Sources: Suricata + AWS Network Firewall severity recalibration (ADR-0069 D4a) - #96
Merged
Merged
Conversation
Recalibrate the Suricata integer-priority -> FireWatch severity map in both firewatch_suricata/normalize.py and firewatch_aws_nfw/normalize.py (NFW's stateful engine IS Suricata; the copy must stay identical): 1 (trojan-activity/web-application-attack/successful-admin) -> high (was critical) 2 (attempted-recon/misc-attack — ambient ET SCAN/DROP mass) -> medium (was high) 3 (misc-activity — ET INFO) -> low (was medium) 4 (unused by shipped classification.config) -> info (was low) missing/unparseable -> low, fail quiet (was `or 3` -> medium) Priority-2 ambient/reputation/scan noise now maps to medium and no longer qualifies an actor for Tier-2 triage on its own (ADR-0067 D1(b)) — the remaining root cause of the triage flood identified in ADR-0069. Golden re-bless (ADR-0069 D7, the only authorized golden move): the six Suricata normalize oracles move to the values D7 enumerates. expected_scores.json is untouched (scoring reads no severity) and the CEF-path pins in test_syslog_cef_golden.py are unchanged (regression net proving no leak into the CEF path). New coverage: the two severity maps are asserted identical (can't silently diverge again); a routing test through the real qualify()/decide() gate proves a priority-2-only actor stays in the observed stratum while a priority-1 breach (alone, or planted among 50 priority-2 ambient events) still reaches Tier 2.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #68
Summary
Recalibrates the Suricata integer-priority → FireWatch severity map in both
firewatch_suricata/normalize.pyandfirewatch_aws_nfw/normalize.py(AWS NFW'sstateful engine IS Suricata, so this file copies the map verbatim — a test now
asserts the two maps stay identical). Implements ADR-0069 D4(a), with the
authorized golden re-bless per ADR-0069 D7.
or 3)The point of the fix: priority-2 ambient/reputation/scan noise now maps to
medium, so it no longer qualifies an actor for Tier-2 triage on its own(ADR-0067 D1(b)) — the remaining root cause of the triage flood per ADR-0069.
Landing order (ADR-0070 D8 / issue #68 must-NOT): #53 and #54 are both merged,
so this recalibration does not land ahead of the attempt-intensity/campaign
rules that keep sustained-but-unsuccessful attacks visible.
The golden re-bless (ADR-0069 D7 — the only authorized golden move)
tests/golden/fixtures/expected_scores.jsonis byte-identical(scoring reads no severity — verified; ADR-0069 D7):
fe4787643955c920e934e3789c79f741cd8c8cde6b2adbc6540b66ff3743f31ffe4787643955c920e934e3789c79f741cd8c8cde6b2adbc6540b66ff3743f31f(unchanged)Per-artifact moves, exactly as ADR-0069 D7 enumerates:
expected_01_web_attack_alert.json(sev 2)expected_02_port_scan_block.json(sev 1)expected_03_trojan_alert.json(sev 2)expected_04_privesc_mitre.json(sev 1)expected_05_recon_alert.json(sev 3)expected_06_tls_dns_flow_enriched.json(sev 2)tests/golden/test_suricata_normalize.pyin-file oracles (_ORACLE_01..05) + the severity=1 oracle test (renamedtest_severity_high_for_severity_1, wastest_severity_critical_for_severity_1— same D7-enumerated artifact, renamed for truthfulness since the assertion now checkshighnotcritical)tests/golden/test_suricata_e2e_demo.pyseverity assertions (events 1/2/7/8)packages/sources/suricata/tests/test_plugin.pyseverity-mapping + NB-4 fallback testspackages/sources/aws-nfw/tests/test_aws_nfw.pyseverity-mapping testtests/golden/test_suricata_network_depth.py(test_severity_and_action_unchanged, fixture 06's inline pin)expected_06artifact — this in-file assertion pins the same fixture/value D7 row 6 authorizes; updated for internal consistency, not an additional golden moveUnchanged, as required (the regression net):
tests/golden/fixtures/expected_scores.json— byte-identical (sha shown above)tests/golden/test_syslog_cef_golden.py— CEF-path pins untouched, proving no leak into the CEF path (D4d)packages/sources/syslog*— out of scope (sibling issue Sources: syslog + syslog_cef fallback — one failed login is 'low', not 'high' (ADR-0069 D4b) #69, already merged separately)New coverage (net-new, not a golden move)
TestSeverityMapsIdentical/TestFailQuietParity— the two_SEVERITY_MAPdicts (and
_map_severity()fail-quiet behavior) are asserted identicalbetween
firewatch_suricataandfirewatch_aws_nfw, so the copy can'tsilently diverge again (issue Sources: Suricata + AWS Network Firewall severity recalibration — priority-2 ambient noise stops earning a triage ticket (ADR-0069 D4a) #68 AC1).
TestPriorityTwoNeverReachesTier2— routes REALnormalize()output for apriority-2-only actor through the REAL
qualify()/decide()gate (not justa mapping unit test) and asserts it stays in the observed stratum
(
tier=None,disposition="observed") for both Suricata and AWS NFW.TestGenuineBreachStillQueues— a lone priority-1 ALERT, and a priority-1breach planted among 50 priority-2 ambient events from the same actor, still
reach Tier 2 — the staged equivalent of the Tests: the volume oracle — a deterministic 'ambient night' fixture gates triage usability at realistic scale #50 breach-among-noise variant
(issue Sources: Suricata + AWS Network Firewall severity recalibration — priority-2 ambient noise stops earning a triage ticket (ADR-0069 D4a) #68 AC, until Tests: the volume oracle — a deterministic 'ambient night' fixture gates triage usability at realistic scale #50 lands), with a control test proving the ambient
noise alone does NOT queue.
New file:
tests/golden/test_issue_68_severity_recalibration.py.Acceptance criteria checklist
normalize()mapsalert.severityto{1: high, 2: medium, 3: low, 4: info}with missing/unparseable →
low, identically in both packages, with atest asserting map parity.
land ahead of them.
Tier 2 — asserted through the real
qualify()/decide()gate.values D7 states;
expected_scores.jsonis byte-identical (sha shownabove); CEF-path pins in
test_syslog_cef_golden.pyare unchanged.equivalent of the Tests: the volume oracle — a deterministic 'ambient night' fixture gates triage usability at realistic scale #50 variant).
(table above and in the mapping-table code comments).
Out of scope (per issue #68)
classification.confighandling.Test plan
bash scripts/gates-backend.shgreen — tree/home/galip/projects/firewatch/.claude/worktrees/agent-a5d5b37b089ac307b,branch
issue-68-suricata-nfw-severity, HEADdeb9f7d(post-merge withorigin/main): 4399 passed, 1 skipped (pre-existing, unrelated), ruff +pyright clean.
git diffontests/golden/fixtures/shows only the six enumeratedexpected_0N_*.jsonseverity fields changed — nothing else.