File size: 1,739 Bytes
a7d517c
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
[
  {
    "name": "window_event_count",
    "index": 0,
    "type": "float",
    "description": "Total number of security events observed for the source IP within the 5-minute sliding window."
  },
  {
    "name": "failure_ratio",
    "index": 1,
    "type": "float",
    "description": "Ratio of failed events (failed passwords, invalid users, 401/403/404 HTTP errors) to total events in the window (range: 0.0 to 1.0)."
  },
  {
    "name": "distinct_paths",
    "index": 2,
    "type": "float",
    "description": "Number of unique URL paths or target resources probed by the source IP in the window."
  },
  {
    "name": "distinct_users",
    "index": 3,
    "type": "float",
    "description": "Number of distinct usernames targeted during SSH authentication attempts within the window."
  },
  {
    "name": "path_entropy",
    "index": 4,
    "type": "float",
    "description": "Shannon character entropy of all concatenated request paths, capturing random probing, fuzzer output, and automated scanner payloads."
  },
  {
    "name": "inter_event_time_mean_ms",
    "index": 5,
    "type": "float",
    "description": "Mean time delta between consecutive events in milliseconds. Low values indicate automated scanning, rapid brute-forcing, or scripted bursts."
  },
  {
    "name": "hour_of_day_norm",
    "index": 6,
    "type": "float",
    "description": "Normalized timestamp hour (hour / 24.0, range: 0.0 to 1.0), capturing temporal deviations from host baseline hours."
  },
  {
    "name": "sensitive_path_ratio",
    "index": 7,
    "type": "float",
    "description": "Proportion of requests targeting high-risk security files or administrative endpoints (.env, wp-config, phpmyadmin, .git, actuator, webshells)."
  }
]