Documentation
¶
Index ¶
- type AIConfig
- type ASNInfo
- type ActionRecommendation
- type AdaptiveThreshold
- type AdaptiveThresholdConfig
- type AttentionMechanism
- type Autoencoder
- type AutoencoderConfig
- type BehaviorAnalysisResult
- type BehaviorAnalyzer
- type BehaviorData
- type BehaviorEdge
- type BehaviorNode
- type BehaviorPattern
- type BehavioralSignature
- type ComprehensiveThreatAnalysis
- type Countermeasure
- type CyberSecurityKnowledgeGraph
- type DecisionNode
- type DeviceFingerprint
- type EmbeddingLayer
- type EngineStats
- type EnrichedThreatIntel
- type EnsembleModel
- type EnsembleResult
- type ExplanationData
- type ExplanationNode
- type FeatureImportance
- type FederatedLearningClient
- type FrequencyAnalysis
- type FrequencyFeatures
- type GeoInfo
- type GeopoliticalInfo
- type GraphAnalysisResult
- type GraphNeuralNetwork
- type IOC
- type InputVector
- type KeyboardEvent
- type KnowledgeGraphConfig
- type KnowledgeMatch
- type MatchedIndicator
- type MemoryActivation
- type MemoryAugmentedNetwork
- type MemoryNetworkConfig
- type MemorySlot
- type Model
- type ModelAggregator
- type ModelConfig
- type MouseEvent
- type NetworkData
- type OnlineLearningConfig
- type OnlineLearningSystem
- type Prediction
- type PrivacyEngine
- type QuantumAnomalyDetector
- type QuantumDetectionConfig
- type QuantumSignature
- type ReasoningStep
- type RequestData
- type SecurityEntity
- type SemanticAnalysisConfig
- type SemanticAnalyzer
- type SpatialFeatures
- type SpatialPattern
- type TTP
- type TemporalAnomaly
- type TemporalFeatures
- type TemporalPattern
- type ThreatActor
- type ThreatCorrelation
- type ThreatDetectionEngine
- type ThreatFeed
- type ThreatFeedConfig
- type ThreatIndicator
- type ThreatIntelligence
- type ThreatIntelligenceData
- type ThreatIntelligenceResult
- type ThresholdHistory
- type Tokenizer
- type TrainingExample
- type TransformerConfig
- type TransformerModel
- type ZeroDayAnalysis
- type ZeroDayConfig
- type ZeroDayDetector
- type ZeroDayStats
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AIConfig ¶
type AIConfig struct {
Models struct {
ThreatDetection *ModelConfig `yaml:"threat_detection"`
BehavioralAnalysis *ModelConfig `yaml:"behavioral_analysis"`
ZeroDayDetection *ModelConfig `yaml:"zero_day_detection"`
} `yaml:"models"`
ThreatIntel struct {
Enabled bool `yaml:"enabled"`
Feeds []*ThreatFeedConfig `yaml:"feeds"`
} `yaml:"threat_intel"`
FederatedLearning struct {
Enabled bool `yaml:"enabled"`
ServerURL string `yaml:"server_url"`
NodeID string `yaml:"node_id"`
} `yaml:"federated_learning"`
}
AIConfig represents AI engine configuration
type ASNInfo ¶
type ASNInfo struct {
Number int `json:"number"`
Organization string `json:"organization"`
Description string `json:"description"`
Country string `json:"country"`
}
ASNInfo contains Autonomous System Number information
type ActionRecommendation ¶
type ActionRecommendation struct {
Action string `json:"action"`
Confidence float64 `json:"confidence"`
Reasoning string `json:"reasoning"`
Parameters map[string]string `json:"parameters"`
Priority int `json:"priority"`
}
ActionRecommendation suggests actions based on analysis
type AdaptiveThreshold ¶
type AdaptiveThreshold struct {
// contains filtered or unexported fields
}
AdaptiveThreshold dynamically adjusts detection thresholds
func NewAdaptiveThreshold ¶
func NewAdaptiveThreshold(config *AdaptiveThresholdConfig, logger *logrus.Logger) (*AdaptiveThreshold, error)
func (*AdaptiveThreshold) GetCurrentThreshold ¶
