Genome pattern, format v1 (draft)¶
Status: draft. Vector: spec/xybern-formats-v1/vectors/genome.json. Reference: Threat Genome.
A genome pattern is the structure of a refused, terminated or quarantined path. It holds no identifiers, no content and no argument values, so two organisations that refused the same shape produce the same pattern_id.
| Key | Meaning |
|---|---|
format |
"xybern-genome-pattern-v1" |
family |
the action family (first token of the action type) |
resource_class |
the resource class only, lower case, never an instance |
delegation |
{depth: "0" | "1" | "2+", kinds: [authority kinds in play]} |
signals |
the rule types and signal codes that fired, sorted |
effect |
{kind, irreversible, external} of the expected effect |
outcome |
refused, terminated or quarantined |
path |
the decision path category |
pattern_id |
gen_ and the first sixteen hex characters of the SHA-256 of the canonical JSON of the other keys |
A feed entry (xybern-genome-feed-v1) is {pattern_id, pattern, count, contributors, first_seen, last_seen}; contributors is the number of distinct blinded contributor hashes, never a list of organisations.