QuantumQuarantineLayer class

LAYER 6 — QuantumQuarantineLayer: a lightweight, rule-based anomaly detector. Despite the name, this deliberately avoids heavy AI/ML — it's a transparent, explainable scoring function over a handful of simple features:

  • transaction amount
  • request frequency (populated by RateLimitLayer via metadata)
  • device change (is this device new for the user?)
  • IP anomalies (is this IP new/unexpected for the user?)

Known devices/IPs per user are tracked in a pluggable StorageAdapter, so "new device" detection is accurate across restarts and, when backed by a shared adapter, across multiple server instances — a returning user is only ever flagged as "new_device" the very first time a given device is seen, never again afterwards.

Scoring rules:

  • High amount + new device increases the score.
  • High request frequency increases the score.
  • New/unexpected IP increases the score.

Thresholds (from SecurityConfig unless overridden):

  • score > blockThreshold (default 0.8) → block
  • score > flagThreshold (default 0.5) → flag (allowed, but marked for review)
  • else → allow
Implemented types

Constructors

QuantumQuarantineLayer({double highAmountThreshold = 1000, int highFrequencyThreshold = 10, StorageAdapter? storage, SecurityConfig config = const SecurityConfig(), double? blockThreshold, double? flagThreshold})
Creates an anomaly-detection layer, defaulting to MemoryStorage and the thresholds in config unless explicitly overridden.

Properties

blockThreshold → double
Risk score above which a request is blocked outright. Defaults to SecurityConfig.blockThreshold unless explicitly overridden.
final
flagThreshold → double
Risk score above which a request is allowed but flagged for review. Defaults to SecurityConfig.flagThreshold unless explicitly overridden.
final
hashCode → int
The hash code for this object.
no setterinherited
highAmountThreshold → double
Amount above which a transaction is considered "high value" for scoring purposes.
final
highFrequencyThreshold → int
Request-frequency threshold above which volume is considered suspicious for scoring purposes (independent of the hard rate limit enforced in RateLimitLayer).
final
name → String
A short, stable, human-readable name used in logs and results.
no setteroverride
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
storage → StorageAdapter
Persistent store of known devices/IPs per user. Defaults to MemoryStorage; pass a shared adapter for multi-instance deployments so device/IP history isn't lost or duplicated per instance.
final

Methods

check(RequestContext context) → Future<SecurityResult>
Inspects context and returns a SecurityResult.
override
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited