0
Likes
0
Saves
Back to updates

[r/ML] Isolation Forest + eBPF events to create a Linux based endpoint detection system [P]

Impact: 7/10
Swipe left/right

Summary

Guardd is a Linux-based host anomaly detection system that leverages the Isolation Forest machine learning algorithm. It uses eBPF to collect execution and network events, grouping them into 60-second windows to create feature vectors. These vectors, comprising counts of unique processes, files, IPs, and ports, are then scored by the model to identify unusual activity.

Editorial note

AI Dose summarizes public reporting and links to original sources when they are available. Review the Editorial Policy, Disclaimer, or Contact page if you need to flag a correction or understand how this site handles sources.

Continue Reading

Explore related coverage about community news and adjacent AI developments: [r/ML] [D] MYTHOS-INVERSION STRUCTURAL AUDIT, [r/LocalLLaMA] karpathy / autoresearch, [HN] Is anyone else bothered that AI agents can basically do what they want?, [r/ML] Why production systems keep making “correct” decisions that are no longer right [D].

Related Articles

Next read

[r/ML] [D] MYTHOS-INVERSION STRUCTURAL AUDIT

Stay with the thread by reading one adjacent story before leaving this update.

Comments

Sign in to leave a comment.

Loading comments...