Skip to content

Sources: Suricata + AWS Network Firewall severity recalibration (ADR-0069 D4a) - #96

Merged
gterdem merged 4 commits into
mainfrom
issue-68-suricata-nfw-severity
Jul 17, 2026
Merged

gterdem merged 4 commits into
mainfrom
issue-68-suricata-nfw-severity

Conversation

@gterdem

@gterdem gterdem commented Jul 17, 2026

Copy link
Copy Markdown
Owner

Closes #68

Summary

Recalibrates the Suricata integer-priority → FireWatch severity map in both
firewatch_suricata/normalize.py and firewatch_aws_nfw/normalize.py (AWS NFW's
stateful engine IS Suricata, so this file copies the map verbatim — a test now
asserts the two maps stay identical). Implements ADR-0069 D4(a), with the
authorized golden re-bless per ADR-0069 D7.

Suricata priority Old New ADR-0069 D4(a) justification
1 (trojan-activity / web-application-attack / successful-admin) critical high Sigma high: "requires a prompt review" — not critical, a single ET match is FP-prone
2 (attempted-recon / misc-attack — ET SCAN / ET DROP-reputation ambient mass) high medium Sigma medium: "reviewed manually on a more frequent basis" — this class is ambient at volume on every exposed sensor (D1 distribution corollary)
3 (misc-activity — ET INFO) medium low Sigma low, verbatim
4 (unused by shipped classification.config) low info Sigma informational floor
missing/unparseable medium (or 3) low D3 rule 4, fail quiet — never fabricated upward

The point of the fix: priority-2 ambient/reputation/scan noise now maps to
medium, so it no longer qualifies an actor for Tier-2 triage on its own
(ADR-0067 D1(b)) — the remaining root cause of the triage flood per ADR-0069.

Landing order (ADR-0070 D8 / issue #68 must-NOT): #53 and #54 are both merged,
so this recalibration does not land ahead of the attempt-intensity/campaign
rules that keep sustained-but-unsuccessful attacks visible.

The golden re-bless (ADR-0069 D7 — the only authorized golden move)

tests/golden/fixtures/expected_scores.json is byte-identical
(scoring reads no severity — verified; ADR-0069 D7):

  • OLD sha256: fe4787643955c920e934e3789c79f741cd8c8cde6b2adbc6540b66ff3743f31f
  • NEW sha256: fe4787643955c920e934e3789c79f741cd8c8cde6b2adbc6540b66ff3743f31f (unchanged)

Per-artifact moves, exactly as ADR-0069 D7 enumerates:

Artifact (EVE severity) Old → New D7 line
expected_01_web_attack_alert.json (sev 2) high → medium D7 row 1
expected_02_port_scan_block.json (sev 1) critical → high D7 row 2
expected_03_trojan_alert.json (sev 2) high → medium D7 row 3
expected_04_privesc_mitre.json (sev 1) critical → high D7 row 4
expected_05_recon_alert.json (sev 3) medium → low D7 row 5 (D7 notes this file moves too — "earlier scoping listed only 01/02/03/04/06")
expected_06_tls_dns_flow_enriched.json (sev 2) high → medium D7 row 6
tests/golden/test_suricata_normalize.py in-file oracles (_ORACLE_01..05) + the severity=1 oracle test (renamed test_severity_high_for_severity_1, was test_severity_critical_for_severity_1 — same D7-enumerated artifact, renamed for truthfulness since the assertion now checks high not critical) per D4(a) table D7 row 7
tests/golden/test_suricata_e2e_demo.py severity assertions (events 1/2/7/8) per D4(a) table D7 row 8
packages/sources/suricata/tests/test_plugin.py severity-mapping + NB-4 fallback tests per D4(a)/D3 D7 row 9
packages/sources/aws-nfw/tests/test_aws_nfw.py severity-mapping test per D4(a) D7 row 9
tests/golden/test_suricata_network_depth.py (test_severity_and_action_unchanged, fixture 06's inline pin) high → medium Same enumerated expected_06 artifact — this in-file assertion pins the same fixture/value D7 row 6 authorizes; updated for internal consistency, not an additional golden move

Unchanged, as required (the regression net):

New coverage (net-new, not a golden move)

New file: tests/golden/test_issue_68_severity_recalibration.py.

Acceptance criteria checklist

Out of scope (per issue #68)

Test plan

  • bash scripts/gates-backend.sh green — tree
    /home/galip/projects/firewatch/.claude/worktrees/agent-a5d5b37b089ac307b,
    branch issue-68-suricata-nfw-severity, HEAD deb9f7d (post-merge with
    origin/main): 4399 passed, 1 skipped (pre-existing, unrelated), ruff +
    pyright clean.
  • git diff on tests/golden/fixtures/ shows only the six enumerated
    expected_0N_*.json severity fields changed — nothing else.

gterdem added 4 commits July 17, 2026 00:38
Recalibrate the Suricata integer-priority -> FireWatch severity map in both
firewatch_suricata/normalize.py and firewatch_aws_nfw/normalize.py (NFW's
stateful engine IS Suricata; the copy must stay identical):

  1 (trojan-activity/web-application-attack/successful-admin) -> high (was critical)
  2 (attempted-recon/misc-attack — ambient ET SCAN/DROP mass)  -> medium (was high)
  3 (misc-activity — ET INFO)                                   -> low (was medium)
  4 (unused by shipped classification.config)                   -> info (was low)
  missing/unparseable                                           -> low, fail quiet (was `or 3` -> medium)

Priority-2 ambient/reputation/scan noise now maps to medium and no longer
qualifies an actor for Tier-2 triage on its own (ADR-0067 D1(b)) — the
remaining root cause of the triage flood identified in ADR-0069.

Golden re-bless (ADR-0069 D7, the only authorized golden move): the six
Suricata normalize oracles move to the values D7 enumerates.
expected_scores.json is untouched (scoring reads no severity) and the CEF-path
pins in test_syslog_cef_golden.py are unchanged (regression net proving no
leak into the CEF path).

New coverage: the two severity maps are asserted identical (can't silently
diverge again); a routing test through the real qualify()/decide() gate
proves a priority-2-only actor stays in the observed stratum while a
priority-1 breach (alone, or planted among 50 priority-2 ambient events)
still reaches Tier 2.
@gterdem
gterdem merged commit 4dbb736 into main Jul 17, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sources: Suricata + AWS Network Firewall severity recalibration — priority-2 ambient noise stops earning a triage ticket (ADR-0069 D4a)

1 participant