Cybersecurity
Network Intrusion Detection System
Machine-learning anomaly detection over live network traffic
- Python
- Scapy
- XGBoost
- Kafka
- +2
Cybersecurity · Major Project
Fake SSH and HTTP services that log and map attacker behaviour
Overview
Low-interaction SSH and HTTP honeypots present convincing but sandboxed services that record every connection, credential attempt and request without exposing a real system. Events stream into MongoDB, and a dashboard geolocates source addresses, ranks the credentials and paths most often tried, and charts attack volume over time.
What makes it stand up
Module breakdown
Emulated SSH and HTTP services that capture attempts safely.
Normalises and persists every interaction to MongoDB.
Adds GeoIP and reverse-DNS context to each source address.
Maps origins and ranks the most-tried credentials and paths.
Container and firewall setup that keeps the trap contained.
After this, you will be able to
Technology stack
You receive
Keep looking
Cybersecurity
Machine-learning anomaly detection over live network traffic