O
OSCF Handbook Accessible cybersecurity standards
Draft v0.1 Repo Framework Docs Overview
← Back to Architecture

Architecture

Risk Engine

Decision logic for challenge strength and escalation.

Latest version

AGVS Draft v0.1

This section is part of the current public OSCF documentation draft.

Inputs

  • request frequency
  • retry count
  • challenge reuse attempts
  • session freshness
  • automation indicators
  • device consistency signals

Outputs

  • risk_score
  • risk_level
  • challenge_strength
  • allow / retry / escalate / block

Risk levels

Low

Normal interaction pattern, no suspicious retries.

Medium

Elevated retry count or unusual timing.

High

Replay attempt detected or rapid abuse pattern.

Draft section of the OSCF public documentation.