Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
TopologyDigital Twin Architecture

Graph Universe Visualizer & 3.2M Node Topology Traversal

100% Complete & Untruncated 8 min read
Return to Research Tracks

J. McKenney

This is a standalone internal technical reference for the Cyber Digital Twin's Seldon Score subsystem rather than an entry in a numbered series; it documents the six physics-inspired risk indicators the WG-08-MO Monte Carlo engine and the CDT dashboard both draw on.

Licence: CC BY 4.0. 17 September 2026.

Executive Abstract#

The Cyber Digital Twin dashboard shows six risk gauges borrowed from physics: an epidemic-spread model (SIR R0), a barrier-crossing model from statistical mechanics (Kramers), an industry exploit-prediction score (EPSS velocity), a social-contagion threshold model (Granovetter), a magnetism model (Ising), and a network-resilience measure (the spectral gap). Each is a single number drawn from the same database and shown to an operator as one reading; an R0 above fifteen flips its gauge to a TIPPING status.

The document states, for each of the six, what it measures, where the number comes from, and whether the application computes it or only displays it. Four of the six (SIR R0, Kramers, Granovetter, and Ising) are populated by an external pipeline and read from the psychohistory_state table. Two, EPSS velocity and the spectral gap, are computed in the application's own Monte Carlo engine, cached for ten and fifteen minutes, and applied as multipliers on its random-walk edge weights rather than surfaced as display values of their own.

It makes no argument and defends no result. Its only claim is that the mapping from indicator to database column to dashboard weight matches what the application code actually does.

Abstract#

The Cyber Digital Twin uses six physics-inspired indicators derived from the SeldonPSYCH database. SIR R0, Kramers, EPSS velocity, Granovetter, Ising, and the spectral gap are read by the Seldon Score endpoint and the L6 globe layer to produce risk gauges on the CDT dashboard. SIR R0, Kramers, Granovetter, and Ising are populated by an external pipeline into the psychohistory_state table and displayed unchanged. EPSS velocity, drawn from the 555,556-row seldon.epss_trajectory table, and the spectral gap, drawn from seldon.spectral_analysis, are computed in the Node.js Monte Carlo engine (mc-weights.ts and mc-engine.ts) and applied as boost factors on random-walk edge weights, ranging from 1.15 to 1.5 for EPSS and up to 1.8 for the spectral gap. Each gauge maps to a database column and a dashboard weight, four at 0.20 and two at 0.10, with display thresholds from 0.02 for the spectral gap to 0.95 for Ising. A separate /ws/cdt WebSocket broadcasts a GPR score and incident count every thirty seconds but not the six indicators.

1. Overview and Indicator Summary#

The table below lists all six indicators together with where each one is actually computed, so a reader can see at a glance which are read from an external pipeline and which are computed inside the application.

IndicatorWhere ComputedNode.js ComputationData Source
SIR R0External pipeline → PGData display onlypsychohistory_state.sir_r0
KramersExternal pipeline → PGData display onlypsychohistory_state.kramers_mttc_epochs, kramers_barrier
EPSS VelocityNode.js (mc-weights.ts)Boost formula applied to MC walksseldon.epss_trajectory (555K rows)
GranovetterExternal pipeline → PGData display onlypsychohistory_state.granovetter_tau
IsingExternal pipeline → PGData display onlypsychohistory_state.ising_spin, ising_h_field
SpectralNode.js (mc-engine.ts); boost onlyEigenvector boost for MC walksseldon.spectral_analysis

2. SIR Compartmental Model (Epidemic Spreading)#

Physics analogy: Susceptible-Infected-Recovered epidemic model applied to vulnerability propagation.

What it measures: How fast a vulnerability "infects" connected systems across the OT/IT network. R0 > 15 triggers a "TIPPING" status.

Implementation: Data display only; no SIR computation in the application layer. The sir_r0 and sir_beta columns in seldon.psychohistory_state are populated by an external pipeline. The application reads them via SQL aggregation:

sql
-- From demo.ts (Seldon Score endpoint)
SELECT AVG(sir_r0) AS sir_r0
FROM seldon.psychohistory_state
WHERE computed_at > NOW() - INTERVAL '90 days'

Dashboard mapping: modelRisk("sir_r0") = min(1, sir_r0 / 50.0), weight 0.20.

Database columns: psychohistory_state.sir_r0, psychohistory_state.sir_beta

3. Kramers Barrier Escape (Time-to-Exploit)#

Physics analogy: Kramers escape rate from a potential well; the probability of a "particle" (attacker) overcoming an energy barrier (defensive control).

What it measures: Expected time for a known vulnerability to be exploited, given current defenses.

Implementation: Data display only; no Kramers computation in the application layer. The kramers_mttc_epochs (mean time to compromise in epochs) and kramers_barrier columns are populated by an external pipeline. The application reads them via:

sql
-- From demo.ts (Seldon Score endpoint)
SELECT AVG(1.0 / NULLIF(kramers_mttc_epochs, 0)) AS kramers
FROM seldon.psychohistory_state
WHERE computed_at > NOW() - INTERVAL '90 days'

The Kramers barrier is also used in the ATQ scoring pipeline via seldon.kramers_barriers (per-actor barrier heights), queried by the atq_c8_kramers() stored procedure. See CDT Mathematical Models for the full barrier formula.

Dashboard mapping: modelRisk("kramers") = min(1, kramers / 0.5), weight 0.20. Threshold: 0.40.

Database columns: psychohistory_state.kramers_mttc_epochs, psychohistory_state.kramers_barrier

4. EPSS Velocity (Exploitation Prediction)#

Physics analogy: Velocity of a moving object; rate of change in exploitation probability.

What it measures: How rapidly CVEs are approaching active exploitation, based on delta_30d from seldon.epss_trajectory.

Implementation: Computed in Node.js (mc-weights.ts). This is the only indicator with real-time application-layer computation. Two code paths use it:

Path 1; MC Edge Weight Modifier (mc-weights.ts computeEdgeWeight()):

typescript
// OPT-5: EPSS trending up = more likely to be exploited soon
if (targetProps.epss_delta_30d != null && targetProps.epss_delta_30d > 0.02) {
    w *= (1.0 + Math.min(targetProps.epss_delta_30d * 3.0, 0.5)); // up to 1.5x
}

Path 2; MC Walk Boost Map (mc-weights.ts getEpssVelocityMap()):

typescript
// Fetches top 100 CVEs with delta_30d > 0.05 from seldon.epss_trajectory
// Boost factor: 1.0 + min(delta_30d * 3.0, 0.5) => range [1.15, 1.5]
const boost = 1.0 + Math.min(e.delta_30d * 3.0, 0.5);

The boost map is cached for 10 minutes and applied during every Monte Carlo random walk step via the boostMaps.epssVelocity lookup in mc-engine.ts.

Data source: seldon.epss_trajectory (555,556 rows), filtered to delta_30d > 0.05, ordered by delta_30d DESC, limit 100.

Dashboard mapping: modelRisk("epss") = min(1, epss), weight 0.20. Threshold: 0.75.

Database table: seldon.epss_trajectory (columns: cve_id, epss_score, delta_30d, delta_14d, alert_flag)

5. Granovetter Cascade Threshold#

Physics analogy: Granovetter's threshold model of collective behavior; how many "neighbors" need to adopt a behavior before cascade occurs.

What it measures: The cascade probability; whether a breach at one facility will cascade to connected facilities.

Implementation: Data display only; no Granovetter computation in the application layer. The granovetter_tau column in seldon.psychohistory_state is populated by an external pipeline. The application reads it directly:

sql
-- From demo.ts (L6 globe layer)
SELECT AVG(ps.granovetter_tau) AS granovetter_tau
FROM seldon.psychohistory_state ps

The Granovetter value also comes from the seldon_score_v2 table via the cascade_probability column in the Seldon Score endpoint.

Dashboard mapping: modelRisk("granovetter") = min(1, value / 0.5), weight 0.20. Threshold: 0.35.

