behaviorbaseline

package
v0.2.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 8 Imported by: 0

Documentation

Overview

Package behaviorbaseline turns the B5 per-host running-process projection plus the host's sealed runtime detections into the coverage-honest RiskContext.Behavior factor (#594 D). It maps a host's running processes to the process features of a baseline.Observation, and folds the per-class rate of the eBPF detections observed on that host in a recent window into the network / privilege / file features, so the statistical baseline scores anomalies over runtime telemetry rather than over process snapshots alone (#822). It LEARNS the asset's normal profile at report time (baselineuc.Observe, which scores-then-folds with anti-poisoning) and SCORES the current profile read-only at risk-assessment time (baselineuc.Score, no fold). Learning and scoring are separated so scoring never poisons the baseline, and the risk-assessment path (an incident is active) never learns.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type BaselineEngine

type BaselineEngine interface {
	Observe(ctx context.Context, actor string, key baseline.Key, obs baseline.Observation, window baseline.LearnWindow) (baselineuc.Assessment, error)
	Score(ctx context.Context, key baseline.Key, obs baseline.Observation) (baselineuc.Assessment, error)
	Rebaseline(ctx context.Context, actor string, key baseline.Key) error
}

BaselineEngine is the baselineuc surface this producer needs: Observe (learn+score) and Score (read-only).

type DetectionRates

type DetectionRates interface {
	ClassCountsByAsset(ctx context.Context, assetID shared.ID, since time.Time) (map[detection.Class]int, error)
}

DetectionRates returns the count of sealed detections observed on an asset since a cutoff, grouped by telemetry class, tenant-scoped by ctx. It is OPTIONAL: a nil DetectionRates leaves the network, privilege and file features unobserved (0), which is the pre-#822 behavior. The memory and Postgres detection-record stores satisfy it.

type Factor

type Factor struct {
	Behavior  int
	Scoreable bool
	Reasons   []string
}

Factor is the coverage-honest Behavior factor for one asset.

type ProcessLister

type ProcessLister interface {
	ListRunningByAsset(ctx context.Context, assetID shared.ID) ([]ports.ProcessSnapshot, error)
}

ProcessLister returns an asset's currently-running processes. ports.EndpointProcessStore satisfies it.

type Service

type Service struct {
	// contains filtered or unexported fields
}

Service produces + learns the Behavior factor from process snapshots and runtime detection rates.

func NewService

func NewService(engine BaselineEngine, processes ProcessLister, detections DetectionRates, now func() time.Time, window time.Duration) (*Service, error)

NewService constructs the producer. The engine and process lister are required. detections is optional (nil = process features only); now defaults to time.Now and window to a day when zero.

func (*Service) BehaviorFor

func (s *Service) BehaviorFor(ctx context.Context, assetID shared.ID) (Factor, error)

BehaviorFor scores the asset's current running-process profile against its baseline, read-only. It is the assembler's Behavior producer: abstains until the baseline is active, and never learns (scoring on the incident path must not poison the baseline).

func (*Service) Learn

func (s *Service) Learn(ctx context.Context, actor string, assetID shared.ID) error

Learn folds the asset's current running-process profile into its behavior baseline. It is called at process-report time — NOT during incident reassessment — so the baseline learns from ordinary activity; baselineuc's anti-poisoning still refuses to fold an anomalous window. A learn failure is the caller's to treat as best-effort (the process report itself already succeeded).

func (*Service) Rebaseline

func (s *Service) Rebaseline(ctx context.Context, actor string, assetID shared.ID) error

Rebaseline drives a drifted or poisoned behavior baseline for one host asset through a clean re-baseline (reset_pending -> learning), so a baseline that latched on drift re-learns from fresh windows instead of abstaining forever. Audited by the underlying engine. It needs no process observation — it acts on the stored baseline for the asset's key.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL