File size: 1,739 Bytes
a7d517c | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 | [
{
"name": "window_event_count",
"index": 0,
"type": "float",
"description": "Total number of security events observed for the source IP within the 5-minute sliding window."
},
{
"name": "failure_ratio",
"index": 1,
"type": "float",
"description": "Ratio of failed events (failed passwords, invalid users, 401/403/404 HTTP errors) to total events in the window (range: 0.0 to 1.0)."
},
{
"name": "distinct_paths",
"index": 2,
"type": "float",
"description": "Number of unique URL paths or target resources probed by the source IP in the window."
},
{
"name": "distinct_users",
"index": 3,
"type": "float",
"description": "Number of distinct usernames targeted during SSH authentication attempts within the window."
},
{
"name": "path_entropy",
"index": 4,
"type": "float",
"description": "Shannon character entropy of all concatenated request paths, capturing random probing, fuzzer output, and automated scanner payloads."
},
{
"name": "inter_event_time_mean_ms",
"index": 5,
"type": "float",
"description": "Mean time delta between consecutive events in milliseconds. Low values indicate automated scanning, rapid brute-forcing, or scripted bursts."
},
{
"name": "hour_of_day_norm",
"index": 6,
"type": "float",
"description": "Normalized timestamp hour (hour / 24.0, range: 0.0 to 1.0), capturing temporal deviations from host baseline hours."
},
{
"name": "sensitive_path_ratio",
"index": 7,
"type": "float",
"description": "Proportion of requests targeting high-risk security files or administrative endpoints (.env, wp-config, phpmyadmin, .git, actuator, webshells)."
}
]
|