simonmorley commited on
Commit
6c9c811
·
verified ·
1 Parent(s): 3d529fe

nightly: refresh public-CVE cut (automated; release-cert passing)

Browse files
Files changed (3) hide show
  1. README.md +10 -12
  2. example_records.json +6 -6
  3. model.joblib +2 -2
README.md CHANGED
@@ -45,10 +45,10 @@ trained on `public-cve-replication` primitives only).
45
  - Decision threshold 0.5 (calibrated). Inference is **scoreability-gated**: a record with no network
46
  signal (e.g. an economic/DeFi bundle) returns `scoreable=False` with no verdict.
47
 
48
- ## Training data — 142 public-CVE attack primitives, 18 chains, 2011 bundles
49
 
50
- **This is the public-CVE cut** (`public-cve-replication` only): 1432 attack + 579 benign
51
- bundles (`pcap + responses + manifest`), 148 chain×primitive instances. Benign traffic
52
  exercises the **same methods / wire messages** the attacks abuse, at normal scale — so the model
53
  separates attack-*use* from benign-*use*, not message type. Every attack reproduces an external public
54
  disclosure with a `provenance.public_source` URL. (0 `original` primitives — NullRabbit's own
@@ -60,7 +60,7 @@ above is literal.)
60
  |---|---|---|---|
61
  | `bitcoin_dup_input_crash` | Bitcoin · p2p | [CVE-2018-17144](https://bitcoincore.org/en/2018/09/20/notice/) | public-cve-replication |
62
  | `bitcoin_tx_relay_jamming` | Bitcoin · p2p | [CVE-2024-55563](https://nvd.nist.gov/vuln/detail/CVE-2024-55563) | public-cve-replication |
63
- | `btc_addr_overflow_flood` | Bitcoin / Dogecoin / Litecoin · p2p | [CVE-2024-52919](https://bitcoincore.org/en/2025/04/28/disclose-cve-2024-52919/) | public-cve-replication |
64
  | `btc_alert_flood` | Bitcoin · p2p | [CVE-2016-10724](https://nvd.nist.gov/vuln/detail/CVE-2016-10724) | public-cve-replication |
65
  | `btc_blocktxn_double_fillblock` | Bitcoin · p2p | [CVE-2024-35202](https://bitcoincore.org/en/2024/10/08/disclose-blocktxn-crash/) | public-cve-replication |
66
  | `btc_bloom_divzero` | Bitcoin · p2p | [CVE-2013-5700](https://nvd.nist.gov/vuln/detail/CVE-2013-5700) | public-cve-replication |
@@ -74,7 +74,7 @@ above is literal.)
74
  | `btc_invalid_block_logfill` | Bitcoin · p2p | [CVE-2025-54605](https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-54605/) | public-cve-replication |
75
  | `btc_invdos_flood` | Bitcoin · p2p | [CVE-2018-17145](https://invdos.net/) | public-cve-replication |
76
  | `btc_mutated_block` | Bitcoin · p2p | [CVE-2024-52921](https://bitcoincore.org/en/2024/10/08/disclose-mutated-blocks-hindering-propagation/) | public-cve-replication |
77
- | `btc_orphan_cpu` | Bitcoin / Dogecoin / Litecoin · p2p | [CVE-2024-52914](https://bitcoincore.org/en/2024/07/03/disclose-orphan-dos/) | public-cve-replication |
78
  | `btc_oversized_recv_buffer` | Bitcoin · p2p | [CVE-2015-3641](https://bitcoincore.org/en/2024/07/03/disclose_receive_buffer_oom/) | public-cve-replication |
79
  | `btc_tx_maprelay` | Bitcoin · p2p | [CVE-2013-4627](https://nvd.nist.gov/vuln/detail/CVE-2013-4627) | public-cve-replication |
80
  | `btc_tx_quad_sighash` | Bitcoin · p2p | [CVE-2025-46598](https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-46598/) | public-cve-replication |
@@ -97,7 +97,6 @@ above is literal.)
97
  | `cosmos_tx_malformed_authinfo_nil_panic` | Cosmos · cometbft-rpc-http | [public disclosure](https://github.com/cosmos/cosmos-sdk/pull/26527) | public-cve-replication |
98
  | `cosmos_vesting_blocked_address` | Cosmos · cometbft-rpc-http | [GHSA-4j93-fm92-rp4m](https://github.com/advisories/GHSA-4j93-fm92-rp4m) | public-cve-replication |
99
  | `cosmwasm_validate_basic_address_count` | Cosmos · cometbft-rpc-http | [GHSA-m3rh-cvr5-x6q4](https://github.com/advisories/GHSA-m3rh-cvr5-x6q4) | public-cve-replication |
100
- | `besu_unbounded_filter_repository` | Ethereum · besu-http-rpc | [public disclosure](https://github.com/advisories/GHSA-vff7-xxjc-rccp) | public-cve-replication |
101