Database column: psychohistory_state.granovetter_tau

6. Ising Model (System Criticality)#

Physics analogy: Ising model of ferromagnetism; binary spin states (secure/compromised) with nearest-neighbor coupling.

What it measures: The "phase transition" proximity; how close the system is to a critical point where correlated failure becomes likely.

Implementation: Data display only; no Ising computation in the application layer. The ising_spin (binary 0/1) and ising_h_field columns are populated by an external pipeline. The application reads them via:

sql
-- From demo.ts (Seldon Score endpoint)
SELECT AVG(CASE WHEN ising_spin = 1
            THEN ising_h_field
            ELSE 1 - ising_h_field END) AS ising
FROM seldon.psychohistory_state
WHERE computed_at > NOW() - INTERVAL '90 days'

Dashboard mapping: modelRisk("ising") = min(1, ising), weight 0.10. Threshold: 0.95.

Database columns: psychohistory_state.ising_spin, psychohistory_state.ising_h_field

7. Spectral Gap (Network Resilience)#

Physics analogy: Spectral gap of the graph Laplacian; the difference between the first two eigenvalues of the adjacency matrix.

What it measures: Network connectivity resilience; a larger spectral gap means the network is more robust to node removal.

Implementation: Partially computed in Node.js (mc-engine.ts); boost map only. The eigenvector centrality computation itself (populating seldon.spectral_analysis) is performed by an external pipeline. The application reads the results and applies a boost to Monte Carlo walk edge weights:

typescript
// mc-engine.ts; getSpectralBoostMap()
// Top 50 nodes with eigen_rank < 0.1 (top 10% eigenvector centrality)
// Linear mapping: eigen_rank 0 => 1.8x boost, eigen_rank 0.1 => 1.1x boost
const boost = 1.8 - (n.eigen_rank * 7.0);
map.set(n.node_id, Math.max(1.1, boost));

The spectral boost is cached for 15 minutes and applied during MC random walk steps alongside EPSS velocity and TACAM boosts.

Dashboard mapping: modelRisk("spectral_gap") = min(1, 0.05 / max(spectral, 0.001)), weight 0.10. Threshold: 0.02 (lower = worse).

Database: seldon.spectral_analysis (columns: node_id, node_type, eigen_rank, spectral_gap), psychohistory_state.spectral_eigen_rank

8. API Endpoints (Actual)#

The indicators above are exposed to the dashboard and to other services through the endpoints below.

EndpointMethodDescription
/api/seldon/scoreGETSeldon Score with all 6 physics gauges aggregated from psychohistory_state (demo.ts)
/api/mc-real/reasoning/psychohistory-stateGETRaw psychohistory_state rows, optional ?customer= filter, top 50 by attack probability (mc-reasoning.ts)
/api/demo/globe-features?layer=l6GETPhysics per customer, geo-joined with customer_facilities for globe overlay (demo.ts)
/ws/cdtWSGPR score + incident count broadcast every 30 seconds (does not include the 6 indicators)

9. Database Table: seldon.psychohistory_state#

This is the central table for all 6 physics indicators. Key columns:

ColumnTypeIndicator
sir_r0numericSIR R0
sir_betanumericSIR transmission rate
kramers_mttc_epochsnumericKramers mean-time-to-compromise
kramers_barriernumericKramers barrier height
epcs_scorenumericEPSS composite score
granovetter_taunumericGranovetter cascade threshold
ising_spinintegerIsing spin state (0 or 1)
ising_h_fieldnumericIsing external field strength
spectral_eigen_ranknumericSpectral eigenvector rank
customertextCustomer code
system_idtextSystem identifier
epoch_idtextEpoch identifier
computed_attimestamptzComputation timestamp
attack_probnumericOverall attack probability
scvs_compositenumericSCVS composite score
geo_stabilitynumericGeopolitical stability
eic_netnumericEIC net score
psych_pressurenumericPsychographic pressure

10. References#

This document catalogues six indicators already implemented in the Cyber Digital Twin's database and Monte Carlo engine rather than external research, and each indicator above names its own database columns or source file in place of a citation. No published source is cited in this reference.

Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 12,651 chars