A signature-less Endpoint Detection and Response (EDR) prototype for Linux. It utilizes eBPF for zero-latency Ring-0 system call telemetry, a PyTorch LSTM Autoencoder for temporal sequence anomaly detection, and a SHA-256 Merkle chain to guarantee forensic log immutability.
This project was engineered to demonstrate a Zero-Trust approach to endpoint security, shifting detection from static malware signatures to dynamic execution behavior.
- The Sensor (eBPF)
The data ingestion layer (chrono_defender.py) bypasses user-space entirely. It injects dynamic Kprobes into the Linux kernel (Ring-0) to monitor critical system calls including execve, openat, and chmod. To eliminate inline context-switch latency, telemetry is streamed asynchronously to the Python mitigation layer via a lockless BPF_PERF_OUTPUT ring buffer.
- The Inference Engine (PyTorch LSTM)
Rather than relying on known threat hashes, the engine utilizes a Long Short-Term Memory (LSTM) Autoencoder (ChronoAutoencoder).
- Training: The model was trained exclusively on a sterile baseline dataset of ~480,000 benign system calls generated via automated filesystem traversals (
data_collector.py). - Inference: It evaluates a rolling window of 20 sequential system calls. If a process executes a highly abnormal sequence (e.g., a rapid ransomware encryption loop), the model fails to reconstruct the sequence, resulting in a spike in Mean Squared Error (MSE).
- Autonomous IPS (Mitigation)
Operating as an Intrusion Prevention System, the Python daemon continuously monitors the MSE loss output. If the anomaly score breaches the predefined mathematical threshold (MSE > 0.05), the system autonomously issues an asynchronous SIGKILL to the offending Process ID (PID), severing it from memory in real-time.
To defend against root-level evasion tactics where an adversary attempts to clear system logs, the telemetry pipeline includes a digital forensics layer (merkle_watcher.py). Every mitigation decision is hashed via SHA-256 alongside the previous event's hash. This creates an immutable, cryptographically entangled JSON ledger (/tmp/chrono_blockchain.json) that guarantees a tamper-proof Chain of Custody.
A real-time telemetry dashboard (dashboard.py) built with Streamlit provides the Blue Team with live visibility into kernel monitoring metrics, the MSE threshold, and forensic integrity status.
.
├── src/
│ ├── chrono_defender.py # Main eBPF sensor and PyTorch mitigation daemon
│ ├── dashboard.py # Streamlit-based C2 interface
│ ├── data_collector.py # Tracepoint-based baseline telemetry generator
│ ├── merkle_watcher.py # Background daemon for cryptographic log linking
│ └── verify_chain.py # Audit script to validate ledger immutability
├── malware-samples/
│ ├── c2_beacon.py # Simulates APT network exfiltration
│ ├── ransomware_sim.py # Simulates aggressive openat/chmod loops
│ └── ... # Additional behavioral threat simulations
├── models/
│ ├── brain_model.pth # Trained PyTorch LSTM weights
│ └── scaler.pkl # Data normalization scaler
├── data/ # Sterile CSV datasets
└── logs/ # Standard text execution outputs