QuantumQuarantineLayer class
LAYER 6 — QuantumQuarantineLayer: a lightweight, rule-based anomaly detector. Despite the name, this deliberately avoids heavy AI/ML — it's a transparent, explainable scoring function over a handful of simple features:
- transaction amount
- request frequency (populated by RateLimitLayer via metadata)
- device change (is this device new for the user?)
- IP anomalies (is this IP new/unexpected for the user?)
Known devices/IPs per user are tracked in a pluggable StorageAdapter, so "new device" detection is accurate across restarts and, when backed by a shared adapter, across multiple server instances — a returning user is only ever flagged as "new_device" the very first time a given device is seen, never again afterwards.
Scoring rules:
- High amount + new device increases the score.
- High request frequency increases the score.
- New/unexpected IP increases the score.
Thresholds (from SecurityConfig unless overridden):
- score > blockThreshold (default 0.8) → block
- score > flagThreshold (default 0.5) → flag (allowed, but marked for review)
- else → allow
- Implemented types
Constructors
- QuantumQuarantineLayer({double highAmountThreshold = 1000, int highFrequencyThreshold = 10, StorageAdapter? storage, SecurityConfig config = const SecurityConfig(), double? blockThreshold, double? flagThreshold})
-
Creates an anomaly-detection layer, defaulting to MemoryStorage
and the thresholds in
configunless explicitly overridden.
Properties
- blockThreshold → double
-
Risk score above which a request is blocked outright. Defaults to
SecurityConfig.blockThreshold unless explicitly overridden.
final
- flagThreshold → double
-
Risk score above which a request is allowed but flagged for review.
Defaults to SecurityConfig.flagThreshold unless explicitly
overridden.
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- highAmountThreshold → double
-
Amount above which a transaction is considered "high value" for
scoring purposes.
final
- highFrequencyThreshold → int
-
Request-frequency threshold above which volume is considered
suspicious for scoring purposes (independent of the hard rate
limit enforced in RateLimitLayer).
final
- name → String
-
A short, stable, human-readable name used in logs and results.
no setteroverride
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- storage → StorageAdapter
-
Persistent store of known devices/IPs per user. Defaults to
MemoryStorage; pass a shared adapter for multi-instance
deployments so device/IP history isn't lost or duplicated per
instance.
final
Methods
-
check(
RequestContext context) → Future< SecurityResult> -
Inspects
contextand returns a SecurityResult.override -
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited