Skip to main content

Lighthouse - AI Traffic Anomalies

Alex Patnick avatar
Written by Alex Patnick
Updated over a week ago

*Available to Early Access Program participants only (alpha version)

Lighthouse AI is Faddom’s new machine learning-based engine for detecting unusual traffic behavior and potential security threats. It automatically identifies issues ranging from denial-of-service (DoS) attacks and unauthorized connections to performance-related problems like outages and packet loss.
Built on a multi-layered machine learning architecture, Lighthouse continuously learns the characteristics of your environment, surfaces only the most relevant insights, and reduces alert noise over time.

Key coverage areas include:

  • Security threats such as DoS, man-in-the-middle (MITM) attacks, DNS spoofing, port scanning, and data exfiltration

  • Network and application performance issues, including outages, packet loss, and latency

To ensure data privacy, all information sent to Lighthouse is abstracted by your Faddom server, which strips identifiable data before processing. While the Lighthouse servers will be able to make sense of the connections, only your instance of Faddom will be able to interpret the data correctly.

Access and Availability
Lighthouse AI is currently in Alpha and available exclusively to customers and design partners participating in our Early Access Program.

To request access, please contact your Customer Success Manager or reach out to Faddom Support - support@faddom.com

Disclaimers

1. All alerts should be verified, as you may experience false positives

2. As previously stated, it is currently an Alpha version, and the feature is subject to change.

Prerequisites

Faddom securely connects to https://lighthouse.faddom.ai to analyze your data. All data is scrambled and encrypted by your Faddom instance, sent securely, analyzed, and then returned, ready to be safely converted back into meaningful insights.

How it Works

  1. Faddom will constantly send the connection data to our servers in an abstract way to ensure no IPs or other sensitive data is sent. Only your instance of Faddom will be able to interpret the data correctly.

  2. For the first detection, a minimum of two weeks of data is required

  3. If less than two weeks, Faddom will continue sending data until it has two weeks' worth

  4. Once the two-week data is received, Faddom will continue adding to the data and continue analysing it

  5. An email will be sent to a preconfigured email address when Faddom detects an anomaly

  6. A Lighthouse icon will show in the Faddom UI that can be clicked to see all the alerts

  7. Notifications will be available from our BETA version of Lighthouse

Statuses

You will see one of four statuses in the Lightuse UI depending on the analysis stage of the data -

  1. Learning - Faddom is gathering the required data on the customer environment

  2. Training - The model is trained based on customer data

  3. Up - AI Anomaly Detection is fully functional

  4. Down - No connection to the API

Feedback

You can click on the thumbs up or thumbs down to let Lighthouse know if the detected anomaly was accurate. Providing this feedback improves the learning and therefore the accuracy of your alerts going forward.

Did this answer your question?