VERITY Network Intelligence v3.1.2 is zero-day anomaly detection by design. No signatures. No training on attack data. No cloud dependency. Calibrate on benign traffic only. Attack labels are not used for calibration or detection. The deviation is the detection.
"Signatures catch what has been seen. Behavioral measurement catches what has not. The attack that has never been catalogued is still a deviation from the baseline, and deviation is measurable."
Signature-based detection works by pattern matching. It is fast, precise, and structurally limited to attacks that have been seen before. Zero-day attacks pass through invisible. So do the long tail of attacks that were never important enough to receive their own signature. The industry response has been to wait for the breach, write the signature, and hope no one else gets hit first.
VERITY takes a different approach. It calibrates on the benign traffic in your environment. It learns the behavioral shape of normal flows: volume, timing, directionality, session structure. Every incoming flow is measured against that baseline. The attack does not need a name. It does not need a signature. It does not need to have been seen before. It only needs to be different from normal, and difference is measurable.
VERITY calibrates on your benign traffic in a single pass. Every flow is then measured across four independent measurement perspectives, each calibrated from benign only. Flows that deviate are flagged. Flows near the decision boundary are escalated. When the system is uncertain, it says so.
5-fold cross-validated. Calibration on benign only. CICIDS multi-scale results independently reproduced on second hardware. Full tables, operating points, and limitations are in the external model card. Methodology stays off the public surface.
| Dataset | Setting | AUC | F1 @ α=0.05 | Notes |
|---|---|---|---|---|
| CICIDS-2017 Friday | Multi-scale | 0.9990 | 0.972 | F1 0.992 at α=0.005 |
| CICIDS-2017 Wednesday | Multi-scale | 0.9986 | 0.957 | F1 0.995 at α=0.005 |
| CICIDS-2017 Tuesday | Multi-scale | 0.9985 | 0.470 | Low prevalence; α recovers F1 |
| CICIDS-2017 Thursday | Multi-scale | 0.9984 | 0.910 | F1 0.969 at α=0.005 |
| MAWI 2016 | Flow-only | 0.954 | 0.608 | Real backbone; peak F1 0.634 |
| MAWI 2021 | Multi-scale | 0.924 | 0.521 | Independently reproduced |
| MAWI 2021 | Flow-only | 0.860 | 0.517 | Shown for method contrast |
| UNSW Test | Flow-level | 0.980 | 0.924 | Modern lab traffic |
BCCC-IoT withheld pending end-to-end reproduction. Live test drive: veritynetwork.credasis.ai.
| Property | VERITY | Signature-based IDS | Behavioral ML platforms |
|---|---|---|---|
| Encrypted traffic | Measures behavior | Cannot inspect | Varies |
| Zero-day attacks | Detected as deviation | Requires signature | Varies |
| Training required | None | Continuous signature updates | Days to weeks |
| Independent benchmark validation | Published, reproducible | n/a | Generally not published |
| GPU required | No | No | Typically yes |
| Air-gapped capable | Yes | Varies | Generally no |
| Engine size | 500–560 KB | Hundreds of MB | GB-scale infrastructure |
| Forensic signature per alert | 28 bytes | Limited | Varies |
The same 500–560 KB engine runs everywhere Python 3.9+ runs. Throughput scales with hardware. Latency is ~1 ms per flow in Precision mode and ~4 ms in Detection mode on workstation-class machines.
Reproduce the v2.1 benchmarks on corrected public datasets. Request a technical briefing. Evaluate VERITY on your own traffic, on your own hardware, with your team operating the engine throughout.