nightly: refresh public-CVE cut (automated; release-cert passing)
Browse files- README.md +10 -12
- example_records.json +6 -6
- model.joblib +2 -2
README.md
CHANGED
|
@@ -45,10 +45,10 @@ trained on `public-cve-replication` primitives only).
|
|
| 45 |
- Decision threshold 0.5 (calibrated). Inference is **scoreability-gated**: a record with no network
|
| 46 |
signal (e.g. an economic/DeFi bundle) returns `scoreable=False` with no verdict.
|
| 47 |
|
| 48 |
-
## Training data —
|
| 49 |
|
| 50 |
-
**This is the public-CVE cut** (`public-cve-replication` only):
|
| 51 |
-
bundles (`pcap + responses + manifest`),
|
| 52 |
exercises the **same methods / wire messages** the attacks abuse, at normal scale — so the model
|
| 53 |
separates attack-*use* from benign-*use*, not message type. Every attack reproduces an external public
|
| 54 |
disclosure with a `provenance.public_source` URL. (0 `original` primitives — NullRabbit's own
|
|
@@ -60,7 +60,7 @@ above is literal.)
|
|
| 60 |
|---|---|---|---|
|
| 61 |
| `bitcoin_dup_input_crash` | Bitcoin · p2p | [CVE-2018-17144](https://bitcoincore.org/en/2018/09/20/notice/) | public-cve-replication |
|
| 62 |
| `bitcoin_tx_relay_jamming` | Bitcoin · p2p | [CVE-2024-55563](https://nvd.nist.gov/vuln/detail/CVE-2024-55563) | public-cve-replication |
|
| 63 |
-
| `btc_addr_overflow_flood` | Bitcoin
|
| 64 |
| `btc_alert_flood` | Bitcoin · p2p | [CVE-2016-10724](https://nvd.nist.gov/vuln/detail/CVE-2016-10724) | public-cve-replication |
|
| 65 |
| `btc_blocktxn_double_fillblock` | Bitcoin · p2p | [CVE-2024-35202](https://bitcoincore.org/en/2024/10/08/disclose-blocktxn-crash/) | public-cve-replication |
|
| 66 |
| `btc_bloom_divzero` | Bitcoin · p2p | [CVE-2013-5700](https://nvd.nist.gov/vuln/detail/CVE-2013-5700) | public-cve-replication |
|
|
@@ -74,7 +74,7 @@ above is literal.)
|
|
| 74 |
| `btc_invalid_block_logfill` | Bitcoin · p2p | [CVE-2025-54605](https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-54605/) | public-cve-replication |
|
| 75 |
| `btc_invdos_flood` | Bitcoin · p2p | [CVE-2018-17145](https://invdos.net/) | public-cve-replication |
|
| 76 |
| `btc_mutated_block` | Bitcoin · p2p | [CVE-2024-52921](https://bitcoincore.org/en/2024/10/08/disclose-mutated-blocks-hindering-propagation/) | public-cve-replication |
|
| 77 |
-
| `btc_orphan_cpu` | Bitcoin
|
| 78 |
| `btc_oversized_recv_buffer` | Bitcoin · p2p | [CVE-2015-3641](https://bitcoincore.org/en/2024/07/03/disclose_receive_buffer_oom/) | public-cve-replication |
|
| 79 |
| `btc_tx_maprelay` | Bitcoin · p2p | [CVE-2013-4627](https://nvd.nist.gov/vuln/detail/CVE-2013-4627) | public-cve-replication |
|
| 80 |
| `btc_tx_quad_sighash` | Bitcoin · p2p | [CVE-2025-46598](https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-46598/) | public-cve-replication |
|
|
@@ -97,7 +97,6 @@ above is literal.)
