Independent author manuscript

Synthetic
Digital Immunity

A bounded path from an observed failure to a tested software repair.

SDI connects request anomaly detection, instrumented replay, evidence-based repair, behavioral verification, and controlled deployment. This research artifact makes the implemented scope—and the evidence supporting it—available for inspection.

Sasikanth KesaniWashington DC Metropolitan Area, USA

Every repair needs an evidence trail.

Five stages connect a suspicious request to a candidate that can be evaluated. Unsupported evidence stops the workflow.

  1. 1

    Detect

    A service-specific density model flags unusual normalized request features.

  2. 2

    Replay

    A configured replay backend captures an observed source location and parameters.

  3. 3

    Repair

    A supported AST guard changes the identified method in a registered source.

  4. 4

    Verify

    Original and candidate code compile; an explicit verifier tests behavior.

  5. 5

    Deploy

    A configured backend controls deployment of a verified artifact.

Reproducibility

Inspect the evidence.

Results below come from the execution summary shipped with this deployment. Coverage describes the measured code and does not establish security effectiveness.

Loading the execution summary…

Boundaries of the artifact

A narrow contract.
An inspectable result.

What the implementation supports matters as much as its measured results.

Explore the source repository

Two supported repair operators

Null guards for reference parameters and bounds guards for array/index parameters. The source location and parameter names must come from observed replay evidence.

Explicit verification

Compilation alone is insufficient. A caller-supplied behavioral verifier must accept the candidate. Tests demonstrate the registered fixtures; they do not prove correctness for arbitrary applications.

Deliberate algorithm limits

The detector uses deterministic Gaussian mixture partition fitting, not expectation-maximization. Signature extraction validates evidence; it does not implement genetic search. Bytecode distance is descriptive, not a security guarantee.

Deployment requires infrastructure

Replay and deployment depend on configured backends. A passing local test does not demonstrate production Kubernetes operation, zero-day prevention, or general exploit coverage.