[ { "name": "window_event_count", "index": 0, "type": "float", "description": "Total number of security events observed for the source IP within the 5-minute sliding window." }, { "name": "failure_ratio", "index": 1, "type": "float", "description": "Ratio of failed events (failed passwords, invalid users, 401/403/404 HTTP errors) to total events in the window (range: 0.0 to 1.0)." }, { "name": "distinct_paths", "index": 2, "type": "float", "description": "Number of unique URL paths or target resources probed by the source IP in the window." }, { "name": "distinct_users", "index": 3, "type": "float", "description": "Number of distinct usernames targeted during SSH authentication attempts within the window." }, { "name": "path_entropy", "index": 4, "type": "float", "description": "Shannon character entropy of all concatenated request paths, capturing random probing, fuzzer output, and automated scanner payloads." }, { "name": "inter_event_time_mean_ms", "index": 5, "type": "float", "description": "Mean time delta between consecutive events in milliseconds. Low values indicate automated scanning, rapid brute-forcing, or scripted bursts." }, { "name": "hour_of_day_norm", "index": 6, "type": "float", "description": "Normalized timestamp hour (hour / 24.0, range: 0.0 to 1.0), capturing temporal deviations from host baseline hours." }, { "name": "sensitive_path_ratio", "index": 7, "type": "float", "description": "Proportion of requests targeting high-risk security files or administrative endpoints (.env, wp-config, phpmyadmin, .git, actuator, webshells)." } ]