|
|
| 97 |
| `cosmos_tx_malformed_authinfo_nil_panic` | Cosmos · cometbft-rpc-http | [public disclosure](https://github.com/cosmos/cosmos-sdk/pull/26527) | public-cve-replication |
|
| 98 |
| `cosmos_vesting_blocked_address` | Cosmos · cometbft-rpc-http | [GHSA-4j93-fm92-rp4m](https://github.com/advisories/GHSA-4j93-fm92-rp4m) | public-cve-replication |
|
| 99 |
| `cosmwasm_validate_basic_address_count` | Cosmos · cometbft-rpc-http | [GHSA-m3rh-cvr5-x6q4](https://github.com/advisories/GHSA-m3rh-cvr5-x6q4) | public-cve-replication |
|
| 100 |
-
| `besu_unbounded_filter_repository` | Ethereum · besu-http-rpc | [public disclosure](https://github.com/advisories/GHSA-vff7-xxjc-rccp) | public-cve-replication |
|
| 101 |
| `discv4_findnode_amplification` | Ethereum · devp2p-discv4-udp | [public disclosure](NethermindEth/nethermind#12211 — 'Resolve some discovery dos vectors (which hive revealed)': discv4 (UDP node-discovery) DoS mitigation — endpoint-proof bonding tied to the exact UDP IP:port before honouring FINDNODE, plus a 50/50 request/response rate-limit split so NEIGHBORS response bursts can't starve legitimate queries. https://github.com/NethermindEth/nethermind/pull/12211) | public-cve-replication |
|
| 102 |
| `geth_alien_peer_pool_pollution` | Ethereum · devp2p-rlpx | [public disclosure](https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md) | public-cve-replication |
|
| 103 |
| `geth_auth_zero_pubkey` | Ethereum · devp2p-rlpx | [CVE-2025-24883](https://github.com/ethereum/go-ethereum/security/advisories/GHSA-q26p-9cq4-7fc2) | public-cve-replication |
|
|
@@ -147,7 +146,6 @@ above is literal.)
|
|
| 147 |
| `conflux_light_storageroots_mptvalue_panic` | conflux · conflux-clp-light | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3497) | public-cve-replication |
|
| 148 |
| `conflux_manifest_trienode_hash_panic` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3535) | public-cve-replication |
|
| 149 |
| `conflux_newblock_header_custom_oom` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3541) | public-cve-replication |
|
| 150 |
-
| `conflux_snapshot_chunk_overlong_key_path_steps_panic` | conflux · conflux-p2p-state-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3560) | public-cve-replication |
|
| 151 |
| `conflux_snapshot_manifest_blame_underflow` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3504) | public-cve-replication |
|
| 152 |
| `envoy_http2_hpack_cookie_amplification` | http2 · http2-hpack-headers | [CVE-2026-47774](CVE-2026-47774 / GHSA-22m2-hvr2-xqc8 (https://github.com/envoyproxy/envoy/security/advisories/GHSA-22m2-hvr2-xqc8). Envoy HTTP/2 codec (oghttp2/quiche): HPACK header-block limits enforced on ENCODED bytes with no total-DECODED-size limit, plus cookie bytes escaping max_request_headers_kb accounting. Affected Envoy < 1.39; patched 1.35.11 / 1.36.7 / 1.37.3 / 1.38.1. CWE-405 + CWE-770; CVSS 7.5.) | public-cve-replication |
|
| 153 |
| `http2_bomb_indexed_ref_window_pin` | http2 · http2-hpack-headers+flowcontrol | [CVE-2026-49975](CVE-2026-49975 ("HTTP/2 Bomb"). HTTP/2 servers (nginx <1.29.8, Apache httpd mod_http2 <2.0.41, Envoy <=1.37.2, Cloudflare Pingora) enforce HPACK limits on ENCODED header-block bytes without bounding the total DECODED header list, and hold each stream's amplified decoded allocation until the stream makes flow-control progress. An attacker seeds the HPACK dynamic table with one generic header then emits thousands of 1-byte indexed references (0x80|62=0xBE, ~5,700:1 decoded-size amplification) WHILE advertising a zero-byte flow-control window (SETTINGS_INITIAL_WINDOW_SIZE=0) and dripping 1-byte WINDOW_UPDATE frames, PINNING the amplified allocation (server can't drain it): ~32 GiB pinned in <20 s from ONE connection -> OOM. CWE-405 + CWE-770 + CWE-400.) | public-cve-replication |
|
|
@@ -201,8 +199,8 @@ above is literal.)
|
|
| 201 |
| `s2n_quic_crypto_offset_amplification` | quic · quic-transport | [CVE-2026-10740](CVE-2026-10740 / GHSA-9q54-f358-3fqf — aws/s2n-quic: CRYPTO-frame offset amplification. The CRYPTO-frame reassembly buffer lacks maximum-size enforcement, so a CRYPTO frame (type 0x06) carrying an artificially HIGH offset forces the receiver to reserve reassembly buffer up to that offset even though the delivered body is tiny: a single ~1200-byte packet causes ~9.4 MB of allocation (~7800x). No authentication or valid handshake is required — the crafted CRYPTO frames ride pre-handshake QUIC Initial packets, so an unauthenticated peer can repeatedly transmit them to exhaust server memory (availability DoS, CVSS 3.1 5.3). Affected s2n-quic <= 1.81.0; fixed in 1.82.0. Advisory: https://github.com/aws/s2n-quic/security/advisories/GHSA-9q54-f358-3fqf) | public-cve-replication |
|
| 202 |
| `s2n_quic_stream_limit_exhaustion` | quic · quic-transport | [GHSA-475v-pq2g-fp9g](GHSA-475v-pq2g-fp9g — AWS s2n-quic <= v1.30.0: 's2n-quic potential denial of service via crafted stream frames' — uncontrolled stream-limit increase when closing remote-initiated streams. https://github.com/aws/s2n-quic/security/advisories/GHSA-475v-pq2g-fp9g) | public-cve-replication |
|
| 203 |
|
| 204 |
-
Distribution: **
|
| 205 |
-
across 18 chains** (Bitcoin, conflux, Cosmos, Dogecoin, Ethereum, http2, http3, ipfs, libp2p, Litecoin, Monero, namada, nimiq, polkadot, quic, Solana, Sui, Zcash) — plus **
|
| 206 |
**no `original` bundles**; the `original` RPC-measurement primitives live in the full internal corpus
|
| 207 |
and ship only if the operator explicitly opts in, always under their honest label.
|
| 208 |
|
|
@@ -220,9 +218,9 @@ the numbers below always match the shipped model.
|
|
| 220 |
Diagnostic ML checks (the corpus of faithfully-modelled public attacks is the deliverable; these are
|
| 221 |
secondary). Reproduced by `scripts/known_class_loco_eval.py` + `scripts/corpus_quality.py`.
|
| 222 |
|
| 223 |
-
- **Within-corpus held-out — binary attack-vs-benign ROC-AUC, GroupKFold by primitive: 0.
|
| 224 |
-
- **Leave-one-chain-out — binary ROC-AUC (HARD zero-shot transfer, *not* a deployment metric):**
|
| 225 |
-
- **Leave-one-attack-primitive-out within Bitcoin (leak-clean disjoint-benign):** all Bitcoin primitives ≥ 0.
|
| 226 |
|
| 227 |
## Intended uses
|
| 228 |
|
|
|
|
| 45 |
- Decision threshold 0.5 (calibrated). Inference is **scoreability-gated**: a record with no network
|
| 46 |
signal (e.g. an economic/DeFi bundle) returns `scoreable=False` with no verdict.
|
| 47 |
|
| 48 |
+
## Training data — 140 public-CVE attack primitives, 18 chains, 919 bundles
|
| 49 |
|
| 50 |
+
**This is the public-CVE cut** (`public-cve-replication` only): 716 attack + 203 benign
|
| 51 |
+
bundles (`pcap + responses + manifest`), 142 chain×primitive instances. Benign traffic
|
| 52 |
exercises the **same methods / wire messages** the attacks abuse, at normal scale — so the model
|
| 53 |
separates attack-*use* from benign-*use*, not message type. Every attack reproduces an external public
|
| 54 |
disclosure with a `provenance.public_source` URL. (0 `original` primitives — NullRabbit's own
|
|
|
|
| 60 |
|---|---|---|---|
|
| 61 |
| `bitcoin_dup_input_crash` | Bitcoin · p2p | [CVE-2018-17144](https://bitcoincore.org/en/2018/09/20/notice/) | public-cve-replication |
|
| 62 |
| `bitcoin_tx_relay_jamming` | Bitcoin · p2p | [CVE-2024-55563](https://nvd.nist.gov/vuln/detail/CVE-2024-55563) | public-cve-replication |
|
| 63 |
+
| `btc_addr_overflow_flood` | Bitcoin · p2p | [CVE-2024-52919](https://bitcoincore.org/en/2025/04/28/disclose-cve-2024-52919/) | public-cve-replication |
|
| 64 |
| `btc_alert_flood` | Bitcoin · p2p | [CVE-2016-10724](https://nvd.nist.gov/vuln/detail/CVE-2016-10724) | public-cve-replication |
|
| 65 |
| `btc_blocktxn_double_fillblock` | Bitcoin · p2p | [CVE-2024-35202](https://bitcoincore.org/en/2024/10/08/disclose-blocktxn-crash/) | public-cve-replication |
|
| 66 |
| `btc_bloom_divzero` | Bitcoin · p2p | [CVE-2013-5700](https://nvd.nist.gov/vuln/detail/CVE-2013-5700) | public-cve-replication |
|
|
|
|
| 74 |
| `btc_invalid_block_logfill` | Bitcoin · p2p | [CVE-2025-54605](https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-54605/) | public-cve-replication |
|
| 75 |
| `btc_invdos_flood` | Bitcoin · p2p | [CVE-2018-17145](https://invdos.net/) | public-cve-replication |
|
| 76 |
| `btc_mutated_block` | Bitcoin · p2p | [CVE-2024-52921](https://bitcoincore.org/en/2024/10/08/disclose-mutated-blocks-hindering-propagation/) | public-cve-replication |
|
| 77 |
+
| `btc_orphan_cpu` | Bitcoin · p2p | [CVE-2024-52914](https://bitcoincore.org/en/2024/07/03/disclose-orphan-dos/) | public-cve-replication |
|
| 78 |
| `btc_oversized_recv_buffer` | Bitcoin · p2p | [CVE-2015-3641](https://bitcoincore.org/en/2024/07/03/disclose_receive_buffer_oom/) | public-cve-replication |
|
| 79 |
| `btc_tx_maprelay` | Bitcoin · p2p | [CVE-2013-4627](https://nvd.nist.gov/vuln/detail/CVE-2013-4627) | public-cve-replication |
|
| 80 |
| `btc_tx_quad_sighash` | Bitcoin · p2p | [CVE-2025-46598](https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-46598/) | public-cve-replication |
|
|
|
|
| 97 |
| `cosmos_tx_malformed_authinfo_nil_panic` | Cosmos · cometbft-rpc-http | [public disclosure](https://github.com/cosmos/cosmos-sdk/pull/26527) | public-cve-replication |
|
| 98 |
| `cosmos_vesting_blocked_address` | Cosmos · cometbft-rpc-http | [GHSA-4j93-fm92-rp4m](https://github.com/advisories/GHSA-4j93-fm92-rp4m) | public-cve-replication |
|
| 99 |
| `cosmwasm_validate_basic_address_count` | Cosmos · cometbft-rpc-http | [GHSA-m3rh-cvr5-x6q4](https://github.com/advisories/GHSA-m3rh-cvr5-x6q4) | public-cve-replication |
|
|
|
|
| 100 |
| `discv4_findnode_amplification` | Ethereum · devp2p-discv4-udp | [public disclosure](NethermindEth/nethermind#12211 — 'Resolve some discovery dos vectors (which hive revealed)': discv4 (UDP node-discovery) DoS mitigation — endpoint-proof bonding tied to the exact UDP IP:port before honouring FINDNODE, plus a 50/50 request/response rate-limit split so NEIGHBORS response bursts can't starve legitimate queries. https://github.com/NethermindEth/nethermind/pull/12211) | public-cve-replication |
|
| 101 |
| `geth_alien_peer_pool_pollution` | Ethereum · devp2p-rlpx | [public disclosure](https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md) | public-cve-replication |
|
| 102 |
| `geth_auth_zero_pubkey` | Ethereum · devp2p-rlpx | [CVE-2025-24883](https://github.com/ethereum/go-ethereum/security/advisories/GHSA-q26p-9cq4-7fc2) | public-cve-replication |
|
|
|
|
| 146 |
| `conflux_light_storageroots_mptvalue_panic` | conflux · conflux-clp-light | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3497) | public-cve-replication |
|
| 147 |
| `conflux_manifest_trienode_hash_panic` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3535) | public-cve-replication |
|
| 148 |
| `conflux_newblock_header_custom_oom` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3541) | public-cve-replication |
|
|
|
|
| 149 |
| `conflux_snapshot_manifest_blame_underflow` | conflux · conflux-cfx-sync | [public disclosure](https://github.com/Conflux-Chain/conflux-rust/pull/3504) | public-cve-replication |
|
| 150 |
| `envoy_http2_hpack_cookie_amplification` | http2 · http2-hpack-headers | [CVE-2026-47774](CVE-2026-47774 / GHSA-22m2-hvr2-xqc8 (https://github.com/envoyproxy/envoy/security/advisories/GHSA-22m2-hvr2-xqc8). Envoy HTTP/2 codec (oghttp2/quiche): HPACK header-block limits enforced on ENCODED bytes with no total-DECODED-size limit, plus cookie bytes escaping max_request_headers_kb accounting. Affected Envoy < 1.39; patched 1.35.11 / 1.36.7 / 1.37.3 / 1.38.1. CWE-405 + CWE-770; CVSS 7.5.) | public-cve-replication |
|
| 151 |
| `http2_bomb_indexed_ref_window_pin` | http2 · http2-hpack-headers+flowcontrol | [CVE-2026-49975](CVE-2026-49975 ("HTTP/2 Bomb"). HTTP/2 servers (nginx <1.29.8, Apache httpd mod_http2 <2.0.41, Envoy <=1.37.2, Cloudflare Pingora) enforce HPACK limits on ENCODED header-block bytes without bounding the total DECODED header list, and hold each stream's amplified decoded allocation until the stream makes flow-control progress. An attacker seeds the HPACK dynamic table with one generic header then emits thousands of 1-byte indexed references (0x80|62=0xBE, ~5,700:1 decoded-size amplification) WHILE advertising a zero-byte flow-control window (SETTINGS_INITIAL_WINDOW_SIZE=0) and dripping 1-byte WINDOW_UPDATE frames, PINNING the amplified allocation (server can't drain it): ~32 GiB pinned in <20 s from ONE connection -> OOM. CWE-405 + CWE-770 + CWE-400.) | public-cve-replication |
|
|
|
|
| 199 |
| `s2n_quic_crypto_offset_amplification` | quic · quic-transport | [CVE-2026-10740](CVE-2026-10740 / GHSA-9q54-f358-3fqf — aws/s2n-quic: CRYPTO-frame offset amplification. The CRYPTO-frame reassembly buffer lacks maximum-size enforcement, so a CRYPTO frame (type 0x06) carrying an artificially HIGH offset forces the receiver to reserve reassembly buffer up to that offset even though the delivered body is tiny: a single ~1200-byte packet causes ~9.4 MB of allocation (~7800x). No authentication or valid handshake is required — the crafted CRYPTO frames ride pre-handshake QUIC Initial packets, so an unauthenticated peer can repeatedly transmit them to exhaust server memory (availability DoS, CVSS 3.1 5.3). Affected s2n-quic <= 1.81.0; fixed in 1.82.0. Advisory: https://github.com/aws/s2n-quic/security/advisories/GHSA-9q54-f358-3fqf) | public-cve-replication |
|
| 200 |
| `s2n_quic_stream_limit_exhaustion` | quic · quic-transport | [GHSA-475v-pq2g-fp9g](GHSA-475v-pq2g-fp9g — AWS s2n-quic <= v1.30.0: 's2n-quic potential denial of service via crafted stream frames' — uncontrolled stream-limit increase when closing remote-initiated streams. https://github.com/aws/s2n-quic/security/advisories/GHSA-475v-pq2g-fp9g) | public-cve-replication |
|
| 201 |
|
| 202 |
+
Distribution: **716** `public-cve-replication` attack bundles — **140 distinct primitives
|
| 203 |
+
across 18 chains** (Bitcoin, conflux, Cosmos, Dogecoin, Ethereum, http2, http3, ipfs, libp2p, Litecoin, Monero, namada, nimiq, polkadot, quic, Solana, Sui, Zcash) — plus **203** benign. This published cut contains
|
| 204 |
**no `original` bundles**; the `original` RPC-measurement primitives live in the full internal corpus
|
| 205 |
and ship only if the operator explicitly opts in, always under their honest label.
|
| 206 |
|
|
|
|
| 218 |
Diagnostic ML checks (the corpus of faithfully-modelled public attacks is the deliverable; these are
|
| 219 |
secondary). Reproduced by `scripts/known_class_loco_eval.py` + `scripts/corpus_quality.py`.
|
| 220 |
|
| 221 |
+
- **Within-corpus held-out — binary attack-vs-benign ROC-AUC, GroupKFold by primitive: 0.9441.** `corpus_sha256 known-class-v10-publiccve`.
