The client is an African telecommunication company with more than 2 million users. By law the company needs to review the network traffic data and produce reports about cyber security attacks, malware, failed connections etc. Producing these reports manually takes significant time of the SOC team.
We designed and developed an automated AI solution to detect malicious behaviours in traffic workflows integrating output from different hardwares and software solutions (switchers, servers, mail data software etc.). Developed a pipeline to automatically report alerts and incidents. Improved effciencies of the analysts’ team (SOC) work of 100%.