Skip to content

Commit cbb1a32

Browse files
author
DeepShield Dev
committed
feat(baseline): P3 statistical baseline analysis engine
- Add zerotrace_baseline.go with three detection modes: 1. EWMA anomaly: per-host metric deviation (unique_domains, dst_ips, bytes_up, dns_queries, http_requests) with configurable alpha/threshold 2. First-seen: new domains not observed in 7-day lookback window, severity escalated by DGA score 3. Beacon detection: periodic DNS connection intervals with low jitter (coefficient of variation < 0.15) indicating C2 communication - Auto-creates siteguard.baseline_alerts and siteguard.ewma_baselines tables - EWMA baselines use ReplacingMergeTree for in-place updates - Endpoints: POST /probe/baseline/run, GET /probe/baseline/status - Also detects: high DGA score hosts (>=0.7) and suspicious path hit hosts - Register baseline routes in zerotrace.go - Verified: 143 alerts generated on first run, 26 EWMA baselines initialized
1 parent c35cef2 commit cbb1a32

2 files changed

Lines changed: 452 additions & 0 deletions

File tree

‎controller/http/router/agent/zerotrace.go‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,10 @@ func (a *ZeroTrace) RegisterTo(e *gin.Engine) {
6969
// Pull query proxy — server forwards queries to agent's local data
7070
g.POST("/probe/query", a.handleAgentQuery)
7171

72+
// Baseline analysis engine — statistical anomaly detection
73+
g.POST("/probe/baseline/run", a.handleBaselineRun)
74+
g.GET("/probe/baseline/status", a.handleBaselineStatus)
75+
7276
// Usage metering — internal endpoint for billing (no API key required)
7377
e.GET("/api/v1/usage/metering", a.handleUsageMetering)
7478
}

0 commit comments

Comments
 (0)