加密流量元数据与行为分析

EncGuard Pro 加密通信恶意行为检测平台

检测模式:规则检测 + 分类模型 + 异常检测 + 攻击链融合 模型状态:已启用

Alert Detail

告警详情

runtime-308c6546-5415-40a3-9581-e25a9b3aada1

模型预测与异常检测已拆分为 model_prediction 与 anomaly_result 两个解释区。

风险评分 95 critical
Basic Info

基础信息

event_id
runtime-308c6546-5415-40a3-9581-e25a9b3aada1
flow_id
safe-lab-20260704092453-e82171-040-data_exfiltration_like
src_ip
10.20.7.81
dst_ip
203.0.113.211
protocol
https
timestamp
2026-07-04T09:24:55.493068+00:00
风险等级
critical
检测类型
data_exfiltration
detectors
rule_engine, anomaly_detector, attack_chain
source
mixed_scenario_lab
chain_related
True
Risk Score

风险评分

final_risk_score
95
severity
critical
security_alert
True
Risk Formation

最终风险形成

rule_score
95
supervised_risk_score
0
calibrated_risk_score
16
anomaly_risk_score
95
final_risk_score
95
fusion_policy
max(rule_score, calibrated_risk_score, anomaly_risk_score)
gate_formula
risk=(1-g)*supervised_risk+g*anomaly_risk
Weak Scenario Support

弱覆盖场景补强证据

scenarios
data_exfiltration
support_type
rule_anomaly_gate_attack_chain_supported
model_claim
not_strong_supervised_label
explanation
This scenario is supported by rules, anomaly detection, uncertainty gate, and chain evidence rather than claimed as a strongly supervised classifier label.
Model Prediction

模型预测 model_prediction

predicted_label
benign
malicious_probability
0.0005
model_score
0
calibrated_risk_score
16
uncertainty_gate
0.171272
probability_entropy
0.005473
top2_margin
0.998937
js_divergence
0.000659
unknown_decision
False
model_supported_label
True

该场景主要由规则、攻击链或异常检测补强,不应表述为当前模型可靠覆盖。

Anomaly Detection

异常检测 anomaly_result

anomaly_score
98.223354
anomaly_risk_score
95
is_anomaly
True
Rule Hits

规则 evidence

data_exfiltration scenario_rule_engine · risk_score=95
Evidence

推荐处置 recommendation

  • uploaded_file=mixed_scenario_features.csv
  • input_label=data_exfiltration
  • uploaded feature row evaluated by EncGuard scenario rule engine
  • anomaly_score=98.223354
  • anomaly_risk_score=90.0
  • uncertainty_gate=0.171272
  • safe_lab_batch=safe-lab-20260704092453-e82171
  • scenario=data_exfiltration_like
  • ground_truth_label=data_exfiltration
  • safe synthetic metadata only; no payload and no real attack execution

recommendation:Review uploaded feature context and validate whether this communication is authorized.

Attack Chain

攻击链关联 attack_chain

encrypted_tunnel_to_data_exfiltration chain_id=inferred-3 · risk_score=95
Safety Boundary

安全边界说明

Raw Feature

原始特征详情

flow_id
safe-lab-20260704092453-e82171-040-data_exfiltration_like
src_ip
10.20.7.81
dst_ip
203.0.113.211
src_port
64725
dst_port
9443
protocol
https
start_time
2026-07-04T09:59:38Z
duration
662.0957
total_packets
269977
total_bytes
487300257
fwd_packets
264052
bwd_packets
5925
fwd_bytes
480863869
bwd_bytes
6436388
upload_download_ratio
74.710205
packets_per_second
407.761323
bytes_per_second
735996.760564
packet_size_mean
1804.969523
packet_size_std
1912.634682
iat_mean
0.011642
iat_std
0.002027
same_src_conn_count_1min
2
same_src_conn_count_5min
2
short_connection_count_5min
1
long_session_flag
False
large_upload_flag
True
unknown_destination_flag
True
non_working_hour_flag
True
packet_direction_sequence_summary
client_to_server_dominant
packet_size_sequence_summary
large_forward_bulk_transfer_like
burst_count
110
interactive_gap_mean
0.011642
interactive_gap_std
0.002027
post_login_long_session_flag
False
command_like_burst_flag
False
failed_login_then_long_session_flag
False
scenario
data_exfiltration_like
label
data_exfiltration
Related Events

相关事件