func (a *AdaptiveThreshold) GetCurrentThreshold(ctx context.Context, input *InputVector) float64
func (*AdaptiveThreshold) UpdateThreshold ¶
func (a *AdaptiveThreshold) UpdateThreshold(score float64, isZeroDay bool) error
type AdaptiveThresholdConfig ¶
type AttentionMechanism ¶
type Autoencoder ¶
type Autoencoder struct {
// contains filtered or unexported fields
}
Autoencoder for unsupervised anomaly detection
func NewAutoencoder ¶
func NewAutoencoder(config *AutoencoderConfig) (*Autoencoder, error)
Missing constructor functions
func (*Autoencoder) DetectAnomaly ¶
func (a *Autoencoder) DetectAnomaly(input *InputVector) (float64, error)
Add missing methods for Autoencoder
type AutoencoderConfig ¶
type BehaviorAnalysisResult ¶
type BehaviorAnalysisResult struct {
AnomalyScore float64 `json:"anomaly_score"`
BehaviorPatterns []BehaviorPattern `json:"behavior_patterns"`
SessionRisk float64 `json:"session_risk"`
DeviceRisk float64 `json:"device_risk"`
TemporalAnomalies []TemporalAnomaly `json:"temporal_anomalies"`
GraphAnalysis *GraphAnalysisResult `json:"graph_analysis"`
}
BehaviorAnalysisResult contains behavioral analysis results
type BehaviorAnalyzer ¶
type BehaviorAnalyzer struct {
// contains filtered or unexported fields
}
BehaviorAnalyzer performs advanced behavioral analysis
func NewBehaviorAnalyzer ¶
func NewBehaviorAnalyzer(config *ModelConfig, logger *logrus.Logger) (*BehaviorAnalyzer, error)
func (*BehaviorAnalyzer) AnalyzeBehavior ¶
func (ba *BehaviorAnalyzer) AnalyzeBehavior(ctx context.Context, data *BehaviorData) (*BehaviorAnalysisResult, error)
Missing methods for BehaviorAnalyzer
type BehaviorData ¶
type BehaviorData struct {
SessionID string `json:"session_id"`
RequestSequence []string `json:"request_sequence"`
TimingPatterns []time.Duration `json:"timing_patterns"`
InteractionDepth int `json:"interaction_depth"`
MouseMovements []MouseEvent `json:"mouse_movements"`
KeyboardTimings []KeyboardEvent `json:"keyboard_timings"`
DeviceFingerprint *DeviceFingerprint `json:"device_fingerprint"`
}
BehaviorData contains behavioral analysis information
type BehaviorEdge ¶
type BehaviorEdge struct {
Source string `json:"source"`
Target string `json:"target"`
Type string `json:"type"` // accesses, follows, contains
Weight float64 `json:"weight"`
Features map[string]float64 `json:"features"`
Timestamp time.Time `json:"timestamp"`
}
BehaviorEdge represents an edge in the behavior graph
type BehaviorNode ¶
type BehaviorNode struct {
ID string `json:"id"`
Type string `json:"type"` // user, session, request, resource
Features map[string]float64 `json:"features"`
Timestamp time.Time `json:"timestamp"`
Metadata map[string]interface{} `json:"metadata"`
}
BehaviorNode represents a node in the behavior graph
type BehaviorPattern ¶
type BehaviorPattern struct {
Type string `json:"type"`
Confidence float64 `json:"confidence"`
Description string `json:"description"`
Indicators []string `json:"indicators"`
}
BehaviorPattern represents identified behavior patterns
type BehavioralSignature ¶
type BehavioralSignature struct {
Signature string `json:"signature"`
Entropy float64 `json:"entropy"`
Complexity float64 `json:"complexity"`
Novelty float64 `json:"novelty"`
TemporalPatterns []TemporalPattern `json:"temporal_patterns"`
SpatialPatterns []SpatialPattern `json:"spatial_patterns"`
FrequencyDomain *FrequencyAnalysis `json:"frequency_domain"`
}
BehavioralSignature represents unique behavioral patterns
type ComprehensiveThreatAnalysis ¶
type ComprehensiveThreatAnalysis struct {
RequestID string `json:"request_id"`
Timestamp time.Time `json:"timestamp"`
InputVector *InputVector `json:"input_vector"`
Predictions map[string]*Prediction `json:"predictions"`
BehaviorAnalysis *BehaviorAnalysisResult `json:"behavior_analysis"`
ThreatIntelligence *ThreatIntelligenceResult `json:"threat_intelligence"`
FinalThreatScore float64 `json:"final_threat_score"`
ProcessingTime time.Duration `json:"processing_time"`
Recommendations []ActionRecommendation `json:"recommendations"`
}
ComprehensiveThreatAnalysis contains the complete analysis results
type Countermeasure ¶
type Countermeasure struct {
Type string `json:"type"`
Action string `json:"action"`
Parameters map[string]string `json:"parameters"`
Effectiveness float64 `json:"effectiveness"`
Priority int `json:"priority"`
AutoApply bool `json:"auto_apply"`
}
Countermeasure suggests specific countermeasures
type CyberSecurityKnowledgeGraph ¶
type CyberSecurityKnowledgeGraph struct {
// contains filtered or unexported fields
}
CyberSecurityKnowledgeGraph maintains cybersecurity knowledge
func NewCyberSecurityKnowledgeGraph ¶
func NewCyberSecurityKnowledgeGraph(config *KnowledgeGraphConfig, logger *logrus.Logger) (*CyberSecurityKnowledgeGraph, error)
func (*CyberSecurityKnowledgeGraph) ReasonAboutThreat ¶
func (k *CyberSecurityKnowledgeGraph) ReasonAboutThreat(ctx context.Context, input *InputVector, analysis *ZeroDayAnalysis) (*KnowledgeMatch, error)
type DecisionNode ¶
type DecisionNode struct {
Feature string `json:"feature"`
Threshold float64 `json:"threshold"`
Direction string `json:"direction"` // left, right
Samples int `json:"samples"`
}
DecisionNode represents a node in the decision tree explanation
type DeviceFingerprint ¶
type DeviceFingerprint struct {
UserAgent string `json:"user_agent"`
ScreenResolution string `json:"screen_resolution"`
Timezone string `json:"timezone"`
Language string `json:"language"`
Plugins []string `json:"plugins"`
Fonts []string `json:"fonts"`
Canvas string `json:"canvas"`
WebGL string `json:"webgl"`
AudioContext string `json:"audio_context"`
ClientRects map[string]string `json:"client_rects"`
}
DeviceFingerprint contains device identification data
type EmbeddingLayer ¶
type EngineStats ¶
type EngineStats struct {
TotalPredictions uint64 `json:"total_predictions"`
AveragePredictionTime time.Duration `json:"average_prediction_time"`
ThreatDetectionRate float64 `json:"threat_detection_rate"`
FalsePositiveRate float64 `json:"false_positive_rate"`
ModelAccuracy float64 `json:"model_accuracy"`
LastUpdate time.Time `json:"last_update"`
}
EngineStats contains performance statistics
type EnrichedThreatIntel ¶
type EnrichedThreatIntel struct {
ThreatActors []ThreatActor `json:"threat_actors"`
TTPs []TTP `json:"ttps"` // Tactics, Techniques, Procedures
IOCs []IOC `json:"iocs"` // Indicators of Compromise
RelatedCampaigns []types.Campaign `json:"related_campaigns"`
GeopoliticalContext *GeopoliticalInfo `json:"geopolitical_context"`
}
EnrichedThreatIntel provides enriched threat intelligence
type EnsembleModel ¶
type EnsembleModel struct {
// contains filtered or unexported fields
}
EnsembleModel combines multiple models for robust detection
type ExplanationData ¶
type ExplanationData struct {
TopFeatures []FeatureImportance `json:"top_features"`
DecisionPath []DecisionNode `json:"decision_path"`
Counterfactuals []string `json:"counterfactuals"`
SimilarCases []string `json:"similar_cases"`
}
ExplanationData provides explainable AI results
type ExplanationNode ¶
type ExplanationNode struct {
Component string `json:"component"`
Decision string `json:"decision"`
Reasoning string `json:"reasoning"`
Evidence []string `json:"evidence"`
Confidence float64 `json:"confidence"`
Alternatives []string `json:"alternatives"`
}
ExplanationNode provides explainable detection results
type FeatureImportance ¶
type FeatureImportance struct {
Feature string `json:"feature"`
Importance float64 `json:"importance"`
Value string `json:"value"`
}
FeatureImportance represents the importance of a feature in the decision
type FederatedLearningClient ¶
type FederatedLearningClient struct {
// contains filtered or unexported fields
}
FederatedLearningClient handles federated learning with global network
func NewFederatedLearningClient ¶
func NewFederatedLearningClient(config interface{}, logger *logrus.Logger) (*FederatedLearningClient, error)
func (*FederatedLearningClient) SyncModels ¶
func (flc *FederatedLearningClient) SyncModels(ctx context.Context) error
type FrequencyAnalysis ¶
type FrequencyFeatures ¶
type FrequencyFeatures struct{}
type GeoInfo ¶
type GeoInfo struct {
Country string `json:"country"`
Region string `json:"region"`
City string `json:"city"`
Latitude float64 `json:"latitude"`
Longitude float64 `json:"longitude"`
ISP string `json:"isp"`
Organization string `json:"organization"`
Timezone string `json:"timezone"`
}
GeoInfo contains geographical information
type GeopoliticalInfo ¶
type GeopoliticalInfo struct {
OriginCountry string `json:"origin_country"`
TargetCountries []string `json:"target_countries"`
GeopoliticalTensions []string `json:"geopolitical_tensions"`
EconomicFactors []string `json:"economic_factors"`
CyberWarfare bool `json:"cyber_warfare"`
}
GeopoliticalInfo provides geopolitical context
type GraphAnalysisResult ¶
type GraphAnalysisResult struct {
NodeEmbedding []float64 `json:"node_embedding"`
CommunityDetection []string `json:"community_detection"`
AnomalousEdges []*BehaviorEdge `json:"anomalous_edges"`
CentralityScores map[string]float64 `json:"centrality_scores"`
}
GraphAnalysisResult contains graph neural network analysis
type GraphNeuralNetwork ¶
type GraphNeuralNetwork struct {
// contains filtered or unexported fields
}
GraphNeuralNetwork for analyzing user behavior graphs
type IOC ¶
type IOC struct {
Type string `json:"type"`
Value string `json:"value"`
Confidence float64 `json:"confidence"`
FirstSeen time.Time `json:"first_seen"`
LastSeen time.Time `json:"last_seen"`
Source string `json:"source"`
Tags []string `json:"tags"`
}
IOC represents Indicators of Compromise
type InputVector ¶
type InputVector struct {
Features map[string]interface{} `json:"features"`
Metadata map[string]string `json:"metadata"`
// Request context
RequestData *RequestData `json:"request_data"`
// Network context
NetworkData *NetworkData `json:"network_data"`
// Behavioral context
BehaviorData *BehaviorData `json:"behavior_data"`
}
InputVector represents input data for AI models
type KeyboardEvent ¶
type KeyboardEvent struct {
Key string `json:"key"`
Timestamp time.Time `json:"timestamp"`
Duration time.Duration `json:"duration"`
Type string `json:"type"` // keydown, keyup
}
KeyboardEvent represents keyboard interaction data
type KnowledgeGraphConfig ¶
type KnowledgeMatch ¶
type KnowledgeMatch struct {
MatchedEntities []*SecurityEntity `json:"matched_entities"`
ReasoningPath []*ReasoningStep `json:"reasoning_path"`
InferredThreats []string `json:"inferred_threats"`
ConfidenceScore float64 `json:"confidence_score"`
}
KnowledgeMatch represents matches in knowledge graph
type MatchedIndicator ¶
type MatchedIndicator struct {
Indicator *ThreatIndicator `json:"indicator"`
MatchType string `json:"match_type"`
Confidence float64 `json:"confidence"`
Context string `json:"context"`
}
MatchedIndicator represents a matched threat indicator
type MemoryActivation ¶
type MemoryActivation struct {
ActivatedMemories []MemorySlot `json:"activated_memories"`
Similarities []float64 `json:"similarities"`
NoveltyScore float64 `json:"novelty_score"`
WrittenMemory *MemorySlot `json:"written_memory"`
}
MemoryActivation represents activation in memory network
type MemoryAugmentedNetwork ¶
type MemoryAugmentedNetwork struct {
// contains filtered or unexported fields
}
MemoryAugmentedNetwork for learning from past attacks
func NewMemoryAugmentedNetwork ¶
func NewMemoryAugmentedNetwork(config *MemoryNetworkConfig, logger *logrus.Logger) (*MemoryAugmentedNetwork, error)
Additional missing constructor functions
func (*MemoryAugmentedNetwork) ProcessInput ¶
func (m *MemoryAugmentedNetwork) ProcessInput(ctx context.Context, input *InputVector) (*MemoryActivation, error)
type MemoryNetworkConfig ¶
type MemorySlot ¶
type Model ¶
type Model interface {
Predict(input *InputVector) (*Prediction, error)
Update(trainingData []*TrainingExample) error
GetAccuracy() float64
GetVersion() string
}
Model represents an AI/ML model for threat detection
type ModelAggregator ¶
type ModelConfig ¶
type ModelConfig struct {
ModelPath string `yaml:"model_path"`
ConfidenceThreshold float64 `yaml:"confidence_threshold"`
BatchSize int `yaml:"batch_size"`
GPUAcceleration bool `yaml:"gpu_acceleration"`
}
ModelConfig represents configuration for an AI model
type MouseEvent ¶
type MouseEvent struct {
X int `json:"x"`
Y int `json:"y"`
Timestamp time.Time `json:"timestamp"`
Button int `json:"button"`
Type string `json:"type"` // move, click, scroll
Velocity float64 `json:"velocity"`
Pressure float64 `json:"pressure"`
}
MouseEvent represents mouse movement data
type NetworkData ¶
type NetworkData struct {
SourceIP string `json:"source_ip"`
DestinationIP string `json:"destination_ip"`
SourcePort int `json:"source_port"`
DestinationPort int `json:"destination_port"`
Protocol string `json:"protocol"`
GeoLocation *GeoInfo `json:"geo_location"`
ASN *ASNInfo `json:"asn"`
TLSFingerprint string `json:"tls_fingerprint"`
}
NetworkData contains network-level information
type OnlineLearningConfig ¶
type OnlineLearningSystem ¶
type OnlineLearningSystem struct {
// contains filtered or unexported fields
}
OnlineLearningSystem for continuous adaptation
func NewOnlineLearningSystem ¶
func NewOnlineLearningSystem(config *OnlineLearningConfig, logger *logrus.Logger) (*OnlineLearningSystem, error)
func (*OnlineLearningSystem) LearnFromDetection ¶
func (o *OnlineLearningSystem) LearnFromDetection(analysis *ZeroDayAnalysis) error
type Prediction ¶
type Prediction struct {
ThreatScore float64 `json:"threat_score"`
Confidence float64 `json:"confidence"`
ThreatTypes []string `json:"threat_types"`
Recommendations []string `json:"recommendations"`
Explanation *ExplanationData `json:"explanation"`
ModelVersion string `json:"model_version"`
ProcessingTime time.Duration `json:"processing_time"`
Features map[string]float64 `json:"features"`
}
Prediction represents the output of AI model prediction
type PrivacyEngine ¶
type PrivacyEngine struct {
// contains filtered or unexported fields
}
PrivacyEngine ensures privacy-preserving machine learning
type QuantumAnomalyDetector ¶
type QuantumAnomalyDetector struct {