|
| 222 |
+
- **Leave-one-chain-out — binary ROC-AUC (HARD zero-shot transfer, *not* a deployment metric):** Sui 1.000 / Ethereum 0.992 / Monero 0.985 / libp2p 0.897 / Bitcoin 0.818 / Cosmos 0.789 / Zcash 0.590. Chains with few public-CVE primitives have the fewest cross-chain near-neighbours; the companion [`nr-bundles-public`](https://huggingface.co/datasets/NullRabbit/nr-bundles-public) dataset card reports the *stricter* held-out-chain 7-class family macro-F1 (0.17 Sui / 0.35 Solana vs ~0.14 floor). Reported honestly, not a deployment claim.
|
| 223 |
+
- **Leave-one-attack-primitive-out within Bitcoin (leak-clean disjoint-benign):** all Bitcoin primitives ≥ 0.958. Detection is on traffic *shape*, not deep wire-semantics.
|
| 224 |
|
| 225 |
## Intended uses
|
| 226 |
|
example_records.json
CHANGED
|
@@ -32,18 +32,18 @@
|
|
| 32 |
}
|
| 33 |
},
|
| 34 |
{
|
| 35 |
-
"label": "solana:
|
| 36 |
"expect": "attack",
|
| 37 |
"feat": {
|
| 38 |
"app.distinct_metric_names": 0.0,
|
| 39 |
-
"pcap.bytes_per_s":
|
| 40 |
"pcap.distinct_dst_ips": 0.0,
|
| 41 |
"pcap.distinct_src_dst_pairs": 0.0,
|
| 42 |
"pcap.distinct_src_ips": 0.0,
|
| 43 |
-
"pcap.duration_s":
|
| 44 |
"pcap.mean_packet_size": 256.0,
|
| 45 |
-
"pcap.packet_count":
|
| 46 |
-
"pcap.packets_per_s":
|
| 47 |
"pcap.rst_fraction": 0.0,
|
| 48 |
"pcap.syn_to_handshake_ratio": 0.0,
|
| 49 |
"pcap.tcp_fin": 0.0,
|
|
@@ -56,7 +56,7 @@
|
|
| 56 |
"pcap.top_dst_port_fraction": 0.0,
|
| 57 |
"pcap.top_src_port": 0.0,
|
| 58 |
"pcap.top_src_port_fraction": 0.0,
|
| 59 |
-
"pcap.total_bytes":
|
| 60 |
"pcap.unique_dst_ports": 0.0,
|
| 61 |
"pcap.unique_src_ports": 0.0,
|
| 62 |
"resp.count": 0.0,
|
|
|
|
| 32 |
}
|
| 33 |
},
|
| 34 |
{
|
| 35 |
+
"label": "solana:sol_tpu_quic_handshake_flood",
|
| 36 |
"expect": "attack",
|
| 37 |
"feat": {
|
| 38 |
"app.distinct_metric_names": 0.0,
|
| 39 |
+
"pcap.bytes_per_s": 28177.114,
|
| 40 |
"pcap.distinct_dst_ips": 0.0,
|
| 41 |
"pcap.distinct_src_dst_pairs": 0.0,
|
| 42 |
"pcap.distinct_src_ips": 0.0,
|
| 43 |
+
"pcap.duration_s": 5.815,
|
| 44 |
"pcap.mean_packet_size": 256.0,
|
| 45 |
+
"pcap.packet_count": 640.0,
|
| 46 |
+
"pcap.packets_per_s": 110.067,
|
| 47 |
"pcap.rst_fraction": 0.0,
|
| 48 |
"pcap.syn_to_handshake_ratio": 0.0,
|
| 49 |
"pcap.tcp_fin": 0.0,
|
|
|
|
| 56 |
"pcap.top_dst_port_fraction": 0.0,
|
| 57 |
"pcap.top_src_port": 0.0,
|
| 58 |
"pcap.top_src_port_fraction": 0.0,
|
| 59 |
+
"pcap.total_bytes": 163840.0,
|
| 60 |
"pcap.unique_dst_ports": 0.0,
|
| 61 |
"pcap.unique_src_ports": 0.0,
|
| 62 |
"resp.count": 0.0,
|
model.joblib
CHANGED
|
@@ -1,3 +1,3 @@
|
|
| 1 |
version https://git-lfs.github.com/spec/v1
|
| 2 |
-
oid sha256:
|
| 3 |
-
size
|
|
|
|
| 1 |
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:c2cd427f67f8268f2b703ee0f60f2309a3de688a0fcc9fe6ce0851f85a08c127
|
| 3 |
+
size 3059116
|