Smart India Hackathon 2026 · PS 26145 · NTRO — AI-based detection of cyber threats in unidirectional IP traffic using passive, read-only analysis.
Status: Full local demo implemented and tested — detection engine, FastAPI replay API with WebSocket alerts, React/HeroUI dashboard, nine threat scenarios, a local scikit-learn model layer, and benchmarked throughput/latency. Appwrite persistence and an optional Ollama explanation layer ship as adapters.
SIH26145 is a cybersecurity software system with a web dashboard. A local Python detection engine replays or ingests synthetic network-flow events, extracts behavioral features, detects threats, and emits explainable alerts. A React/TypeScript dashboard presents those alerts in near real time.
Synthetic traffic → read-only replay → Python detection engine
↓
structured alerts
↓
Appwrite storage/realtime
↓
React security dashboard
The prototype simulates a secure monitoring enclave. It does not claim to implement a physical data diode.
The live detection console shows scenario-driven replay controls, realtime metrics, a detection timeline, threat-class distribution, and a streaming alert table with severity, confidence, and supporting evidence for every detection.
Threat classes detected (9):
| Threat | Detection approach |
|---|---|
| SYN flood / volumetric DDoS | flow rate and source-IP entropy statistics |
| UDP reflection / amplification | packet rate + distinct sources toward amplification ports |
| Slowloris | held-open, incomplete connections; rate-capped to exclude floods |
| Botnet C2 beaconing | periodicity and inter-arrival analysis of repeating flows |
| DGA domains | entropy / n-gram analysis of DNS query names |
| DNS tunnelling | query length and record-type anomalies |
| Malware in encrypted sessions | TLS/QUIC metadata only — fingerprints, packet-size and timing |
| Reconnaissance / port scanning | fan-out across destination ports and hosts |
| Data exfiltration | asymmetric flow-volume and outbound/inbound byte ratios |
Architectural guarantees:
- Read-only ingest — never probes, re-contacts, blocks, or issues commands to the observed network.
- Metadata-only TLS/QUIC analysis — payloads are never decrypted.
- Streaming detection with bounded latency, not end-of-run batch reports.
- Standardized, explainable alerts: timestamp, flow ID, threat class, confidence, supporting evidence.
- Benchmark-verified throughput and latency (see Testing).
| Document | Covers |
|---|---|
| Project plan | Milestones and deliverables |
| Problem interpretation & scope | Reading of the PS and what is in/out of scope |
| Architecture | Pipeline and component design |
| Technology stack | Languages, frameworks, tools |
| Detection & ML | Detectors, features, model and evaluation |
| Dataset & scenarios | Fixtures and replay scenarios |
| Alert schema | Structured alert contract |
| Frontend | Dashboard design |
| Security constraints | Read-only and privacy guarantees |
| Testing & benchmarks | Test plan and measured throughput/latency |
| Roadmap | What's done and what's next |
| Local demo guide | Run it end-to-end |
| SIH submission | Problem → solution traceability for the hackathon |
| Area | Technology |
|---|---|
| Detection engine | Python |
| API/control plane | FastAPI |
| Packet/flow replay | JSONL initially; PCAP adapter later |
| Features and ML | Rule-based detectors plus a trained scikit-learn RandomForest layer (NumPy/SciPy features) |
| Alert validation | Pydantic |
| Application backend | Appwrite |
| Frontend | React, TypeScript, Vite |
| UI components | HeroUI + Tailwind CSS |
| Charts | Recharts |
| Local explanation model | Optional Qwen2.5-3B-Instruct through Ollama |
| Deployment | Docker Compose |
| Testing | pytest, Vitest, React Testing Library |
The primary detection path remains local and deterministic/measurable. The optional small local LLM only explains already-generated structured alerts; it does not make or change detection decisions.
python -m pip install -e 'backend[test]'
uvicorn sih_detector.api:app --app-dir backend/src --reloadIn a second terminal:
cd frontend
npm install
npm run devOpen http://localhost:5173, select a scenario, and start replay. The dashboard uses the local API and WebSocket by default. No network capture, Appwrite credentials, or external AI API is required.
docker compose upThe same dashboard is available at http://localhost:5173.
Licensed under the Apache License, Version 2.0.