  | `discv4_findnode_amplification` | Ethereum · devp2p-discv4-udp | [public disclosure](NethermindEth/nethermind#12211 — 'Resolve some discovery dos vectors (which hive revealed)': discv4 (UDP node-discovery) DoS mitigation — endpoint-proof bonding tied to the exact UDP IP:port before honouring FINDNODE, plus a 50/50 request/response rate-limit split so NEIGHBORS response bursts can't starve legitimate queries. https://github.com/NethermindEth/nethermind/pull/12211) | public-cve-replication |
102
  | `geth_alien_peer_pool_pollution` | Ethereum · devp2p-rlpx | [public disclosure](https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md) | public-cve-replication |
103
  | `geth_auth_zero_pubkey` | Ethereum · devp2p-rlpx | [CVE-2025-24883](https://github.com/ethereum/go-ethereum/security/advisories/GHSA-q26p-9cq4-7fc2) | public-cve-replication |
@@ -147,7 +146,6 @@ above is literal.)
147
  | `conflux_light_storageroots_mptvalue_panic` | conflux · conflux-clp-light | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3497) | public-cve-replication |
148
  | `conflux_manifest_trienode_hash_panic` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3535) | public-cve-replication |
149
  | `conflux_newblock_header_custom_oom` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3541) | public-cve-replication |
150
- | `conflux_snapshot_chunk_overlong_key_path_steps_panic` | conflux · conflux-p2p-state-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3560) | public-cve-replication |
151
  | `conflux_snapshot_manifest_blame_underflow` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3504) | public-cve-replication |
152
  | `envoy_http2_hpack_cookie_amplification` | http2 · http2-hpack-headers | [CVE-2026-47774](CVE-2026-47774 / GHSA-22m2-hvr2-xqc8 (https://github.com/envoyproxy/envoy/security/advisories/GHSA-22m2-hvr2-xqc8). Envoy HTTP/2 codec (oghttp2/quiche): HPACK header-block limits enforced on ENCODED bytes with no total-DECODED-size limit, plus cookie bytes escaping max_request_headers_kb accounting. Affected Envoy < 1.39; patched 1.35.11 / 1.36.7 / 1.37.3 / 1.38.1. CWE-405 + CWE-770; CVSS 7.5.) | public-cve-replication |
153
  | `http2_bomb_indexed_ref_window_pin` | http2 · http2-hpack-headers+flowcontrol | [CVE-2026-49975](CVE-2026-49975 ("HTTP/2 Bomb"). HTTP/2 servers (nginx <1.29.8, Apache httpd mod_http2 <2.0.41, Envoy <=1.37.2, Cloudflare Pingora) enforce HPACK limits on ENCODED header-block bytes without bounding the total DECODED header list, and hold each stream's amplified decoded allocation until the stream makes flow-control progress. An attacker seeds the HPACK dynamic table with one generic header then emits thousands of 1-byte indexed references (0x80|62=0xBE, ~5,700:1 decoded-size amplification) WHILE advertising a zero-byte flow-control window (SETTINGS_INITIAL_WINDOW_SIZE=0) and dripping 1-byte WINDOW_UPDATE frames, PINNING the amplified allocation (server can't drain it): ~32 GiB pinned in <20 s from ONE connection -> OOM. CWE-405 + CWE-770 + CWE-400.) | public-cve-replication |
@@ -201,8 +199,8 @@ above is literal.)
201
  | `s2n_quic_crypto_offset_amplification` | quic · quic-transport | [CVE-2026-10740](CVE-2026-10740 / GHSA-9q54-f358-3fqf — aws/s2n-quic: CRYPTO-frame offset amplification. The CRYPTO-frame reassembly buffer lacks maximum-size enforcement, so a CRYPTO frame (type 0x06) carrying an artificially HIGH offset forces the receiver to reserve reassembly buffer up to that offset even though the delivered body is tiny: a single ~1200-byte packet causes ~9.4 MB of allocation (~7800x). No authentication or valid handshake is required — the crafted CRYPTO frames ride pre-handshake QUIC Initial packets, so an unauthenticated peer can repeatedly transmit them to exhaust server memory (availability DoS, CVSS 3.1 5.3). Affected s2n-quic <= 1.81.0; fixed in 1.82.0. Advisory: https://github.com/aws/s2n-quic/security/advisories/GHSA-9q54-f358-3fqf) | public-cve-replication |
202
  | `s2n_quic_stream_limit_exhaustion` | quic · quic-transport | [GHSA-475v-pq2g-fp9g](GHSA-475v-pq2g-fp9g — AWS s2n-quic <= v1.30.0: 's2n-quic potential denial of service via crafted stream frames' — uncontrolled stream-limit increase when closing remote-initiated streams. https://github.com/aws/s2n-quic/security/advisories/GHSA-475v-pq2g-fp9g) | public-cve-replication |
203
 
204
- Distribution: **1432** `public-cve-replication` attack bundles — **142 distinct primitives
205
- across 18 chains** (Bitcoin, conflux, Cosmos, Dogecoin, Ethereum, http2, http3, ipfs, libp2p, Litecoin, Monero, namada, nimiq, polkadot, quic, Solana, Sui, Zcash) — plus **579** benign. This published cut contains
206
  **no `original` bundles**; the `original` RPC-measurement primitives live in the full internal corpus
207
  and ship only if the operator explicitly opts in, always under their honest label.
208
 
@@ -220,9 +218,9 @@ the numbers below always match the shipped model.
220
  Diagnostic ML checks (the corpus of faithfully-modelled public attacks is the deliverable; these are
221
  secondary). Reproduced by `scripts/known_class_loco_eval.py` + `scripts/corpus_quality.py`.
222
 
223
- - **Within-corpus held-out — binary attack-vs-benign ROC-AUC, GroupKFold by primitive: 0.9689.** `corpus_sha256 known-class-v10-publiccve`.
224
- - **Leave-one-chain-out — binary ROC-AUC (HARD zero-shot transfer, *not* a deployment metric):** Dogecoin 1.000 / Cosmos 0.990 / Sui 0.989 / Litecoin 0.979 / Solana 0.964 / Ethereum 0.957 / Bitcoin 0.912 / Monero 0.901 / libp2p 0.835 / Zcash 0.640. Chains with few public-CVE primitives have the fewest cross-chain near-neighbours; the companion [`nr-bundles-public`](https://huggingface.co/datasets/NullRabbit/nr-bundles-public) dataset card reports the *stricter* held-out-chain 7-class family macro-F1 (0.17 Sui / 0.35 Solana vs ~0.14 floor). Reported honestly, not a deployment claim.
225
- - **Leave-one-attack-primitive-out within Bitcoin (leak-clean disjoint-benign):** all Bitcoin primitives ≥ 0.998. Detection is on traffic *shape*, not deep wire-semantics.
226
 
227
  ## Intended uses
228
 
 
45
  - Decision threshold 0.5 (calibrated). Inference is **scoreability-gated**: a record with no network
46
  signal (e.g. an economic/DeFi bundle) returns `scoreable=False` with no verdict.
47
 
48
+ ## Training data — 140 public-CVE attack primitives, 18 chains, 919 bundles
49
 
50
+ **This is the public-CVE cut** (`public-cve-replication` only): 716 attack + 203 benign
51
+ bundles (`pcap + responses + manifest`), 142 chain×primitive instances. Benign traffic
52
  exercises the **same methods / wire messages** the attacks abuse, at normal scale — so the model
53
  separates attack-*use* from benign-*use*, not message type. Every attack reproduces an external public
54
  disclosure with a `provenance.public_source` URL. (0 `original` primitives — NullRabbit's own
 
60
  |---|---|---|---|
61
  | `bitcoin_dup_input_crash` | Bitcoin · p2p | [CVE-2018-17144](https://bitcoincore.org/en/2018/09/20/notice/) | public-cve-replication |
62
  | `bitcoin_tx_relay_jamming` | Bitcoin · p2p | [CVE-2024-55563](https://nvd.nist.gov/vuln/detail/CVE-2024-55563) | public-cve-replication |
63
+ | `btc_addr_overflow_flood` | Bitcoin · p2p | [CVE-2024-52919](https://bitcoincore.org/en/2025/04/28/disclose-cve-2024-52919/) | public-cve-replication |
64
  | `btc_alert_flood` | Bitcoin · p2p | [CVE-2016-10724](https://nvd.nist.gov/vuln/detail/CVE-2016-10724) | public-cve-replication |
65
  | `btc_blocktxn_double_fillblock` | Bitcoin · p2p | [CVE-2024-35202](https://bitcoincore.org/en/2024/10/08/disclose-blocktxn-crash/) | public-cve-replication |
66
  | `btc_bloom_divzero` | Bitcoin · p2p | [CVE-2013-5700](https://nvd.nist.gov/vuln/detail/CVE-2013-5700) | public-cve-replication |
 
74
  | `btc_invalid_block_logfill` | Bitcoin · p2p | [CVE-2025-54605](https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-54605/) | public-cve-replication |
75
  | `btc_invdos_flood` | Bitcoin · p2p | [CVE-2018-17145](https://invdos.net/) | public-cve-replication |
76
  | `btc_mutated_block` | Bitcoin · p2p | [CVE-2024-52921](https://bitcoincore.org/en/2024/10/08/disclose-mutated-blocks-hindering-propagation/) | public-cve-replication |
77
+ | `btc_orphan_cpu` | Bitcoin · p2p | [CVE-2024-52914](https://bitcoincore.org/en/2024/07/03/disclose-orphan-dos/) | public-cve-replication |
78
  | `btc_oversized_recv_buffer` | Bitcoin · p2p | [CVE-2015-3641](https://bitcoincore.org/en/2024/07/03/disclose_receive_buffer_oom/) | public-cve-replication |
79
  | `btc_tx_maprelay` | Bitcoin · p2p | [CVE-2013-4627](https://nvd.nist.gov/vuln/detail/CVE-2013-4627) | public-cve-replication |
80
  | `btc_tx_quad_sighash` | Bitcoin · p2p | [CVE-2025-46598](https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-46598/) | public-cve-replication |
 
97
  | `cosmos_tx_malformed_authinfo_nil_panic` | Cosmos · cometbft-rpc-http | [public disclosure](https://github.com/cosmos/cosmos-sdk/pull/26527) | public-cve-replication |
98
  | `cosmos_vesting_blocked_address` | Cosmos · cometbft-rpc-http | [GHSA-4j93-fm92-rp4m](https://github.com/advisories/GHSA-4j93-fm92-rp4m) | public-cve-replication |
99
  | `cosmwasm_validate_basic_address_count` | Cosmos · cometbft-rpc-http | [GHSA-m3rh-cvr5-x6q4](https://github.com/advisories/GHSA-m3rh-cvr5-x6q4) | public-cve-replication |
 
100
  | `discv4_findnode_amplification` | Ethereum · devp2p-discv4-udp | [public disclosure](NethermindEth/nethermind#12211 — 'Resolve some discovery dos vectors (which hive revealed)': discv4 (UDP node-discovery) DoS mitigation — endpoint-proof bonding tied to the exact UDP IP:port before honouring FINDNODE, plus a 50/50 request/response rate-limit split so NEIGHBORS response bursts can't starve legitimate queries. https://github.com/NethermindEth/nethermind/pull/12211) | public-cve-replication |
101
  | `geth_alien_peer_pool_pollution` | Ethereum · devp2p-rlpx | [public disclosure](https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md) | public-cve-replication |
102
  | `geth_auth_zero_pubkey` | Ethereum · devp2p-rlpx | [CVE-2025-24883](https://github.com/ethereum/go-ethereum/security/advisories/GHSA-q26p-9cq4-7fc2) | public-cve-replication |
 
146
  | `conflux_light_storageroots_mptvalue_panic` | conflux · conflux-clp-light | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3497) | public-cve-replication |
147
  | `conflux_manifest_trienode_hash_panic` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3535) | public-cve-replication |
148
  | `conflux_newblock_header_custom_oom` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3541) | public-cve-replication |
 
149
  | `conflux_snapshot_manifest_blame_underflow` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3504) | public-cve-replication |
150
  | `envoy_http2_hpack_cookie_amplification` | http2 · http2-hpack-headers | [CVE-2026-47774](CVE-2026-47774 / GHSA-22m2-hvr2-xqc8 (https://github.com/envoyproxy/envoy/security/advisories/GHSA-22m2-hvr2-xqc8). Envoy HTTP/2 codec (oghttp2/quiche): HPACK header-block limits enforced on ENCODED bytes with no total-DECODED-size limit, plus cookie bytes escaping max_request_headers_kb accounting. Affected Envoy < 1.39; patched 1.35.11 / 1.36.7 / 1.37.3 / 1.38.1. CWE-405 + CWE-770; CVSS 7.5.) | public-cve-replication |
151
  | `http2_bomb_indexed_ref_window_pin` | http2 · http2-hpack-headers+flowcontrol | [CVE-2026-49975](CVE-2026-49975 ("HTTP/2 Bomb"). HTTP/2 servers (nginx <1.29.8, Apache httpd mod_http2 <2.0.41, Envoy <=1.37.2, Cloudflare Pingora) enforce HPACK limits on ENCODED header-block bytes without bounding the total DECODED header list, and hold each stream's amplified decoded allocation until the stream makes flow-control progress. An attacker seeds the HPACK dynamic table with one generic header then emits thousands of 1-byte indexed references (0x80|62=0xBE, ~5,700:1 decoded-size amplification) WHILE advertising a zero-byte flow-control window (SETTINGS_INITIAL_WINDOW_SIZE=0) and dripping 1-byte WINDOW_UPDATE frames, PINNING the amplified allocation (server can't drain it): ~32 GiB pinned in <20 s from ONE connection -> OOM. CWE-405 + CWE-770 + CWE-400.) | public-cve-replication |
 
199
  | `s2n_quic_crypto_offset_amplification` | quic · quic-transport | [CVE-2026-10740](CVE-2026-10740 / GHSA-9q54-f358-3fqf — aws/s2n-quic: CRYPTO-frame offset amplification. The CRYPTO-frame reassembly buffer lacks maximum-size enforcement, so a CRYPTO frame (type 0x06) carrying an artificially HIGH offset forces the receiver to reserve reassembly buffer up to that offset even though the delivered body is tiny: a single ~1200-byte packet causes ~9.4 MB of allocation (~7800x). No authentication or valid handshake is required — the crafted CRYPTO frames ride pre-handshake QUIC Initial packets, so an unauthenticated peer can repeatedly transmit them to exhaust server memory (availability DoS, CVSS 3.1 5.3). Affected s2n-quic <= 1.81.0; fixed in 1.82.0. Advisory: https://github.com/aws/s2n-quic/security/advisories/GHSA-9q54-f358-3fqf) | public-cve-replication |
200
  | `s2n_quic_stream_limit_exhaustion` | quic · quic-transport | [GHSA-475v-pq2g-fp9g](GHSA-475v-pq2g-fp9g — AWS s2n-quic <= v1.30.0: 's2n-quic potential denial of service via crafted stream frames' — uncontrolled stream-limit increase when closing remote-initiated streams. https://github.com/aws/s2n-quic/security/advisories/GHSA-475v-pq2g-fp9g) | public-cve-replication |
201
 
202
+ Distribution: **716** `public-cve-replication` attack bundles — **140 distinct primitives
203
+ across 18 chains** (Bitcoin, conflux, Cosmos, Dogecoin, Ethereum, http2, http3, ipfs, libp2p, Litecoin, Monero, namada, nimiq, polkadot, quic, Solana, Sui, Zcash) — plus **203** benign. This published cut contains
204
  **no `original` bundles**; the `original` RPC-measurement primitives live in the full internal corpus
205
  and ship only if the operator explicitly opts in, always under their honest label.
206
 
 
218
  Diagnostic ML checks (the corpus of faithfully-modelled public attacks is the deliverable; these are
219
  secondary). Reproduced by `scripts/known_class_loco_eval.py` + `scripts/corpus_quality.py`.
220
 
