Repository navigation
Feat/credential stuffing - #15
Merged
Merged
Conversation
Extends item 8's AnomalyStore rather than tracking attempts twice: CountTargetsForIP reads the same rows and partial index, so no migration. Known and unknown targets are counted separately because the attempted email is never stored — unknowns can only be attempts.
Runs on failures (where a spray is visible) and on successes (where a spray that landed is visible), both after the attempt is recorded so the burst includes it. Cooldown keeps a sustained attack to a few audit events instead of one per failed attempt. Report-only, nil-safe.
The wiring tests are the point: one IP failing against many accounts is flagged, one account hammered repeatedly is not, a success from a spraying IP is flagged against its account, and a broken store or a zero TargetAccounts degrades to no detection rather than no logins.
Runs the spray, the unknown-address variant, the one-account-hammered case that must NOT flag, cooldown suppression, and both off switches against an in-memory engine. No database required.
Covers the spray, the unknown-address variant, the one-account case that must not flag, cooldown behaviour, both off switches, and the per-IP blind spot a botnet-distributed spray leaves.
Item 9 removed from NEXT.md and its remaining items renumbered, per that file's convention. CURRENT-STATE.md records the branch, why it was cut from feat/anomaly-detection instead of main, and the assumptions.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.