dxa-guard / features.json
mosetireagan's picture
Release DXA-Guard GBDT intrusion detection model and weights
a7d517c verified
Raw History Blame Contribute Delete
1.74 kB
[
{
"name": "window_event_count",
"index": 0,
"type": "float",
"description": "Total number of security events observed for the source IP within the 5-minute sliding window."
},
{
"name": "failure_ratio",
"index": 1,
"type": "float",
"description": "Ratio of failed events (failed passwords, invalid users, 401/403/404 HTTP errors) to total events in the window (range: 0.0 to 1.0)."
},
{
"name": "distinct_paths",
"index": 2,
"type": "float",
"description": "Number of unique URL paths or target resources probed by the source IP in the window."
},
{
"name": "distinct_users",
"index": 3,
"type": "float",
"description": "Number of distinct usernames targeted during SSH authentication attempts within the window."
},
{
"name": "path_entropy",
"index": 4,
"type": "float",
"description": "Shannon character entropy of all concatenated request paths, capturing random probing, fuzzer output, and automated scanner payloads."
},
{
"name": "inter_event_time_mean_ms",
"index": 5,
"type": "float",
"description": "Mean time delta between consecutive events in milliseconds. Low values indicate automated scanning, rapid brute-forcing, or scripted bursts."
},
{
"name": "hour_of_day_norm",
"index": 6,
"type": "float",
"description": "Normalized timestamp hour (hour / 24.0, range: 0.0 to 1.0), capturing temporal deviations from host baseline hours."
},
{
"name": "sensitive_path_ratio",
"index": 7,
"type": "float",
"description": "Proportion of requests targeting high-risk security files or administrative endpoints (.env, wp-config, phpmyadmin, .git, actuator, webshells)."
}
]