221
+ - **Within-corpus held-out — binary attack-vs-benign ROC-AUC, GroupKFold by primitive: 0.9441.** `corpus_sha256 known-class-v10-publiccve`.
222
+ - **Leave-one-chain-out — binary ROC-AUC (HARD zero-shot transfer, *not* a deployment metric):** Sui 1.000 / Ethereum 0.992 / Monero 0.985 / libp2p 0.897 / Bitcoin 0.818 / Cosmos 0.789 / Zcash 0.590. Chains with few public-CVE primitives have the fewest cross-chain near-neighbours; the companion [`nr-bundles-public`](https://huggingface.co/datasets/NullRabbit/nr-bundles-public) dataset card reports the *stricter* held-out-chain 7-class family macro-F1 (0.17 Sui / 0.35 Solana vs ~0.14 floor). Reported honestly, not a deployment claim.
223
+ - **Leave-one-attack-primitive-out within Bitcoin (leak-clean disjoint-benign):** all Bitcoin primitives ≥ 0.958. Detection is on traffic *shape*, not deep wire-semantics.
224
 
225
  ## Intended uses
226
 
example_records.json CHANGED
@@ -32,18 +32,18 @@
32
  }
33
  },
34
  {
35
- "label": "solana:sol_tpu_quic_initial_cpu",
36
  "expect": "attack",
37
  "feat": {
38
  "app.distinct_metric_names": 0.0,
39
- "pcap.bytes_per_s": 13828.406,
40
  "pcap.distinct_dst_ips": 0.0,
41
  "pcap.distinct_src_dst_pairs": 0.0,
42
  "pcap.distinct_src_ips": 0.0,
43
- "pcap.duration_s": 7.035,
44
  "pcap.mean_packet_size": 256.0,
45
- "pcap.packet_count": 380.0,
46
- "pcap.packets_per_s": 54.017,
47
  "pcap.rst_fraction": 0.0,
48
  "pcap.syn_to_handshake_ratio": 0.0,
49
  "pcap.tcp_fin": 0.0,
@@ -56,7 +56,7 @@
56
  "pcap.top_dst_port_fraction": 0.0,
57
  "pcap.top_src_port": 0.0,
58
  "pcap.top_src_port_fraction": 0.0,
59
- "pcap.total_bytes": 97280.0,
60
  "pcap.unique_dst_ports": 0.0,
61
  "pcap.unique_src_ports": 0.0,
62
  "resp.count": 0.0,
 
32
  }
33
  },
34
  {
35
+ "label": "solana:sol_tpu_quic_handshake_flood",
36
  "expect": "attack",
37
  "feat": {
38
  "app.distinct_metric_names": 0.0,
39
+ "pcap.bytes_per_s": 28177.114,
40
  "pcap.distinct_dst_ips": 0.0,
41
  "pcap.distinct_src_dst_pairs": 0.0,
42
  "pcap.distinct_src_ips": 0.0,
43
+ "pcap.duration_s": 5.815,
44
  "pcap.mean_packet_size": 256.0,
45
+ "pcap.packet_count": 640.0,
46
+ "pcap.packets_per_s": 110.067,
47
  "pcap.rst_fraction": 0.0,
48
  "pcap.syn_to_handshake_ratio": 0.0,
49
  "pcap.tcp_fin": 0.0,
 
56
  "pcap.top_dst_port_fraction": 0.0,
57
  "pcap.top_src_port": 0.0,
58
  "pcap.top_src_port_fraction": 0.0,
59
+ "pcap.total_bytes": 163840.0,
60
  "pcap.unique_dst_ports": 0.0,
61
  "pcap.unique_src_ports": 0.0,
62
  "resp.count": 0.0,
model.joblib CHANGED
@@ -1,3 +1,3 @@
1
  version https://git-lfs.github.com/spec/v1
2
- oid sha256:11cba870291b9b46e2cbb87d068bebcc067f5c89fc57df002cdc536875ec61df
3
- size 3675741
 
1
  version https://git-lfs.github.com/spec/v1
2
+ oid sha256:c2cd427f67f8268f2b703ee0f60f2309a3de688a0fcc9fe6ce0851f85a08c127
3
+ size 3059116