Add nr-network-known-class-detector: v10 public-CVE cut (39 primitives, 9 chains, held-out ROC 0.9082)
Browse files- LICENSE +202 -0
- README.md +168 -0
- example_records.json +95 -0
- inference_example.py +31 -0
- model.joblib +3 -0
- predict.py +89 -0
LICENSE
ADDED
|
@@ -0,0 +1,202 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
|
| 2 |
+
Apache License
|
| 3 |
+
Version 2.0, January 2004
|
| 4 |
+
http://www.apache.org/licenses/
|
| 5 |
+
|
| 6 |
+
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
| 7 |
+
|
| 8 |
+
1. Definitions.
|
| 9 |
+
|
| 10 |
+
"License" shall mean the terms and conditions for use, reproduction,
|
| 11 |
+
and distribution as defined by Sections 1 through 9 of this document.
|
| 12 |
+
|
| 13 |
+
"Licensor" shall mean the copyright owner or entity authorized by
|
| 14 |
+
the copyright owner that is granting the License.
|
| 15 |
+
|
| 16 |
+
"Legal Entity" shall mean the union of the acting entity and all
|
| 17 |
+
other entities that control, are controlled by, or are under common
|
| 18 |
+
control with that entity. For the purposes of this definition,
|
| 19 |
+
"control" means (i) the power, direct or indirect, to cause the
|
| 20 |
+
direction or management of such entity, whether by contract or
|
| 21 |
+
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
| 22 |
+
outstanding shares, or (iii) beneficial ownership of such entity.
|
| 23 |
+
|
| 24 |
+
"You" (or "Your") shall mean an individual or Legal Entity
|
| 25 |
+
exercising permissions granted by this License.
|
| 26 |
+
|
| 27 |
+
"Source" form shall mean the preferred form for making modifications,
|
| 28 |
+
including but not limited to software source code, documentation
|
| 29 |
+
source, and configuration files.
|
| 30 |
+
|
| 31 |
+
"Object" form shall mean any form resulting from mechanical
|
| 32 |
+
transformation or translation of a Source form, including but
|
| 33 |
+
not limited to compiled object code, generated documentation,
|
| 34 |
+
and conversions to other media types.
|
| 35 |
+
|
| 36 |
+
"Work" shall mean the work of authorship, whether in Source or
|
| 37 |
+
Object form, made available under the License, as indicated by a
|
| 38 |
+
copyright notice that is included in or attached to the work
|
| 39 |
+
(an example is provided in the Appendix below).
|
| 40 |
+
|
| 41 |
+
"Derivative Works" shall mean any work, whether in Source or Object
|
| 42 |
+
form, that is based on (or derived from) the Work and for which the
|
| 43 |
+
editorial revisions, annotations, elaborations, or other modifications
|
| 44 |
+
represent, as a whole, an original work of authorship. For the purposes
|
| 45 |
+
of this License, Derivative Works shall not include works that remain
|
| 46 |
+
separable from, or merely link (or bind by name) to the interfaces of,
|
| 47 |
+
the Work and Derivative Works thereof.
|
| 48 |
+
|
| 49 |
+
"Contribution" shall mean any work of authorship, including
|
| 50 |
+
the original version of the Work and any modifications or additions
|
| 51 |
+
to that Work or Derivative Works thereof, that is intentionally
|
| 52 |
+
submitted to Licensor for inclusion in the Work by the copyright owner
|
| 53 |
+
or by an individual or Legal Entity authorized to submit on behalf of
|
| 54 |
+
the copyright owner. For the purposes of this definition, "submitted"
|
| 55 |
+
means any form of electronic, verbal, or written communication sent
|
| 56 |
+
to the Licensor or its representatives, including but not limited to
|
| 57 |
+
communication on electronic mailing lists, source code control systems,
|
| 58 |
+
and issue tracking systems that are managed by, or on behalf of, the
|
| 59 |
+
Licensor for the purpose of discussing and improving the Work, but
|
| 60 |
+
excluding communication that is conspicuously marked or otherwise
|
| 61 |
+
designated in writing by the copyright owner as "Not a Contribution."
|
| 62 |
+
|
| 63 |
+
"Contributor" shall mean Licensor and any individual or Legal Entity
|
| 64 |
+
on behalf of whom a Contribution has been received by Licensor and
|
| 65 |
+
subsequently incorporated within the Work.
|
| 66 |
+
|
| 67 |
+
2. Grant of Copyright License. Subject to the terms and conditions of
|
| 68 |
+
this License, each Contributor hereby grants to You a perpetual,
|
| 69 |
+
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
| 70 |
+
copyright license to reproduce, prepare Derivative Works of,
|
| 71 |
+
publicly display, publicly perform, sublicense, and distribute the
|
| 72 |
+
Work and such Derivative Works in Source or Object form.
|
| 73 |
+
|
| 74 |
+
3. Grant of Patent License. Subject to the terms and conditions of
|
| 75 |
+
this License, each Contributor hereby grants to You a perpetual,
|
| 76 |
+
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
| 77 |
+
(except as stated in this section) patent license to make, have made,
|
| 78 |
+
use, offer to sell, sell, import, and otherwise transfer the Work,
|
| 79 |
+
where such license applies only to those patent claims licensable
|
| 80 |
+
by such Contributor that are necessarily infringed by their
|
| 81 |
+
Contribution(s) alone or by combination of their Contribution(s)
|
| 82 |
+
with the Work to which such Contribution(s) was submitted. If You
|
| 83 |
+
institute patent litigation against any entity (including a
|
| 84 |
+
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
| 85 |
+
or a Contribution incorporated within the Work constitutes direct
|
| 86 |
+
or contributory patent infringement, then any patent licenses
|
| 87 |
+
granted to You under this License for that Work shall terminate
|
| 88 |
+
as of the date such litigation is filed.
|
| 89 |
+
|
| 90 |
+
4. Redistribution. You may reproduce and distribute copies of the
|
| 91 |
+
Work or Derivative Works thereof in any medium, with or without
|
| 92 |
+
modifications, and in Source or Object form, provided that You
|
| 93 |
+
meet the following conditions:
|
| 94 |
+
|
| 95 |
+
(a) You must give any other recipients of the Work or
|
| 96 |
+
Derivative Works a copy of this License; and
|
| 97 |
+
|
| 98 |
+
(b) You must cause any modified files to carry prominent notices
|
| 99 |
+
stating that You changed the files; and
|
| 100 |
+
|
| 101 |
+
(c) You must retain, in the Source form of any Derivative Works
|
| 102 |
+
that You distribute, all copyright, patent, trademark, and
|
| 103 |
+
attribution notices from the Source form of the Work,
|
| 104 |
+
excluding those notices that do not pertain to any part of
|
| 105 |
+
the Derivative Works; and
|
| 106 |
+
|
| 107 |
+
(d) If the Work includes a "NOTICE" text file as part of its
|
| 108 |
+
distribution, then any Derivative Works that You distribute must
|
| 109 |
+
include a readable copy of the attribution notices contained
|
| 110 |
+
within such NOTICE file, excluding those notices that do not
|
| 111 |
+
pertain to any part of the Derivative Works, in at least one
|
| 112 |
+
of the following places: within a NOTICE text file distributed
|
| 113 |
+
as part of the Derivative Works; within the Source form or
|
| 114 |
+
documentation, if provided along with the Derivative Works; or,
|
| 115 |
+
within a display generated by the Derivative Works, if and
|
| 116 |
+
wherever such third-party notices normally appear. The contents
|
| 117 |
+
of the NOTICE file are for informational purposes only and
|
| 118 |
+
do not modify the License. You may add Your own attribution
|
| 119 |
+
notices within Derivative Works that You distribute, alongside
|
| 120 |
+
or as an addendum to the NOTICE text from the Work, provided
|
| 121 |
+
that such additional attribution notices cannot be construed
|
| 122 |
+
as modifying the License.
|
| 123 |
+
|
| 124 |
+
You may add Your own copyright statement to Your modifications and
|
| 125 |
+
may provide additional or different license terms and conditions
|
| 126 |
+
for use, reproduction, or distribution of Your modifications, or
|
| 127 |
+
for any such Derivative Works as a whole, provided Your use,
|
| 128 |
+
reproduction, and distribution of the Work otherwise complies with
|
| 129 |
+
the conditions stated in this License.
|
| 130 |
+
|
| 131 |
+
5. Submission of Contributions. Unless You explicitly state otherwise,
|
| 132 |
+
any Contribution intentionally submitted for inclusion in the Work
|
| 133 |
+
by You to the Licensor shall be under the terms and conditions of
|
| 134 |
+
this License, without any additional terms or conditions.
|
| 135 |
+
Notwithstanding the above, nothing herein shall supersede or modify
|
| 136 |
+
the terms of any separate license agreement you may have executed
|
| 137 |
+
with Licensor regarding such Contributions.
|
| 138 |
+
|
| 139 |
+
6. Trademarks. This License does not grant permission to use the trade
|
| 140 |
+
names, trademarks, service marks, or product names of the Licensor,
|
| 141 |
+
except as required for reasonable and customary use in describing the
|
| 142 |
+
origin of the Work and reproducing the content of the NOTICE file.
|
| 143 |
+
|
| 144 |
+
7. Disclaimer of Warranty. Unless required by applicable law or
|
| 145 |
+
agreed to in writing, Licensor provides the Work (and each
|
| 146 |
+
Contributor provides its Contributions) on an "AS IS" BASIS,
|
| 147 |
+
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
| 148 |
+
implied, including, without limitation, any warranties or conditions
|
| 149 |
+
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
| 150 |
+
PARTICULAR PURPOSE. You are solely responsible for determining the
|
| 151 |
+
appropriateness of using or redistributing the Work and assume any
|
| 152 |
+
risks associated with Your exercise of permissions under this License.
|
| 153 |
+
|
| 154 |
+
8. Limitation of Liability. In no event and under no legal theory,
|
| 155 |
+
whether in tort (including negligence), contract, or otherwise,
|
| 156 |
+
unless required by applicable law (such as deliberate and grossly
|
| 157 |
+
negligent acts) or agreed to in writing, shall any Contributor be
|
| 158 |
+
liable to You for damages, including any direct, indirect, special,
|
| 159 |
+
incidental, or consequential damages of any character arising as a
|
| 160 |
+
result of this License or out of the use or inability to use the
|
| 161 |
+
Work (including but not limited to damages for loss of goodwill,
|
| 162 |
+
work stoppage, computer failure or malfunction, or any and all
|
| 163 |
+
other commercial damages or losses), even if such Contributor
|
| 164 |
+
has been advised of the possibility of such damages.
|
| 165 |
+
|
| 166 |
+
9. Accepting Warranty or Additional Liability. While redistributing
|
| 167 |
+
the Work or Derivative Works thereof, You may choose to offer,
|
| 168 |
+
and charge a fee for, acceptance of support, warranty, indemnity,
|
| 169 |
+
or other liability obligations and/or rights consistent with this
|
| 170 |
+
License. However, in accepting such obligations, You may act only
|
| 171 |
+
on Your own behalf and on Your sole responsibility, not on behalf
|
| 172 |
+
of any other Contributor, and only if You agree to indemnify,
|
| 173 |
+
defend, and hold each Contributor harmless for any liability
|
| 174 |
+
incurred by, or claims asserted against, such Contributor by reason
|
| 175 |
+
of your accepting any such warranty or additional liability.
|
| 176 |
+
|
| 177 |
+
END OF TERMS AND CONDITIONS
|
| 178 |
+
|
| 179 |
+
APPENDIX: How to apply the Apache License to your work.
|
| 180 |
+
|
| 181 |
+
To apply the Apache License to your work, attach the following
|
| 182 |
+
boilerplate notice, with the fields enclosed by brackets "[]"
|
| 183 |
+
replaced with your own identifying information. (Don't include
|
| 184 |
+
the brackets!) The text should be enclosed in the appropriate
|
| 185 |
+
comment syntax for the file format. We also recommend that a
|
| 186 |
+
file or class name and description of purpose be included on the
|
| 187 |
+
same "printed page" as the copyright notice for easier
|
| 188 |
+
identification within third-party archives.
|
| 189 |
+
|
| 190 |
+
Copyright [yyyy] [name of copyright owner]
|
| 191 |
+
|
| 192 |
+
Licensed under the Apache License, Version 2.0 (the "License");
|
| 193 |
+
you may not use this file except in compliance with the License.
|
| 194 |
+
You may obtain a copy of the License at
|
| 195 |
+
|
| 196 |
+
http://www.apache.org/licenses/LICENSE-2.0
|
| 197 |
+
|
| 198 |
+
Unless required by applicable law or agreed to in writing, software
|
| 199 |
+
distributed under the License is distributed on an "AS IS" BASIS,
|
| 200 |
+
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
| 201 |
+
See the License for the specific language governing permissions and
|
| 202 |
+
limitations under the License.
|
README.md
ADDED
|
@@ -0,0 +1,168 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
---
|
| 2 |
+
license: apache-2.0
|
| 3 |
+
library_name: scikit-learn
|
| 4 |
+
tags:
|
| 5 |
+
- cybersecurity
|
| 6 |
+
- blockchain
|
| 7 |
+
- network-security
|
| 8 |
+
- validator-security
|
| 9 |
+
- anomaly-detection
|
| 10 |
+
- intrusion-detection
|
| 11 |
+
- ddos
|
| 12 |
+
- cve
|
| 13 |
+
datasets:
|
| 14 |
+
- NullRabbit/nr-bundles-public
|
| 15 |
+
metrics:
|
| 16 |
+
- roc_auc
|
| 17 |
+
- f1
|
| 18 |
+
---
|
| 19 |
+
|
| 20 |
+
# nr-network-known-class-detector
|
| 21 |
+
|
| 22 |
+
A binary **attack-vs-benign** detector for **blockchain-node network/resource attacks**, trained
|
| 23 |
+
entirely on faithful reproductions of **publicly-disclosed** attacks. Every attack class in the
|
| 24 |
+
corpus reproduces a specific public disclosure — a CVE, a GHSA, or a named third-party security
|
| 25 |
+
audit — and each carries a `provenance.source_class` recording how public its sourcing is. Part of
|
| 26 |
+
NullRabbit's work on **autonomous defence for decentralised networks** — *watch the outside of the
|
| 27 |
+
perimeter*.
|
| 28 |
+
|
| 29 |
+
> **STATUS: DIAGNOSTIC, not a deployment claim.** Trained on synthetic localnet reproductions (lab
|
| 30 |
+
> fidelity), not real production traffic. See *Evaluation* and *Limitations*.
|
| 31 |
+
|
| 32 |
+
## Model description
|
| 33 |
+
|
| 34 |
+
Given the network-layer signal of a short capture window against a blockchain node (packet-rate /
|
| 35 |
+
size statistics from the pcap, and amplification / request-response / timing statistics from the RPC
|
| 36 |
+
responses), the model emits a calibrated attack probability. It is one multi-family model over the
|
| 37 |
+
`network-v1` feature manifold — it spans eight protocol layers and nine chains, all public-sourced
|
| 38 |
+
(this published cut is trained on `public-cve-replication` primitives only).
|
| 39 |
+
|
| 40 |
+
## Architecture
|
| 41 |
+
|
| 42 |
+
- `HistGradientBoostingClassifier` + isotonic calibration (scikit-learn), NaN-native.
|
| 43 |
+
- **34 features** kept (of the 103 `network-v1` features present in the corpus; 69 degenerate dropped
|
| 44 |
+
by a per-fit robust-column guard) — pcap aggregates + RPC-response aggregates. No host-load features
|
| 45 |
+
(the containerised lab node is root-owned, so CPU/connection host metrics are unreadable).
|
| 46 |
+
- Decision threshold 0.5 (calibrated). Inference is **scoreability-gated**: a record with no network
|
| 47 |
+
signal (e.g. an economic/DeFi bundle) returns `scoreable=False` with no verdict.
|
| 48 |
+
|
| 49 |
+
## Training data — 39 public-CVE attack primitives, 9 chains, 8 layers, 1084 bundles
|
| 50 |
+
|
| 51 |
+
**This is the public-CVE cut** (`public-cve-replication` only): 708 attack + 376 benign bundles
|
| 52 |
+
(`pcap + responses + manifest`), 45 chain×primitive instances. Benign traffic exercises the **same
|
| 53 |
+
methods / wire messages** the attacks abuse, at normal scale — so the model separates attack-*use*
|
| 54 |
+
from benign-*use*, not message type. Every attack reproduces an external public disclosure (CVE / GHSA
|
| 55 |
+
/ named third-party audit) with a `provenance.public_source` URL. (An additional 8 `original`
|
| 56 |
+
primitives — NullRabbit's own measurement of vendor-acknowledged Solana/Ethereum RPC amplification, for
|
| 57 |
+
which no CVE exists — are held in the full corpus but **excluded from this published cut**, so the
|
| 58 |
+
"trained entirely on public disclosures" claim above is literal.)
|
| 59 |
+
|
| 60 |
+
| primitive | chain · layer | public source | source_class |
|
| 61 |
+
|---|---|---|---|
|
| 62 |
+
| `btc_inv_buffer_blowup` | Bitcoin · P2P | **CVE-2024-52915** | public-cve-replication |
|
| 63 |
+
| `btc_invdos_flood` | Bitcoin · P2P | **CVE-2018-17145** (INVDoS) | public-cve-replication |
|
| 64 |
+
| `btc_getdata_flood` | Bitcoin · P2P | **CVE-2024-52920** | public-cve-replication |
|
| 65 |
+
| `btc_headers_oom` | Bitcoin · P2P | **CVE-2019-25220** | public-cve-replication |
|
| 66 |
+
| `btc_orphan_cpu` | Bitcoin · P2P | **CVE-2024-52914** | public-cve-replication |
|
| 67 |
+
| `btc_addr_overflow_flood` | Bitcoin · P2P | **CVE-2024-52919** / GHSA-qwp9-p9rr-h729 | public-cve-replication |
|
| 68 |
+
| `btc_bloom_divzero` | Bitcoin · P2P | **CVE-2013-5700** | public-cve-replication |
|
| 69 |
+
| `cosmos_protobuf_nest_bomb` | Cosmos · deserialization | **GHSA-8wcc-m6j2-qxvm** | public-cve-replication |
|
| 70 |
+
| `sol_tpu_quic_handshake_flood` | Solana · TPU-QUIC | Neodyme Firedancer audit ND-FD04-LO-01 | public-cve-replication |
|
| 71 |
+
| `geth_devp2p_ping_flood` | Ethereum · devp2p/RLPx | **CVE-2023-40591** (GHSA-ppjg-v974-84cm) | public-cve-replication |
|
| 72 |
+
| `geth_rlpx_auth_flood` | Ethereum · devp2p/RLPx | **EL-2026-06** (EF public-disclosures) | public-cve-replication |
|
| 73 |
+
| `gossipsub_prune_backoff_overflow` | libp2p · gossipsub | **CVE-2026-34219** / CVE-2026-33040 | public-cve-replication |
|
| 74 |
+
| `gossipsub_subscribe_flood` | libp2p · gossipsub | **CVE-2026-46679** | public-cve-replication |
|
| 75 |
+
| `libp2p_stream_exhaustion` | libp2p · muxer | **CVE-2022-23492** / CVE-2022-23486 | public-cve-replication |
|
| 76 |
+
| `monero_levin_array_memcorrupt` | Monero · Levin/epee | **CVE-2018-3972** (CVSS 10) | public-cve-replication |
|
| 77 |
+
| `monero_portable_storage_oom` | Monero · Levin/epee | Monero PR#7190 / 0.17.1.8 | public-cve-replication |
|
| 78 |
+
| `btc_headers_genesis_spam` / `btc_inv_eviction_jam` / `btc_tx_quad_sighash` / `btc_oversized_recv_buffer` | Bitcoin · P2P | CVE-2024-52916 / -52913 / 2025-46598 / 2015-3641 | public-cve-replication |
|
| 79 |
+
| `btc_version_timestamp_overflow` / `btc_version_selfnonce` | Bitcoin · P2P | CVE-2024-52912 / 2025-54604 | public-cve-replication |
|
| 80 |
+
| `btc_cmpctblock_stall` / `btc_cmpctblock_overflow` | Bitcoin · P2P (BIP152) | **CVE-2024-52922** / **CVE-2025-46597** | public-cve-replication |
|
| 81 |
+
| `btc_mutated_block` / `btc_invalid_block_logfill` / `btc_alert_flood` / `btc_tx_maprelay` | Bitcoin · P2P | CVE-2024-52921 / 2025-54605 / 2016-10724 / 2013-4627 | public-cve-replication |
|
| 82 |
+
| `p2p_getheaders_drain` + inherited `btc_addr_overflow_flood` / `btc_orphan_cpu` | Bitcoin/Dogecoin/Litecoin · P2P | CVE-2023-33297 / 2024-52919 / 2024-52914 | public-cve-replication |
|
| 83 |
+
| `geth_eth_receipt_flood` | Ethereum · devp2p/RLPx | **EL-2024-20** (EF public-disclosure) | public-cve-replication |
|
| 84 |
+
| `geth_snap_trienode_dos` | Ethereum · devp2p/snap | **CVE-2021-41173** (GHSA-59hh-656j-3p7v) | public-cve-replication |
|
| 85 |
+
| `geth_tcp_handshake_flood` | Ethereum · devp2p | **EL-2024-06** (EF public-disclosure) | public-cve-replication |
|
| 86 |
+
| `sol_tpu_quic_slowloris` / `sol_tpu_quic_initial_cpu` | Solana · TPU-QUIC | Neodyme ND-FD04-IN-02 / ND-FD1-MD-02 | public-cve-replication |
|
| 87 |
+
| `cosmos_p2p_conn_flood` | Cosmos · P2P | **CVE-2020-5303** (Tendermint) | public-cve-replication |
|
| 88 |
+
| `libp2p_signed_peer_record_flood` | libp2p · identify | **CVE-2023-40583** | public-cve-replication |
|
| 89 |
+
| `sui_verifier_hamsterwheel` / `sui_disassemble_panic` / `sui_move_recursion` | Sui · Move-VM / JSON-RPC | CertiK Skyfall ×2 / **CVE-2023-36184** | public-cve-replication |
|
| 90 |
+
|
| 91 |
+
Distribution: **708** `public-cve-replication` attack bundles — **39 distinct primitives across 9
|
| 92 |
+
chains** (Bitcoin, Ethereum, Solana, Sui, Cosmos, Monero, Dogecoin, Litecoin, libp2p) — plus **376**
|
| 93 |
+
benign. This published cut contains **no `original` bundles**; the 8 `original` RPC-measurement
|
| 94 |
+
primitives live in the full internal corpus and ship only if the operator explicitly opts in, always
|
| 95 |
+
under their honest label.
|
| 96 |
+
|
| 97 |
+
## Training procedure (methodology is the contribution)
|
| 98 |
+
|
| 99 |
+
Per NullRabbit's pre-registration discipline: the corpus is built attack-by-attack from a public
|
| 100 |
+
disclosure with `provenance.public_source`; a Cleanlab data-quality scan gates label-issues and
|
| 101 |
+
duplicates before training; a methodology auditor reviews each gate event with sanity floors and
|
| 102 |
+
falsification holdouts; honest limitations are stated; cycles — not the final number — are the
|
| 103 |
+
contribution. This corpus passed audit **APPROVED WITH REFINEMENTS** (all applied) — including the
|
| 104 |
+
correction of a benign train/test leak in one held-out eval, reported transparently.
|
| 105 |
+
|
| 106 |
+
## Evaluation
|
| 107 |
+
|
| 108 |
+
Diagnostic ML checks (the corpus of faithfully-modelled public attacks is the deliverable; these are
|
| 109 |
+
secondary). Reproduced by `scripts/known_class_loco_eval.py` + `scripts/corpus_quality.py`.
|
| 110 |
+
|
| 111 |
+
- **Corpus** (public-CVE cut): 1084/1084 distinct vectors, 0 duplicate rows; 2 Cleanlab review-flags — both deliberately-stealthy low-volume `gossipsub_subscribe_flood` captures that legitimately resemble benign (labels correct, not mislabels).
|
| 112 |
+
- **Within-corpus held-out — GroupKFold by primitive (66 groups, leakage-clean): ROC 0.9082.** `corpus_sha256 known-class-v10-publiccve`.
|
| 113 |
+
- **Leave-one-attack-primitive-out within Bitcoin (leak-clean, disjoint-benign):** all 20 Bitcoin primitives ≥ 0.969. Detection is on traffic *shape*, not deep wire-semantics.
|
| 114 |
+
- **Leave-one-chain-out (HARD zero-shot transfer — *not* a deployment metric):** Cosmos / Ethereum / Litecoin 1.00, Dogecoin 0.995, Bitcoin 0.934, libp2p 0.844, Solana 0.688, Sui 0.661, **Monero 0.592**. Chains with few public-CVE primitives (Monero's unique Levin protocol; Sui/Solana with 3 each) have the fewest cross-chain near-neighbours, so zero-shot transfer to them is hardest — reported honestly, not spun.
|
| 115 |
+
|
| 116 |
+
## Intended uses
|
| 117 |
+
|
| 118 |
+
Research and benchmarking of network/resource-abuse detection on blockchain infrastructure; a
|
| 119 |
+
worked, public-provenance reference corpus; downstream training. **Not** a turnkey production IDS.
|
| 120 |
+
|
| 121 |
+
## Limitations
|
| 122 |
+
|
| 123 |
+
- **Synthetic lab fidelity** — generated localnet traffic, not a real-world deployment claim. A
|
| 124 |
+
deployment claim needs a real-traffic validation gate (real mainnet RPC + real attack instances).
|
| 125 |
+
- **Detection is on traffic *shape*** (volume / rate / size / connection-churn), not deep wire
|
| 126 |
+
semantics — adequate for these volumetric/crash DoS classes; it would not separate two attacks with
|
| 127 |
+
identical traffic profiles.
|
| 128 |
+
- **No host-load features** (root-owned container).
|
| 129 |
+
- **This is the public-CVE cut** — every shipped attack class reproduces an external public disclosure
|
| 130 |
+
(CVE / GHSA / named audit). The `original` Solana/Ethereum RPC-amplification measurements
|
| 131 |
+
(vendor-acknowledged but not CVE-backed — RPC amplification has ~no CVEs) are **excluded** from this
|
| 132 |
+
model; they exist in the full internal corpus and ship only on explicit operator opt-in.
