The gateway can summarize activity by persistent owner/unit identity rather than forcing the model to guess from changing IP addresses and ports. Local evidence may include event counts, target diversity, services, timing, previous incidents and owner confirmations.
The DB server can add a compact intelligence package describing what the wider TaraSec network knows. This can include independent corroboration, cross-owner observations, candidate botnet relationships and global severity indicators without requiring the central service to pay for the gateway's full AI analysis.
TaraSec also distinguishes customer/LAN units, identified by owner ID plus owner-generated unit ID, from known TaraSec/network nodes, identified as infrastructure, and from genuinely unknown IP-only observations.