# Architecture — PDHPI

**Polymorphic Dual Hyper-Predictive Infrastructure.**

Two engines, one state file, one process.

1. **Wrapper morphing** — the console changes the shape of its own
   packets on a fixed schedule. Padding bucket, framing style, and
   header ordering rotate together. Behavior is identical; bytes are not.
2. **Adversarial prediction** — a small set of hypotheses runs against
   the rolling event window and produces a ranked list of what the
   attacker is likely to try next. Predictions are armed before the
   request arrives; hits are logged.

Together they form a proactive posture. The console does not just wait
to score incoming traffic — it changes the terrain and anticipates the
next step.

## What runs here

One PHP file. It creates its own supporting files on first visit, stores
its state as JSON on disk, and serves a live operations console in a
browser. No database, no message broker, no external API calls.

## Mapping to production

| Console pane | Reference (this repo) | Production equivalent |
|---|---|---|
| Event stream | PHP-generated events | CloudWatch Logs → EventBridge |
| Wrapper rotation | JSON state in `state.json` | Envoy filter / Lambda@Edge / WAF rule set |
| Prediction queue | Closures over event window | SageMaker endpoint / Lambda hypothesis runner |
| Threat score | Rolling window in JSON | Lambda aggregation → DynamoDB |
| Blocked sources | Counter | WAF IP set + Security Group ingress |
| Morph log | Ring buffer | DynamoDB stream + Kinesis |
| Report export | HTML/CSV/JSON download | Lambda → SES → S3 with Object Lock |

## The two-engine pattern

    ┌──────────────────────────────────────────────────────┐
    │                                                      │
    │  ┌─────────────────┐         ┌────────────────────┐  │
    │  │ Wrapper morph   │         │ Prediction engine  │  │
    │  │ (offense-side)  │         │ (defense-side)     │  │
    │  └────────┬────────┘         └─────────┬──────────┘  │
    │           │                            │             │
    │           └──────────┬─────────────────┘             │
    │                      ▼                               │
    │              rolling event window                    │
    │                      │                               │
    │                      ▼                               │
    │              state.json (single source)              │
    │                                                      │
    └──────────────────────────────────────────────────────┘

The morph engine writes to `morph_log`. The prediction engine reads
`events` and writes to `predictions`. They share a state file but not
a code path. Their only visible meeting point is the morph bubble in
the bottom-right corner of the console.

## Runtime requirements

- PHP 7.4 or newer
- Write access to its own folder
- Anything that serves PHP

## Runtime non-requirements

- No database, no Composer, no Python, no Node
- No cloud provider, no external services