|
| 133 |
+
|
| 134 |
+
## How to use
|
| 135 |
+
|
| 136 |
+
```python
|
| 137 |
+
from predict import load, predict
|
| 138 |
+
model = load("model.joblib")
|
| 139 |
+
out = predict(model, [{"pcap.packet_rate": 850.0, "resp.amp_ratio_max": 224.0}])
|
| 140 |
+
# -> [{"scoreable": True, "score": ..., "verdict": "attack"|"benign", "threshold": 0.5}]
|
| 141 |
+
```
|
| 142 |
+
|
| 143 |
+
Run `python inference_example.py` for a worked example on real captured vectors (Bitcoin + Solana
|
| 144 |
+
attacks fire; benign Bitcoin peer is benign; an economic bundle is `scoreable=False`).
|
| 145 |
+
|
| 146 |
+
## Licensing
|
| 147 |
+
|
| 148 |
+
Apache-2.0 (see `LICENSE`). Attribution appreciated.
|
| 149 |
+
|
| 150 |
+
## Citation
|
| 151 |
+
|
| 152 |
+
```bibtex
|
| 153 |
+
@software{nullrabbit_network_known_class_2026,
|
| 154 |
+
author = {NullRabbit Labs},
|
| 155 |
+
title = {nr-network-known-class-detector: a public-provenance blockchain network-attack detector},
|
| 156 |
+
year = {2026},
|
| 157 |
+
url = {https://huggingface.co/NullRabbit/nr-network-known-class-detector}
|
| 158 |
+
}
|
| 159 |
+
```
|
| 160 |
+
|
| 161 |
+
Related: the open **bundle format** (`nr-bundle-spec`), the **family taxonomy** (mechanism-defined),
|
| 162 |
+
the **earned-autonomy framework** ([Zenodo 10.5281/zenodo.18406828](https://doi.org/10.5281/zenodo.18406828)),
|
| 163 |
+
the NullRabbit substrate paper (in preparation), the dataset `NullRabbit/nr-bundles-public`, and
|
| 164 |
+
[nullrabbit.ai](https://nullrabbit.ai).
|
| 165 |
+
|
| 166 |
+
## Contact
|
| 167 |
+
|
| 168 |
+
NullRabbit Labs — [huggingface.co/NullRabbit](https://huggingface.co/NullRabbit) · [nullrabbit.ai](https://nullrabbit.ai)
|
example_records.json
ADDED
|
@@ -0,0 +1,95 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
[
|
| 2 |
+
{
|
| 3 |
+
"label": "bitcoin:btc_invdos_flood",
|
| 4 |
+
"expect": "attack",
|
| 5 |
+
"feat": {
|
| 6 |
+
"pcap.bytes_per_s": 79402.155,
|
| 7 |
+
"pcap.distinct_dst_ips": 1.0,
|
| 8 |
+
"pcap.distinct_src_dst_pairs": 295.0,
|
| 9 |
+
"pcap.distinct_src_ips": 1.0,
|
| 10 |
+
"pcap.duration_s": 7.679,
|
| 11 |
+
"pcap.mean_packet_size": 111.385,
|
| 12 |
+
"pcap.packet_count": 5474.0,
|
| 13 |
+
"pcap.packets_per_s": 712.862,
|
| 14 |
+
"pcap.rst_fraction": 0.056,
|
| 15 |
+
"pcap.syn_to_handshake_ratio": 0.402,
|
| 16 |
+
"pcap.tcp_fin": 1.0,
|
| 17 |
+
"pcap.tcp_handshake_ack": 1463.0,
|
| 18 |
+
"pcap.tcp_rst": 308.0,
|
| 19 |
+
"pcap.tcp_syn": 588.0,
|
| 20 |
+
"pcap.tcp_syn_ack": 294.0,
|
| 21 |
+
"pcap.tcp_total_packets": 5474.0,
|
| 22 |
+
"pcap.top_dst_port": 18444.0,
|
| 23 |
+
"pcap.top_dst_port_fraction": 0.484,
|
| 24 |
+
"pcap.top_src_port": 18444.0,
|
| 25 |
+
"pcap.top_src_port_fraction": 0.516,
|
| 26 |
+
"pcap.total_bytes": 609722.0,
|
| 27 |
+
"pcap.unique_dst_ports": 5.0,
|
| 28 |
+
"pcap.unique_src_ports": 5.0,
|
| 29 |
+
"resp.count": 0.0,
|
| 30 |
+
"resp.resp_bytes_total": 0.0
|
| 31 |
+
}
|
| 32 |
+
},
|
| 33 |
+
{
|
| 34 |
+
"label": "solana:sol_tpu_quic_initial_cpu",
|
| 35 |
+
"expect": "attack",
|
| 36 |
+
"feat": {
|
| 37 |
+
"pcap.bytes_per_s": 13828.406,
|
| 38 |
+
"pcap.distinct_dst_ips": 0.0,
|
| 39 |
+
"pcap.distinct_src_dst_pairs": 0.0,
|
| 40 |
+
"pcap.distinct_src_ips": 0.0,
|
| 41 |
+
"pcap.duration_s": 7.035,
|
| 42 |
+
"pcap.mean_packet_size": 256.0,
|
| 43 |
+
"pcap.packet_count": 380.0,
|
| 44 |
+
"pcap.packets_per_s": 54.017,
|
| 45 |
+
"pcap.rst_fraction": 0.0,
|
| 46 |
+
"pcap.syn_to_handshake_ratio": 0.0,
|
| 47 |
+
"pcap.tcp_fin": 0.0,
|
| 48 |
+
"pcap.tcp_handshake_ack": 0.0,
|
| 49 |
+
"pcap.tcp_rst": 0.0,
|
| 50 |
+
"pcap.tcp_syn": 0.0,
|
| 51 |
+
"pcap.tcp_syn_ack": 0.0,
|
| 52 |
+
"pcap.tcp_total_packets": 0.0,
|
| 53 |
+
"pcap.top_dst_port": 0.0,
|
| 54 |
+
"pcap.top_dst_port_fraction": 0.0,
|
| 55 |
+
"pcap.top_src_port": 0.0,
|
| 56 |
+
"pcap.top_src_port_fraction": 0.0,
|
| 57 |
+
"pcap.total_bytes": 97280.0,
|
| 58 |
+
"pcap.unique_dst_ports": 0.0,
|
| 59 |
+
"pcap.unique_src_ports": 0.0,
|
| 60 |
+
"resp.count": 0.0,
|
| 61 |
+
"resp.resp_bytes_total": 0.0
|
| 62 |
+
}
|
| 63 |
+
},
|
| 64 |
+
{
|
| 65 |
+
"label": "bitcoin:benign_bitcoin_mixed_normal",
|
| 66 |
+
"expect": "benign",
|
| 67 |
+
"feat": {
|
| 68 |
+
"pcap.bytes_per_s": 22167.878,
|
| 69 |
+
"pcap.distinct_dst_ips": 1.0,
|
| 70 |
+
"pcap.distinct_src_dst_pairs": 75.0,
|
| 71 |
+
"pcap.distinct_src_ips": 1.0,
|
| 72 |
+
"pcap.duration_s": 7.252,
|
| 73 |
+
"pcap.mean_packet_size": 112.416,
|
| 74 |
+
"pcap.packet_count": 1430.0,
|
| 75 |
+
"pcap.packets_per_s": 197.195,
|
| 76 |
+
"pcap.rst_fraction": 0.055,
|
| 77 |
+
"pcap.syn_to_handshake_ratio": 0.493,
|
| 78 |
+
"pcap.tcp_fin": 5.0,
|
| 79 |
+
"pcap.tcp_handshake_ack": 300.0,
|
| 80 |
+
"pcap.tcp_rst": 78.0,
|
| 81 |
+
"pcap.tcp_syn": 148.0,
|
| 82 |
+
"pcap.tcp_syn_ack": 74.0,
|
| 83 |
+
"pcap.tcp_total_packets": 1430.0,
|
| 84 |
+
"pcap.top_dst_port": 18444.0,
|
| 85 |
+
"pcap.top_dst_port_fraction": 0.517,
|
| 86 |
+
"pcap.top_src_port": 18444.0,
|
| 87 |
+
"pcap.top_src_port_fraction": 0.483,
|
| 88 |
+
"pcap.total_bytes": 160755.0,
|
| 89 |
+
"pcap.unique_dst_ports": 5.0,
|
| 90 |
+
"pcap.unique_src_ports": 5.0,
|
| 91 |
+
"resp.count": 0.0,
|
| 92 |
+
"resp.resp_bytes_total": 0.0
|
| 93 |
+
}
|
| 94 |
+
}
|
| 95 |
+
]
|
inference_example.py
ADDED
|
@@ -0,0 +1,31 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
#!/usr/bin/env python3
|
| 2 |
+
"""nr-network-known-class-detector — inference example (Apache-2.0).
|
| 3 |
+
|
| 4 |
+
Runs real `network-v1` feature vectors (captured from the lab corpus and shipped in
|
| 5 |
+
`example_records.json`) through the detector:
|
| 6 |
+
1. a Bitcoin Core P2P attack (INVDoS flood, CVE-2018-17145) -> should FIRE
|
| 7 |
+
2. a Solana RPC attack (getProgramAccounts amplification) -> should FIRE
|
| 8 |
+
3. a benign Bitcoin peer (same message types, normal rate) -> benign
|
| 9 |
+
4. an out-of-domain record (no network signal) -> scoreable=False
|
| 10 |
+
|
| 11 |
+
Run from the model repo dir: python inference_example.py
|
| 12 |
+
"""
|
| 13 |
+
import json
|
| 14 |
+
|
| 15 |
+
from predict import load, predict
|
| 16 |
+
|
| 17 |
+
model = load("model.joblib")
|
| 18 |
+
records = json.load(open("example_records.json"))
|
| 19 |
+
|
| 20 |
+
# add an out-of-domain record (no pcap.*/resp.* signal) to show the scoreability gate
|
| 21 |
+
records.append({"label": "out-of-domain (economic bundle)", "expect": "unscoreable",
|
| 22 |
+
"feat": {"econ.gov_weight_held_blocks": 0.0}})
|
| 23 |
+
|
| 24 |
+
results = predict(model, [r["feat"] for r in records])
|
| 25 |
+
for r, out in zip(records, results):
|
| 26 |
+
if out["scoreable"]:
|
| 27 |
+
flag = "✓" if out["verdict"] == r["expect"] else "✗"
|
| 28 |
+
print(f"{flag} {r['label']:<42} score={out['score']:<7} verdict={out['verdict']} "
|
| 29 |
+
f"(expect {r['expect']}, threshold {out['threshold']})")
|
| 30 |
+
else:
|
| 31 |
+
print(f" {r['label']:<42} UNSCOREABLE (no network signal — out of domain)")
|
model.joblib
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:9fb86002e090d9c42d96569c268385554dcc3eb5ac27c1626c22106b1cc22605
|
| 3 |
+
size 3111901
|
predict.py
ADDED
|
@@ -0,0 +1,89 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
#!/usr/bin/env python3
|
| 2 |
+
"""nr-network-known-class-detector — scoreability-gated inference helper (Apache-2.0).
