Skip to content

Write the battery deep-dive: graded-response methodology + stated instrument limits #39

Description

@NickCrew

Summary

Write the capstone analysis document for the honest battery: how Crucible's
scenarios performed against Synapse, and — more importantly — what was actually
measured and what was deliberately not.
The doc's credibility comes from stating
its two honesty boundaries as features, not buried caveats. A report that
names what its instrument cannot measure is more trustworthy than one that
implies total coverage.

This is the capstone: it can only be written credibly once the scoring is graded
(#37), the curve is reported (#38), and the run is reproducible (atlas-crew/Bridge#3).

The two honesty boundaries (stated as features)

1. Distributed-correlation exclusion — an instrument limit

The battery does not claim to test Synapse's distributed / multi-source
correlation detection, because the instrument (Crucible) generates single-origin,
L7-only traffic — "many origins" is header spoofing (X-Forwarded-For,
User-Agent), not genuinely distinct network sources or TLS fingerprints
(see #36). State this proudly and precisely: name the class of detection the
instrument cannot exercise, so no reader infers coverage that was never claimed.
This is the inverse of the botnet false-positive — honesty about the instrument's
reach prevents a fake-green at the report level.

2. Graded-response methodology — why "caught/missed" is too crude

A behavioral WAF that escalates Cookie → JS PoW → CAPTCHA → Tarpit → Block does
not have a binary verdict. Document what we measured instead:

Acceptance criteria

Related / blocked by

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions