Skip to content
archduke1337Public

About

SIH 2026 (PS 26145) — AI-based detection of cyber threats in unidirectional IP traffic. Passive flow analysis with rule + scikit-learn detectors, FastAPI/WebSocket alert stream, React dashboard.

Topics

Resources

Security policy

Stars

6 stars

Watchers

0 watching

Forks

Repository files navigation

SIH26145 — Passive AI Cyber-Threat Detection

Smart India Hackathon 2026 · PS 26145 · NTRO — AI-based detection of cyber threats in unidirectional IP traffic using passive, read-only analysis.

CI License Python FastAPI React

Status: Full local demo implemented and tested — detection engine, FastAPI replay API with WebSocket alerts, React/HeroUI dashboard, nine threat scenarios, a local scikit-learn model layer, and benchmarked throughput/latency. Appwrite persistence and an optional Ollama explanation layer ship as adapters.

What are we building?

SIH26145 is a cybersecurity software system with a web dashboard. A local Python detection engine replays or ingests synthetic network-flow events, extracts behavioral features, detects threats, and emits explainable alerts. A React/TypeScript dashboard presents those alerts in near real time.

Synthetic traffic → read-only replay → Python detection engine
                                      ↓
                              structured alerts
                                      ↓
                         Appwrite storage/realtime
                                      ↓
                           React security dashboard

The prototype simulates a secure monitoring enclave. It does not claim to implement a physical data diode.

Dashboard

Passive Detection Console — live dashboard

The live detection console shows scenario-driven replay controls, realtime metrics, a detection timeline, threat-class distribution, and a streaming alert table with severity, confidence, and supporting evidence for every detection.

Features

Threat classes detected (9):

Threat Detection approach
SYN flood / volumetric DDoS flow rate and source-IP entropy statistics
UDP reflection / amplification packet rate + distinct sources toward amplification ports
Slowloris held-open, incomplete connections; rate-capped to exclude floods
Botnet C2 beaconing periodicity and inter-arrival analysis of repeating flows
DGA domains entropy / n-gram analysis of DNS query names
DNS tunnelling query length and record-type anomalies
Malware in encrypted sessions TLS/QUIC metadata only — fingerprints, packet-size and timing
Reconnaissance / port scanning fan-out across destination ports and hosts
Data exfiltration asymmetric flow-volume and outbound/inbound byte ratios

Architectural guarantees:

  • Read-only ingest — never probes, re-contacts, blocks, or issues commands to the observed network.
  • Metadata-only TLS/QUIC analysis — payloads are never decrypted.
  • Streaming detection with bounded latency, not end-of-run batch reports.
  • Standardized, explainable alerts: timestamp, flow ID, threat class, confidence, supporting evidence.
  • Benchmark-verified throughput and latency (see Testing).

Documentation

Document Covers
Project plan Milestones and deliverables
Problem interpretation & scope Reading of the PS and what is in/out of scope
Architecture Pipeline and component design
Technology stack Languages, frameworks, tools
Detection & ML Detectors, features, model and evaluation
Dataset & scenarios Fixtures and replay scenarios
Alert schema Structured alert contract
Frontend Dashboard design
Security constraints Read-only and privacy guarantees
Testing & benchmarks Test plan and measured throughput/latency
Roadmap What's done and what's next
Local demo guide Run it end-to-end
SIH submission Problem → solution traceability for the hackathon

Stack

Area Technology
Detection engine Python
API/control plane FastAPI
Packet/flow replay JSONL initially; PCAP adapter later
Features and ML Rule-based detectors plus a trained scikit-learn RandomForest layer (NumPy/SciPy features)
Alert validation Pydantic
Application backend Appwrite
Frontend React, TypeScript, Vite
UI components HeroUI + Tailwind CSS
Charts Recharts
Local explanation model Optional Qwen2.5-3B-Instruct through Ollama
Deployment Docker Compose
Testing pytest, Vitest, React Testing Library

Demo principle

The primary detection path remains local and deterministic/measurable. The optional small local LLM only explains already-generated structured alerts; it does not make or change detection decisions.

Run the local demo

Option A: local processes

python -m pip install -e 'backend[test]'
uvicorn sih_detector.api:app --app-dir backend/src --reload

In a second terminal:

cd frontend
npm install
npm run dev

Open http://localhost:5173, select a scenario, and start replay. The dashboard uses the local API and WebSocket by default. No network capture, Appwrite credentials, or external AI API is required.

Option B: Docker Compose

docker compose up

The same dashboard is available at http://localhost:5173.

License

Licensed under the Apache License, Version 2.0.

About

SIH 2026 (PS 26145) — AI-based detection of cyber threats in unidirectional IP traffic. Passive flow analysis with rule + scikit-learn detectors, FastAPI/WebSocket alert stream, React dashboard.

Topics

Resources

Security policy

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages