加密流量元数据与行为分析

EncGuard Pro 加密通信恶意行为检测平台

检测模式:规则检测 + 分类模型 + 异常检测 + 攻击链融合 模型状态:已启用

Alert Detail

告警详情

sample-evt-013

模型预测与异常检测已拆分为 model_prediction 与 anomaly_result 两个解释区。

风险评分 84 high
Basic Info

基础信息

event_id
sample-evt-013
flow_id
sample-post-003
src_ip
10.10.2.52
dst_ip
10.10.1.11
protocol
scp
timestamp
2026-01-01T20:28:00Z
风险等级
high
检测类型
post_bruteforce_action
detectors
rule_engine, attack_chain
source
main_project
chain_related
True
Risk Score

风险评分

final_risk_score
84
severity
high
security_alert
True
Risk Formation

最终风险形成

rule_score
-
supervised_risk_score
-
calibrated_risk_score
-
anomaly_risk_score
-
final_risk_score
84
fusion_policy
-
gate_formula
-
Weak Scenario Support

弱覆盖场景补强证据

该事件不属于弱覆盖场景,或无需额外补强说明。

Model Prediction

模型预测 model_prediction

当前事件没有模型推理结果,可能来自规则检测或攻击链分析。

该场景主要由规则、攻击链或异常检测补强,不应表述为当前模型可靠覆盖。

Anomaly Detection

异常检测 anomaly_result

anomaly_score
-
anomaly_risk_score
-
is_anomaly
False
Rule Hits

规则 evidence

post_bruteforce_action rule_engine · risk_score=84
Evidence

推荐处置 recommendation

  • SCP transfer followed repeated SSH attempts from the same source segment
  • session duration and byte volume are above the host baseline

recommendation:Verify whether the SCP transfer was approved.

Attack Chain

攻击链关联 attack_chain

ssh_bruteforce_to_post_action chain_id=sample-chain-013 · risk_score=84
Safety Boundary

安全边界说明

Raw Feature

原始特征详情

当前 flow_id 未匹配到特征详情。