apparent collapse in leading-application dominance reflects vendor reporting logic rather than aggregation. Within the limits of this single-gateway case study, the results indicate that short windows are useful for burst triage but unsafe as stand-alone evidence of security state. We propose, but do not yet validate, a multi-timescale workflow for converting vendor telemetry into cyber-risk intelligence through alignment, normalisation, reconciliation, corroboration, and explicit confidence labels.
dc.identifier.citationElectronics, MDPI, ISSN: 2079-9292 (Print); 2079-9292 (Online), MDPI AG, 15, 1-29. doi: 10.3390/electronics15194570
dc.identifier.doi10.3390/electronics15194570
dc.identifier.issn2079-9292
dc.identifier.issn2079-9292
dc.identifier.urihttp://hdl.handle.net/10292/22109
dc.languageEnglish
dc.publisherMDPI AG
dc.relation.urihttps://www.mdpi.com/2079-9292/15/19/4570
dc.rightsCopyright: © 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article.
dc.rights.accessrightsOpenAccess
dc.rights.licenseCreative Commons Attribution (CC BY) license.
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.subject0906 Electrical and Electronic Engineering
dc.subject4009 Electronics, sensors and digital hardware
dc.subjectnetwork telemetry
dc.subjectcyber-risk intelligence
dc.subjecttemporal aggregation
dc.subjectsecurity operations
dc.subjectintrusion prevention
dc.subjectdashboard consistency
dc.subjectrisk observability
dc.subjecttraffic analysis
dc.titleA Quiet Day Is Not a Secure Network: Multi-Timescale Evidence from a Single Enterprise Security Gateway
dc.typeJournal Article
pubs.elements-id775681

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
electronics-15-04570.pdf
Size:
2.61 MB
Format:
Adobe Portable Document Format
Description:
Journal article