Systems and methods for behavioral
baselining of network systems. In one embodiment, a method includes: storing, in an asset attribute
database, information regarding assets, wherein each asset comprises at least one attribute; storing, in a relationship
database, information regarding relationships, wherein each relationship comprises at least one attribute; selecting, from the asset attribute
database, assets based on at least one attribute value; selecting, from the relationship database, one or more relationships based on at least one attribute value, the selected relationships including a
first relationship; creating a baseline, wherein the baseline comprises the selected assets and the selected relationships; connecting a first
event stream to the baseline, wherein the first
event stream comprises a set of events, and each event comprises attributes; and detecting a drift from the baseline, wherein the drift is determined using the first
event stream and is based on a failure of at least one attribute value in a first event of the first event
stream to match at least one attribute value of the
first relationship.