Skip to content

Genome pattern, format v1 (draft)

Status: draft. Vector: spec/xybern-formats-v1/vectors/genome.json. Reference: Threat Genome.

A genome pattern is the structure of a refused, terminated or quarantined path. It holds no identifiers, no content and no argument values, so two organisations that refused the same shape produce the same pattern_id.

Key Meaning
format "xybern-genome-pattern-v1"
family the action family (first token of the action type)
resource_class the resource class only, lower case, never an instance
delegation {depth: "0" | "1" | "2+", kinds: [authority kinds in play]}
signals the rule types and signal codes that fired, sorted
effect {kind, irreversible, external} of the expected effect
outcome refused, terminated or quarantined
path the decision path category
pattern_id gen_ and the first sixteen hex characters of the SHA-256 of the canonical JSON of the other keys

A feed entry (xybern-genome-feed-v1) is {pattern_id, pattern, count, contributors, first_seen, last_seen}; contributors is the number of distinct blinded contributor hashes, never a list of organisations.