Skip to content
Cybersecurity

AI in Network Security: What Anomaly Detection Can Do Today and What It Cannot

How AI anomaly detection in network traffic works, which attacks it reveals, where false positives arise and why it cannot replace segmentation.

Published on 5 min read

Monitor on a white desk showing a flat curve with a single spike on a dark background.

Hardly any vendor today sells a firewall, switch or Wi-Fi system without the label “AI-powered”. The promise: a system learns your network’s normal behaviour and raises an alarm when something deviates. That can shorten the time to detect an attack considerably, but only if the network is prepared and someone handles the alarms.

The problem: time to detection

According to media reports, the Berlin state network incident of August 2026 went unnoticed for five days while several terabytes were exfiltrated. Bitkom’s Wirtschaftsschutz 2026 study reports that only 67 per cent of companies surveyed could reliably detect an attack, down from 87 per cent the year before. Both figures are discussed in the article Cyber attacks on companies in Berlin and Brandenburg.

The IT-Grundschutz of the German Federal Office for Information Security (BSI) therefore requires firewalls to log rejected connections and failed logins (NET.3.2.A9) and recommends a monitoring concept with automatic alerting (NET.3.2.A23). What is new is that evaluation moves from people with rules to systems with statistical models.

How anomaly detection works

Classic detection works with signatures: known malware, known pattern, block. That works against known threats, not new ones. Anomaly detection instead observes over days or weeks which devices talk to which, when, over which protocols and with what data volumes. This produces a baseline against which live traffic is compared.

Typical deviations it makes visible:

  • A workstation transfers several gigabytes at night to an unknown address: the pattern of exfiltration before extortion.
  • A device in the office VLAN systematically probes addresses and ports in the server zone: lateral movement after initial access.
  • A printer contacts a server on the internet it has never talked to.
  • A single account modifies and renames thousands of files in a short time.

Because the threshold for “unusual” differs in every network, a learning model is superior to a hand-written rule set here.

What anomaly detection delivers

Such systems, known as Network Detection and Response (NDR), do three things well. They shorten the time to detection, because data exfiltration and lateral movement each produce several deviations from the baseline. They see what endpoint protection cannot: printers, cameras, building services, medical devices and hotel room controls have no antivirus, and only the network can observe their behaviour. And they provide context for the response: which device has talked to which others, and since when.

What it does not deliver

It detects deviations, not attacks. A new backup job, a software rollout or an employee on holiday in another time zone are anomalies, not attacks. False positives are the rule in the first weeks. Without someone to assess them and adjust the model, alarms are soon ignored.

It needs a network that can be observed. A flat network without zones produces noise in which deviations can hardly be separated from normal traffic. In a segmented network, where a printer may only talk to the print server, every other connection stands out. Segmentation under NET.1.1 is thus both protection and prerequisite for detection. How to plan it from the start is described in the checklist for networks in new builds and hotels.

It does not replace the basics. The BSI names restrictive access management, timely updates and minimising publicly reachable systems as the levers for 2026. At best, anomaly detection reports that someone has got through; preventing it is the job of the configuration described in the article Firewall rules and port forwarding.

It cannot see into encrypted traffic and works mainly with metadata. And it can itself be attacked: anyone who knows a baseline is being learned moves slowly and shifts small data volumes over long periods. According to the ENISA Threat Landscape 2025, attackers use AI to optimise their activities.

Who handles the alarm

Someone has to see the alarm at three in the morning, decide whether it is real and disconnect the device. In a corporation, a security operations centre does that. An SME, a hotel or a local authority has two realistic options: either detection is configured so tightly that only a few reliable alarms with clear response rules reach the IT team or IT service provider, or detection and response are bought in as Managed Detection and Response, with an external team assessing and intervening around the clock.

Key points

  • Anomaly detection shortens time to detection and covers devices without endpoint protection, but replaces neither multi-factor authentication nor updates nor segmentation.
  • It only produces useful alarms in a segmented network with central logging; in a flat network it produces noise.
  • Every alarm needs a recipient and a response rule, in the IT team or as Managed Detection and Response.

How DEVACON supports companies with assessment, protective measures and Managed Detection and Response is described on the page Cybersecurity.

Sources

  • ENISA: Threat Landscape 2025, published 1 October 2025, analysis of 4,875 incidents from 1 July 2024 to 30 June 2025, enisa.europa.eu
  • Federal Office for Information Security (BSI): Die Lage der IT-Sicherheit in Deutschland 2025, bsi.bund.de/lagebericht
  • BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.3.2 Firewall, bsi.bund.de
  • BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.1.1 Netzarchitektur und -design, bsi.bund.de
  • Bitkom: Wirtschaftsschutz 2026, study report, bitkom.org
  • Security-Insider: Berlin-Hack 2026: Ransomware, Datenabfluss und KRITIS-Lücke, 18 September 2026, security-insider.de

Topics AI Anomaly detection Network Monitoring NDR

This article comes from the DEVACON blog and was editorially revised for the new website.