Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

A signature-less Endpoint Detection and Response (EDR) prototype for Linux. It utilizes eBPF for zero-latency Ring-0 system call telemetry, a PyTorch LSTM Autoencoder for temporal sequence anomaly detection, and a SHA-256 Merkle chain to guarantee forensic log immutability.

This project was engineered to demonstrate a Zero-Trust approach to endpoint security, shifting detection from static malware signatures to dynamic execution behavior.

Core Architecture

  1. The Sensor (eBPF)

The data ingestion layer (chrono_defender.py) bypasses user-space entirely. It injects dynamic Kprobes into the Linux kernel (Ring-0) to monitor critical system calls including execve, openat, and chmod. To eliminate inline context-switch latency, telemetry is streamed asynchronously to the Python mitigation layer via a lockless BPF_PERF_OUTPUT ring buffer.

  1. The Inference Engine (PyTorch LSTM)

Rather than relying on known threat hashes, the engine utilizes a Long Short-Term Memory (LSTM) Autoencoder (ChronoAutoencoder).

  • Training: The model was trained exclusively on a sterile baseline dataset of ~480,000 benign system calls generated via automated filesystem traversals (data_collector.py).
  • Inference: It evaluates a rolling window of 20 sequential system calls. If a process executes a highly abnormal sequence (e.g., a rapid ransomware encryption loop), the model fails to reconstruct the sequence, resulting in a spike in Mean Squared Error (MSE).
  1. Autonomous IPS (Mitigation)

Operating as an Intrusion Prevention System, the Python daemon continuously monitors the MSE loss output. If the anomaly score breaches the predefined mathematical threshold (MSE > 0.05), the system autonomously issues an asynchronous SIGKILL to the offending Process ID (PID), severing it from memory in real-time.

4. Forensic Immutability (Merkle Ledger)

To defend against root-level evasion tactics where an adversary attempts to clear system logs, the telemetry pipeline includes a digital forensics layer (merkle_watcher.py). Every mitigation decision is hashed via SHA-256 alongside the previous event's hash. This creates an immutable, cryptographically entangled JSON ledger (/tmp/chrono_blockchain.json) that guarantees a tamper-proof Chain of Custody.

5. Command & Control (C2) Dashboard

A real-time telemetry dashboard (dashboard.py) built with Streamlit provides the Blue Team with live visibility into kernel monitoring metrics, the MSE threshold, and forensic integrity status.

Directory Structure

.
├── src/
│   ├── chrono_defender.py     # Main eBPF sensor and PyTorch mitigation daemon
│   ├── dashboard.py           # Streamlit-based C2 interface
│   ├── data_collector.py      # Tracepoint-based baseline telemetry generator
│   ├── merkle_watcher.py      # Background daemon for cryptographic log linking
│   └── verify_chain.py        # Audit script to validate ledger immutability
├── malware-samples/
│   ├── c2_beacon.py           # Simulates APT network exfiltration
│   ├── ransomware_sim.py      # Simulates aggressive openat/chmod loops
│   └── ...                    # Additional behavioral threat simulations
├── models/
│   ├── brain_model.pth        # Trained PyTorch LSTM weights
│   └── scaler.pkl             # Data normalization scaler
├── data/                      # Sterile CSV datasets
└── logs/                      # Standard text execution outputs

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages