Documentation
¶
Overview ¶
Package behaviorbaseline turns the B5 per-host running-process projection plus the host's sealed runtime detections into the coverage-honest RiskContext.Behavior factor (#594 D). It maps a host's running processes to the process features of a baseline.Observation, and folds the per-class rate of the eBPF detections observed on that host in a recent window into the network / privilege / file features, so the statistical baseline scores anomalies over runtime telemetry rather than over process snapshots alone (#822). It LEARNS the asset's normal profile at report time (baselineuc.Observe, which scores-then-folds with anti-poisoning) and SCORES the current profile read-only at risk-assessment time (baselineuc.Score, no fold). Learning and scoring are separated so scoring never poisons the baseline, and the risk-assessment path (an incident is active) never learns.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type BaselineEngine ¶
type BaselineEngine interface {
Observe(ctx context.Context, actor string, key baseline.Key, obs baseline.Observation, window baseline.LearnWindow) (baselineuc.Assessment, error)
Score(ctx context.Context, key baseline.Key, obs baseline.Observation) (baselineuc.Assessment, error)
Rebaseline(ctx context.Context, actor string, key baseline.Key) error
}
BaselineEngine is the baselineuc surface this producer needs: Observe (learn+score) and Score (read-only).
type DetectionRates ¶
type DetectionRates interface {
ClassCountsByAsset(ctx context.Context, assetID shared.ID, since time.Time) (map[detection.Class]int, error)
}
DetectionRates returns the count of sealed detections observed on an asset since a cutoff, grouped by telemetry class, tenant-scoped by ctx. It is OPTIONAL: a nil DetectionRates leaves the network, privilege and file features unobserved (0), which is the pre-#822 behavior. The memory and Postgres detection-record stores satisfy it.
type ProcessLister ¶
type ProcessLister interface {
ListRunningByAsset(ctx context.Context, assetID shared.ID) ([]ports.ProcessSnapshot, error)
}
ProcessLister returns an asset's currently-running processes. ports.EndpointProcessStore satisfies it.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service produces + learns the Behavior factor from process snapshots and runtime detection rates.
func NewService ¶
func NewService(engine BaselineEngine, processes ProcessLister, detections DetectionRates, now func() time.Time, window time.Duration) (*Service, error)
NewService constructs the producer. The engine and process lister are required. detections is optional (nil = process features only); now defaults to time.Now and window to a day when zero.
func (*Service) BehaviorFor ¶
BehaviorFor scores the asset's current running-process profile against its baseline, read-only. It is the assembler's Behavior producer: abstains until the baseline is active, and never learns (scoring on the incident path must not poison the baseline).
func (*Service) Learn ¶
Learn folds the asset's current running-process profile into its behavior baseline. It is called at process-report time — NOT during incident reassessment — so the baseline learns from ordinary activity; baselineuc's anti-poisoning still refuses to fold an anomalous window. A learn failure is the caller's to treat as best-effort (the process report itself already succeeded).
func (*Service) Rebaseline ¶
Rebaseline drives a drifted or poisoned behavior baseline for one host asset through a clean re-baseline (reset_pending -> learning), so a baseline that latched on drift re-learns from fresh windows instead of abstaining forever. Audited by the underlying engine. It needs no process observation — it acts on the stored baseline for the asset's key.