|
| 3 |
+
|
| 4 |
+
Self-contained: needs only numpy + joblib + scikit-learn (the version the model was trained with).
|
| 5 |
+
Loads `model.joblib` (a dict carrying the HistGradientBoostingClassifier + its feature contract) and
|
| 6 |
+
scores feature dicts produced by the NullRabbit `network-v1` featuriser (pcap + responses aggregates).
|
| 7 |
+
|
| 8 |
+
SCOREABILITY GATE: this is a network/resource-abuse detector. A record is *scoreable* only if it
|
| 9 |
+
carries at least one of the model's network features (pcap.* / resp.*) non-NaN. A record with no
|
| 10 |
+
network signal (e.g. a pure economic/DeFi bundle, or an empty dict) is returned `scoreable=False`
|
| 11 |
+
with no verdict — the model must not emit a confident score outside its domain.
|
| 12 |
+
|
| 13 |
+
The model is DIAGNOSTIC (trained on synthetic localnet reproductions of public attacks); see the
|
| 14 |
+
model card. Default decision threshold 0.5 (the classifier is isotonic-calibrated).
|
| 15 |
+
|
| 16 |
+
Usage:
|
| 17 |
+
from predict import load, predict
|
| 18 |
+
model = load("model.joblib")
|
| 19 |
+
out = predict(model, [{"pcap.packet_rate": 850.0, "resp.amp_ratio_max": 224.0, ...}])
|
| 20 |
+
# -> [{"scoreable": True, "score": 0.99, "verdict": "attack", "threshold": 0.5}]
|
| 21 |
+
"""
|
| 22 |
+
from __future__ import annotations
|
| 23 |
+
|
| 24 |
+
import joblib
|
| 25 |
+
import numpy as np
|
| 26 |
+
|
| 27 |
+
DEFAULT_THRESHOLD = 0.5
|
| 28 |
+
|
| 29 |
+
|
| 30 |
+
def load(path: str = "model.joblib") -> dict:
|
| 31 |
+
m = joblib.load(path)
|
| 32 |
+
assert {"model", "feature_names"} <= set(m), "model.joblib is not the expected contract dict"
|
| 33 |
+
return m
|
| 34 |
+
|
| 35 |
+
|
| 36 |
+
def _is_scoreable(feat: dict, names: list[str]) -> bool:
|
| 37 |
+
nameset = set(names)
|
| 38 |
+
for k, v in feat.items():
|
| 39 |
+
if k not in nameset or v is None:
|
| 40 |
+
continue
|
| 41 |
+
try:
|
| 42 |
+
if not np.isnan(float(v)):
|
| 43 |
+
return True
|
| 44 |
+
except (TypeError, ValueError):
|
| 45 |
+
continue
|
| 46 |
+
return False
|
| 47 |
+
|
| 48 |
+
|
| 49 |
+
def predict(model: dict, records: list[dict], threshold: float = DEFAULT_THRESHOLD) -> list[dict]:
|
| 50 |
+
"""Score a list of network-v1 feature dicts. Unscoreable records get no verdict.
|
| 51 |
+
|
| 52 |
+
`feature_names` in the contract is already the post-robust-guard set the model was fit on
|
| 53 |
+
(34 features); build the vector over exactly those, NaN for anything absent (HGB is NaN-native).
|
| 54 |
+
"""
|
| 55 |
+
names = model["feature_names"]
|
| 56 |
+
clf = model["model"]
|
| 57 |
+
idx = {n: i for i, n in enumerate(names)}
|
| 58 |
+
|
| 59 |
+
out: list[dict | None] = []
|
| 60 |
+
rows, pos = [], []
|
| 61 |
+
for i, feat in enumerate(records):
|
| 62 |
+
if not _is_scoreable(feat, names):
|
| 63 |
+
out.append({"scoreable": False, "score": None, "verdict": None, "threshold": threshold})
|
| 64 |
+
continue
|
| 65 |
+
vec = np.full(len(names), np.nan)
|
| 66 |
+
for k, v in feat.items():
|
| 67 |
+
if k in idx and v is not None:
|
| 68 |
+
try:
|
| 69 |
+
vec[idx[k]] = float(v)
|
| 70 |
+
except (TypeError, ValueError):
|
| 71 |
+
pass
|
| 72 |
+
rows.append(vec)
|
| 73 |
+
pos.append(i)
|
| 74 |
+
out.append(None)
|
| 75 |
+
|
| 76 |
+
if rows:
|
| 77 |
+
proba = clf.predict_proba(np.array(rows))[:, 1]
|
| 78 |
+
for p_i, p in zip(pos, proba):
|
| 79 |
+
out[p_i] = {"scoreable": True, "score": round(float(p), 4),
|
| 80 |
+
"verdict": "attack" if p >= threshold else "benign", "threshold": threshold}
|
| 81 |
+
return out
|
| 82 |
+
|
| 83 |
+
|
| 84 |
+
if __name__ == "__main__":
|
| 85 |
+
import sys
|
| 86 |
+
m = load(sys.argv[1] if len(sys.argv) > 1 else "model.joblib")
|
| 87 |
+
print(f"loaded nr-network-known-class-detector: {len(m['feature_names'])} features, "
|
| 88 |
+
f"corpus {m.get('corpus_bundle_count')} bundles, version {m.get('features_version')}, "
|
| 89 |
+
f"sha {m.get('corpus_sha256')}")
|