Cybersecurity
Network Intrusion Detection System
Machine-learning anomaly detection over live network traffic
- Python
- Scapy
- XGBoost
- Kafka
- +2
Cybersecurity · Major Project
Classifies Windows executables as benign or malicious from static features
Overview
Trains a gradient-boosted classifier on the public EMBER dataset, which describes Windows PE files through pre-extracted static features such as header fields, imports, section entropy and byte histograms. No live malware is executed or distributed. A small web app extracts the same features from an uploaded file and returns a verdict with the features that drove it.
What makes it stand up
Module breakdown
Loads EMBER vectors and builds train and test splits by date.
Explores imports, section entropy and header fields by class.
Gradient boosting with tuned depth, learning rate and leaves.
Measures detection rate at fixed false-positive thresholds.
Extracts PE features from an upload and shows the verdict.
After this, you will be able to
Technology stack
You receive
Keep looking
Cybersecurity
Machine-learning anomaly detection over live network traffic