This 2D companion renders the same CASB gateway from directly above: the gateway sits at the centre of the view and every connected app is placed on a ring around it, exactly like the 3D scene's orbit, but flattened to a single plane you can pan and zoom freely instead of orbiting a camera. A Cloud Access Security Broker cannot inspect the content of every connection, so it infers whether a destination is a sanctioned app or unmonitored Shadow IT purely from traffic behaviour — an anomaly score built from three signals, smoothed with an exponentially-weighted moving average (EWMA):
rateDev = |actualRate − signatureRate| / signatureRate
sigTerm = knownSignature ? 0 : 1
score_raw = clamp(40·rateDev + 50·sigTerm + 10·volumeFactor, 0, 100)
score(t) = score(t−dt) + (score_raw − score(t−dt))·(1 − e^(−dt/τ))
Apps with a known signature (sanctioned SaaS) stay near 0 even when bursty, because the burst still matches an expected pattern. Apps with no signature on file accumulate score from the moment any traffic reaches them. When score stays above the detection threshold for a sustained dwell window, the CASB flags the destination as discovered Shadow IT.
- Detection threshold — lower catches shadow apps faster but risks flagging noisy sanctioned traffic; higher is safer but slower to react.
- Active users — more simultaneous users raises traffic volume/rate into every app, including undiscovered ones.
- Enforcement — Monitor Only logs discoveries without touching traffic; Block Shadow Apps drops every packet to a discovered unsanctioned destination at the gateway, the same way a CASB in blocking mode would.
- Pan / zoom — drag the view to pan around the ring of apps, and scroll (or pinch) to zoom in on a single app's packet traffic.
Real-world relevance: this is the statistical core of how products like Netskope, Microsoft Defender for Cloud Apps and Skyhigh CASB build their app-risk inventories — traffic metadata (frequency, volume, destination reputation) rather than payload content, which is why CASB discovery complements, not replaces, content-aware DLP.