← CYBERNETICSINTERN.COMCYBERNETIC INTERN
Detection EngineeringFOUNDATION

Why a 99% accurate detection still drowns you

Accuracy is measured against the thing you are looking for. Volume is measured against everything else, and everything else is almost all of your traffic.

A vendor tells you a detection is 99% accurate. That sounds like one bad alert in every hundred. It is not, and the gap between those two things is where alert fatigue comes from.

Accuracy is measured against the thing you are hunting. Volume comes from everything else. In security, everything else is almost all of your traffic.

Work it through. A hundred thousand logins a day, ten of them malicious. A rule that catches 99% of the bad ones finds about ten. The same rule misfires on 1% of the benign ones, and 1% of a hundred thousand is a thousand. Your analysts open roughly a thousand and ten alerts to find ten real ones.

The rule did exactly what it promised. The maths still buried the team.

This is why “it catches the attack” is never the whole question. The question is what the rule does to the other 99.99% of your day, and that is decided by the false positive rate multiplied by your volume, not by the accuracy figure on the slide.

Two practical consequences. Narrow the population before you widen the logic: a rule scoped to service accounts rather than all accounts changes the denominator, not just the numerator. And measure a new rule by how many alerts it produces in a week of real traffic, before it ever pages anybody.

CHECK YOURSELF

A rule is 99% accurate and fires on 1% of benign logins as well. You have 100,000 logins a day and 10 are malicious. Roughly how many alerts are real?

SHOW THE ANSWER

About 1 in 100

Why. The rule catches about 10 real logins, but 1% of the roughly 100,000 benign ones is another 1,000 alerts. Ten real out of about 1,010 total is roughly one in a hundred. The accuracy figure never mentioned the size of the population it would be wrong about.

REFERENCE

← ALL DETECTION ENGINEERING