第 1 层 · SENSE · 四层架构

感知

直接触碰对手的一层——持续进行,在生产环境中。

在推理开始之前,必须有真实的观测。我们的蜜罐传感器伪装成互联网上的脆弱服务,接收真实的攻击流量。这里没有任何合成数据:以下每个数字都是对生产遥测的实时查询。

查询 /api/metrics →攻击地图
L1 · PROOF实时数据
Honeypot events
D1 · honeypot_logs
Events / 24h
live window
Events / last hour
live window
Arrival rate λ
model · per second
L1 · HOW感知如何工作
step 1

Decoys on the open internet

Vulnerable-looking services exposed on purpose. Attackers find them the same way they find anything: scanning.

step 2

Probes become events

Each probe is logged as an event — source, timing, protocol, payload shape. Individually noise; in aggregate, a live map of adversarial behaviour.

step 3

IOCs extracted

IPs, credential patterns, fingerprints — indicators of compromise ready for correlation in layer 02.

step 4

Poisson modelling

Arrivals follow $P(k) = (\lambda t)^k e^{-\lambda t}/k!$ per window. λ is estimated live from the last hour; the homepage overlays observed counts on this model. Deviation from the model is itself signal.

L1 · NEXT信号的下游去向
→ L2

Agent swarm

IOCs and events are correlated by 54 specialised agents.

→ layer 02 · connect
→ page

Attack map

Geographic and temporal view of live attack activity.

→ attack-map.html
→ contract

Manifesto

Why “proven, not claimed” is a design rule, not a slogan.

→ /vision