cyb009-baseline-classifier / feature_meta.json
pradeep-xpert's picture
Initial release: vulnerability_class baseline + comprehensive 8-oracle-path leakage diagnostic on CYB009 sample
e520bf1 verified
{
"feature_names": [
"cvss_base_score",
"epss_score_final",
"exploitation_occurred_flag",
"zero_day_flag",
"cisa_kev_flag",
"supply_chain_propagation_flag",
"compensating_control_flag",
"false_positive_flag",
"remediation_success_flag",
"sla_compliance_flag",
"scanner_coverage",
"patch_mgmt_maturity",
"mean_time_to_remediate_days",
"sla_critical_days",
"sla_high_days",
"sla_medium_days",
"internet_exposed_flag",
"sbom_depth_score",
"log_epss",
"is_high_cvss",
"exposure_severity_composite",
"risk_flag_count",
"epss_x_base",
"severity_class_critical",
"severity_class_high",
"severity_class_low",
"severity_class_medium",
"asset_type_api_gateway",
"asset_type_cloud_vm",
"asset_type_container_workload",
"asset_type_database_server",
"asset_type_endpoint_workstation",
"asset_type_iot_firmware_device",
"asset_type_network_service",
"asset_type_ot_ics_controller",
"asset_type_saas_integration",
"asset_type_server_on_premises",
"asset_type_supply_chain_dependency",
"asset_type_web_application",
"criticality_tier_critical",
"criticality_tier_high",
"criticality_tier_low",
"criticality_tier_medium",
"environment_type_edge_iot_fleet",
"environment_type_hybrid_cloud",
"environment_type_on_premises_datacenter",
"environment_type_ot_ics_network",
"environment_type_public_cloud_aws",
"environment_type_public_cloud_azure",
"environment_type_public_cloud_gcp",
"environment_type_saas_dependent",
"os_family_android_iot",
"os_family_embedded_rtos",
"os_family_freebsd",
"os_family_linux",
"os_family_macos",
"os_family_windows"
],
"numeric_features": [
"cvss_base_score",
"epss_score_final",
"exploitation_occurred_flag",
"zero_day_flag",
"cisa_kev_flag",
"supply_chain_propagation_flag",
"compensating_control_flag",
"false_positive_flag",
"remediation_success_flag",
"sla_compliance_flag",
"scanner_coverage",
"patch_mgmt_maturity",
"mean_time_to_remediate_days",
"sla_critical_days",
"sla_high_days",
"sla_medium_days",
"internet_exposed_flag",
"sbom_depth_score",
"log_epss",
"is_high_cvss",
"exposure_severity_composite",
"risk_flag_count",
"epss_x_base"
],
"categorical_levels": {
"severity_class": [
"critical",
"high",
"low",
"medium"
],
"asset_type": [
"api_gateway",
"cloud_vm",
"container_workload",
"database_server",
"endpoint_workstation",
"iot_firmware_device",
"network_service",
"ot_ics_controller",
"saas_integration",
"server_on_premises",
"supply_chain_dependency",
"web_application"
],
"criticality_tier": [
"critical",
"high",
"low",
"medium"
],
"environment_type": [
"edge_iot_fleet",
"hybrid_cloud",
"on_premises_datacenter",
"ot_ics_network",
"public_cloud_aws",
"public_cloud_azure",
"public_cloud_gcp",
"saas_dependent"
],
"os_family": [
"android_iot",
"embedded_rtos",
"freebsd",
"linux",
"macos",
"windows"
]
},
"label_to_int": {
"auth_access_control": 0,
"cryptographic_failure": 1,
"information_disclosure": 2,
"injection_family": 3,
"logic_flaw": 4,
"memory_corruption": 5,
"misconfiguration": 6,
"supply_chain_weakness": 7
},
"int_to_label": {
"0": "auth_access_control",
"1": "cryptographic_failure",
"2": "information_disclosure",
"3": "injection_family",
"4": "logic_flaw",
"5": "memory_corruption",
"6": "misconfiguration",
"7": "supply_chain_weakness"
},
"outcome_leak_excluded": [
"time_to_exploit_days",
"time_to_remediate_days",
"patch_lag_days",
"risk_score_composite",
"exploit_maturity_final",
"cvss_temporal_score_final"
]
}