Cybersecurity
Network Intrusion Detection System
Machine-learning anomaly detection over live network traffic
- Python
- Scapy
- XGBoost
- Kafka
- +2
Cybersecurity · Capstone
Ingests syslog and auth logs, correlates events and alerts on anomalies
Overview
A scaled-down security information and event management system: agents ship syslog and Linux auth logs into a searchable store, correlation rules fire on patterns like repeated failed logins, and an unsupervised model flags volume and timing anomalies the rules miss. Analysts triage everything from a dashboard of ranked, deduplicated alerts.
What makes it stand up
Module breakdown
Ships and parses logs into a normalised event schema.
Indexes events for fast time-range and field search.
Rule engine matching multi-step suspicious sequences.
Baselines event rates and flags statistical outliers.
Ranks, deduplicates and tracks the state of each alert.
After this, you will be able to
Technology stack
You receive
Keep looking
Cybersecurity
Machine-learning anomaly detection over live network traffic