AT&T Developer Hub · Schema

ThreatAssessment

ThreatAssessment schema

Fortune 1005GNetwork APIsCAMARAConnectivityTelecommunicationsEdge ComputingDevice StatusSIM Swap

Properties

Name Type Description
riskLevel string Overall risk level for the device
anomalyScore number Normalized anomaly score from 0.0 (normal) to 1.0 (highly anomalous)
threats array List of detected threat indicators
assessedAt string Timestamp of the threat assessment
View JSON Schema on GitHub

JSON Schema

mobility-threat-anomaly-detection-api-threat-assessment-schema.json Raw ↑
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://raw.githubusercontent.com/api-evangelist/at-t-developer-hub/refs/heads/main/json-schema/mobility-threat-anomaly-detection-api-threat-assessment-schema.json",
  "title": "ThreatAssessment",
  "description": "ThreatAssessment schema",
  "type": "object",
  "properties": {
    "riskLevel": {
      "type": "string",
      "description": "Overall risk level for the device",
      "enum": [
        "LOW",
        "MEDIUM",
        "HIGH",
        "CRITICAL"
      ],
      "example": "LOW"
    },
    "anomalyScore": {
      "type": "number",
      "format": "double",
      "description": "Normalized anomaly score from 0.0 (normal) to 1.0 (highly anomalous)",
      "minimum": 0.0,
      "maximum": 1.0,
      "example": 0.05
    },
    "threats": {
      "type": "array",
      "description": "List of detected threat indicators",
      "items": {
        "type": "object",
        "properties": {
          "type": {
            "type": "string",
            "description": "Type of threat detected",
            "enum": [
              "UNUSUAL_LOCATION",
              "ABNORMAL_DATA_USAGE",
              "KNOWN_MALWARE_TRAFFIC",
              "SIM_CLONING",
              "ROAMING_ANOMALY",
              "CALL_PATTERN_ANOMALY"
            ],
            "example": "UNUSUAL_LOCATION"
          },
          "severity": {
            "type": "string",
            "description": "Severity of the threat indicator",
            "enum": [
              "LOW",
              "MEDIUM",
              "HIGH",
              "CRITICAL"
            ],
            "example": "MEDIUM"
          },
          "description": {
            "type": "string",
            "description": "Human-readable description of the threat",
            "example": "Device location changed rapidly from expected home area"
          },
          "detectedAt": {
            "type": "string",
            "format": "date-time",
            "description": "When the threat indicator was detected",
            "example": "2026-04-19T14:30:00Z"
          }
        }
      }
    },
    "assessedAt": {
      "type": "string",
      "format": "date-time",
      "description": "Timestamp of the threat assessment",
      "example": "2026-04-19T14:30:00Z"
    }
  }
}