// contains filtered or unexported fields
}
QuantumAnomalyDetector - Cutting-edge quantum-inspired detection
func NewQuantumAnomalyDetector ¶
func NewQuantumAnomalyDetector(config interface{}, logger *logrus.Logger) (*QuantumAnomalyDetector, error)
func (*QuantumAnomalyDetector) AnalyzeQuantumSignature ¶
func (q *QuantumAnomalyDetector) AnalyzeQuantumSignature(ctx context.Context, input *InputVector) (*QuantumSignature, error)
type QuantumDetectionConfig ¶
type QuantumSignature ¶
type QuantumSignature struct {
QuantumState string `json:"quantum_state"`
Entanglement float64 `json:"entanglement"`
Coherence float64 `json:"coherence"`
MeasurementBasis string `json:"measurement_basis"`
QuantumFeatures map[string]complex128 `json:"quantum_features"`
}
QuantumSignature represents quantum-inspired analysis results
type ReasoningStep ¶
type RequestData ¶
type RequestData struct {
Method string `json:"method"`
URL string `json:"url"`
Headers map[string]string `json:"headers"`
Body string `json:"body"`
UserAgent string `json:"user_agent"`
ContentType string `json:"content_type"`
Size int64 `json:"size"`
Timestamp time.Time `json:"timestamp"`
}
RequestData contains HTTP request information
type SecurityEntity ¶
type SemanticAnalysisConfig ¶
type SemanticAnalyzer ¶
type SemanticAnalyzer struct {
// contains filtered or unexported fields
}
SemanticAnalyzer performs deep semantic analysis of requests
func NewSemanticAnalyzer ¶
func NewSemanticAnalyzer(config *SemanticAnalysisConfig, logger *logrus.Logger) (*SemanticAnalyzer, error)
func (*SemanticAnalyzer) AnalyzeSemantics ¶
func (s *SemanticAnalyzer) AnalyzeSemantics(ctx context.Context, input *InputVector) (map[string]float64, error)
Missing method implementations for ZeroDayDetector
type SpatialFeatures ¶
type SpatialFeatures struct{}
type SpatialPattern ¶
type TTP ¶
type TTP struct {
TacticID string `json:"tactic_id"`
TacticName string `json:"tactic_name"`
TechniqueID string `json:"technique_id"`
TechniqueName string `json:"technique_name"`
SubTechnique string `json:"sub_technique"`
MITREAttackID string `json:"mitre_attack_id"`
Procedures []string `json:"procedures"`
}
TTP represents Tactics, Techniques, and Procedures
type TemporalAnomaly ¶
type TemporalAnomaly struct {
Type string `json:"type"`
Timestamp time.Time `json:"timestamp"`
Severity string `json:"severity"`
Description string `json:"description"`
}
TemporalAnomaly represents time-based anomalies
type TemporalFeatures ¶
type TemporalFeatures struct{}
type TemporalPattern ¶
type ThreatActor ¶
type ThreatActor struct {
Name string `json:"name"`
Aliases []string `json:"aliases"`
Attribution string `json:"attribution"`
Motivation []string `json:"motivation"`
Capabilities []string `json:"capabilities"`
FirstSeen time.Time `json:"first_seen"`
LastActivity time.Time `json:"last_activity"`
}
ThreatActor represents threat actor information
type ThreatCorrelation ¶
type ThreatCorrelation struct {
Type string `json:"type"`
Score float64 `json:"score"`
Description string `json:"description"`
Timestamp time.Time `json:"timestamp"`
}
ThreatCorrelation represents correlated threat data
type ThreatDetectionEngine ¶
type ThreatDetectionEngine struct {
// contains filtered or unexported fields
}
ThreatDetectionEngine represents the core AI engine
func NewThreatDetectionEngine ¶
func NewThreatDetectionEngine(config *AIConfig, logger *logrus.Logger) (*ThreatDetectionEngine, error)
NewThreatDetectionEngine creates a new AI threat detection engine
func (*ThreatDetectionEngine) AnalyzeThreat ¶
func (e *ThreatDetectionEngine) AnalyzeThreat(ctx context.Context, input *InputVector) (*ComprehensiveThreatAnalysis, error)
AnalyzeThreat performs comprehensive threat analysis using multiple AI models
func (*ThreatDetectionEngine) GetStats ¶
func (e *ThreatDetectionEngine) GetStats() *EngineStats
GetStats returns current engine statistics
func (*ThreatDetectionEngine) UpdateModels ¶
func (e *ThreatDetectionEngine) UpdateModels(ctx context.Context, trainingData []*TrainingExample) error
UpdateModels updates AI models with new training data
type ThreatFeed ¶
type ThreatFeed struct {
Name string `json:"name"`
URL string `json:"url"`
Format string `json:"format"`
Priority int `json:"priority"`
LastUpdate time.Time `json:"last_update"`
UpdateInterval time.Duration `json:"update_interval"`
Indicators []*ThreatIndicator `json:"indicators"`
Metadata map[string]string `json:"metadata"`
}
ThreatFeed represents a threat intelligence feed
type ThreatFeedConfig ¶
type ThreatFeedConfig struct {
Name string `yaml:"name"`
URL string `yaml:"url"`
Format string `yaml:"format"`
UpdateInterval time.Duration `yaml:"update_interval"`
Priority int `yaml:"priority"`
}
ThreatFeedConfig represents threat feed configuration
type ThreatIndicator ¶
type ThreatIndicator struct {
Type string `json:"type"` // ip, domain, hash, url, email
Value string `json:"value"`
Confidence float64 `json:"confidence"`
Severity string `json:"severity"`
FirstSeen time.Time `json:"first_seen"`
LastSeen time.Time `json:"last_seen"`
Source string `json:"source"`
Tags []string `json:"tags"`
Description string `json:"description"`
TTL time.Duration `json:"ttl"`
}
ThreatIndicator represents a threat indicator
type ThreatIntelligence ¶
type ThreatIntelligence struct {
// contains filtered or unexported fields
}
ThreatIntelligence manages global threat intelligence
func NewThreatIntelligence ¶
func NewThreatIntelligence(config interface{}, logger *logrus.Logger) (*ThreatIntelligence, error)
Missing constructor functions
func (*ThreatIntelligence) CheckIndicators ¶
func (ti *ThreatIntelligence) CheckIndicators(ctx context.Context, input *InputVector) (*ThreatIntelligenceResult, error)
Missing methods for ThreatIntelligence
type ThreatIntelligenceData ¶
type ThreatIntelligenceData struct{}
type ThreatIntelligenceResult ¶
type ThreatIntelligenceResult struct {
MatchedIndicators []MatchedIndicator `json:"matched_indicators"`
ReputationScore float64 `json:"reputation_score"`
RiskLevel string `json:"risk_level"`
Sources []string `json:"sources"`
Correlations []ThreatCorrelation `json:"correlations"`
}
ThreatIntelligenceResult contains threat intelligence findings
type ThresholdHistory ¶
type ThresholdHistory struct {
Values []float64 `json:"values"`
Timestamps []time.Time `json:"timestamps"`
AverageValue float64 `json:"average_value"`
Variance float64 `json:"variance"`
}
Missing AI analysis types
type Tokenizer ¶
type Tokenizer struct {
Vocab map[string]int `json:"vocab"`
MaxLen int `json:"max_len"`
PadToken string `json:"pad_token"`
}
Missing AI component types
type TrainingExample ¶
type TrainingExample struct {
Input *InputVector `json:"input"`
Output *Prediction `json:"output"`
Label string `json:"label"` // threat, benign
}
TrainingExample represents a training example for model updates
type TransformerConfig ¶
type TransformerConfig struct {
VocabSize int `json:"vocab_size"`
HiddenSize int `json:"hidden_size"`
NumLayers int `json:"num_layers"`
NumHeads int `json:"num_heads"`
MaxSeqLength int `json:"max_seq_length"`
DropoutRate float64 `json:"dropout_rate"`
LearningRate float64 `json:"learning_rate"`
BatchSize int `json:"batch_size"`
}
TransformerConfig contains transformer model configuration
type TransformerModel ¶
type TransformerModel struct {
// contains filtered or unexported fields
}
TransformerModel implements advanced transformer-based threat detection
func NewTransformerModel ¶
func NewTransformerModel(config *ModelConfig) (*TransformerModel, error)
Constructor functions for missing types
func (*TransformerModel) GetAccuracy ¶
func (tm *TransformerModel) GetAccuracy() float64
func (*TransformerModel) GetVersion ¶
func (tm *TransformerModel) GetVersion() string
func (*TransformerModel) Predict ¶
func (tm *TransformerModel) Predict(input *InputVector) (*Prediction, error)
Implement Model interface for TransformerModel
func (*TransformerModel) Update ¶
func (tm *TransformerModel) Update(trainingData []*TrainingExample) error
type ZeroDayAnalysis ¶
type ZeroDayAnalysis struct {
IsZeroDay bool `json:"is_zero_day"`
Confidence float64 `json:"confidence"`
ExploitType string `json:"exploit_type"`
AttackVector string `json:"attack_vector"`
Severity string `json:"severity"`
AnomalyScore float64 `json:"anomaly_score"`
SemanticFeatures map[string]float64 `json:"semantic_features"`
BehavioralSignature *BehavioralSignature `json:"behavioral_signature"`
MemoryActivation *MemoryActivation `json:"memory_activation"`
QuantumSignature *QuantumSignature `json:"quantum_signature"`
KnowledgeMatch *KnowledgeMatch `json:"knowledge_match"`
ExplanationChain []*ExplanationNode `json:"explanation_chain"`
Countermeasures []Countermeasure `json:"countermeasures"`
ThreatIntelligence *EnrichedThreatIntel `json:"threat_intelligence"`
}
ZeroDayAnalysis represents the result of zero-day analysis
type ZeroDayConfig ¶
type ZeroDayConfig struct {
Autoencoders []*AutoencoderConfig `yaml:"autoencoders"`
SemanticAnalysis *SemanticAnalysisConfig `yaml:"semantic_analysis"`
MemoryNetwork *MemoryNetworkConfig `yaml:"memory_network"`
QuantumDetection *QuantumDetectionConfig `yaml:"quantum_detection"`
KnowledgeGraph *KnowledgeGraphConfig `yaml:"knowledge_graph"`
OnlineLearning *OnlineLearningConfig `yaml:"online_learning"`
AdaptiveThreshold *AdaptiveThresholdConfig `yaml:"adaptive_threshold"`
}
ZeroDayConfig represents configuration for zero-day detection
type ZeroDayDetector ¶
type ZeroDayDetector struct {
// contains filtered or unexported fields
}
ZeroDayDetector - Revolutionary zero-day exploit detection system
This is the most advanced zero-day detection system that surpasses any existing solution including CrowdSec and ModSecurity
func NewZeroDayDetector ¶
func NewZeroDayDetector(config *ZeroDayConfig, logger *logrus.Logger) (*ZeroDayDetector, error)
NewZeroDayDetector creates a new zero-day detection system
func (*ZeroDayDetector) DetectZeroDay ¶
func (z *ZeroDayDetector) DetectZeroDay(ctx context.Context, input *InputVector) (*ZeroDayAnalysis, error)
DetectZeroDay performs comprehensive zero-day exploit detection
type ZeroDayStats ¶
type ZeroDayStats struct {
TotalAnalyzed uint64 `json:"total_analyzed"`
ZeroDaysDetected uint64 `json:"zero_days_detected"`
FalsePositives uint64 `json:"false_positives"`
TruePositives uint64 `json:"true_positives"`
AverageConfidence float64 `json:"average_confidence"`
DetectionLatency time.Duration `json:"detection_latency"`
LastDetection time.Time `json:"last_detection"`
ModelAccuracy float64 `json:"model_accuracy"`
}
ZeroDayStats contains zero-day detection statistics