Skip to content

Design evidence-preserving fusion for related detector findings #55

Description

@MahdiHedhli

Context

The current finding key intentionally keeps different detector categories separate, even when they concern the same device and observable. This protects explanation and lifecycle semantics but can show adjacent cards for one incident.

Desired outcome

Group related findings into a higher-level incident view without collapsing or obscuring detector evidence.

Acceptance criteria

  • Define deterministic correlation rules using stable device identity, typed observables, time windows, and detector relationships.
  • Keep each detector result and source provenance independently inspectable.
  • Distinguish primary evidence from corroboration.
  • Define incident priority, outcome, recurrence, suppression, and lifecycle semantics.
  • Prevent community-only evidence from independently creating or escalating an incident.
  • Preserve raw findings and make fusion reversible/auditable.
  • Add false-merge, DHCP-change, unresolved-device, recurrence, and concurrency tests.
  • Measure cards-per-incident and operator dismissal/suppression outcomes before broadening rules.

Boundary

No opaque ML grouping in the first implementation.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions