Two supported repair operators
Null guards for reference parameters and bounds guards for array/index parameters. The source location and parameter names must come from observed replay evidence.
Independent author manuscript
A bounded path from an observed failure to a tested software repair.
SDI connects request anomaly detection, instrumented replay, evidence-based repair, behavioral verification, and controlled deployment. This research artifact makes the implemented scope—and the evidence supporting it—available for inspection.
Five stages connect a suspicious request to a candidate that can be evaluated. Unsupported evidence stops the workflow.
A service-specific density model flags unusual normalized request features.
A configured replay backend captures an observed source location and parameters.
A supported AST guard changes the identified method in a registered source.
Original and candidate code compile; an explicit verifier tests behavior.
A configured backend controls deployment of a verified artifact.
Reproducibility
Results below come from the execution summary shipped with this deployment. Coverage describes the measured code and does not establish security effectiveness.
Boundaries of the artifact
What the implementation supports matters as much as its measured results.
Explore the source repositoryNull guards for reference parameters and bounds guards for array/index parameters. The source location and parameter names must come from observed replay evidence.
Compilation alone is insufficient. A caller-supplied behavioral verifier must accept the candidate. Tests demonstrate the registered fixtures; they do not prove correctness for arbitrary applications.
The detector uses deterministic Gaussian mixture partition fitting, not expectation-maximization. Signature extraction validates evidence; it does not implement genetic search. Bytecode distance is descriptive, not a security guarantee.
Replay and deployment depend on configured backends. A passing local test does not demonstrate production Kubernetes operation, zero-day prevention, or general exploit coverage.