Cybersecurity
Network Intrusion Detection System
Machine-learning anomaly detection over live network traffic
- Python
- Scapy
- XGBoost
- Kafka
- +2
Cybersecurity · Capstone
Watches file events for entropy spikes and halts the process in a sandbox
Overview
A behavioural monitor that watches file-system events on a sandboxed VM and looks for the signature of ransomware in progress: bursts of rapid rewrites, mass renames and a sharp rise in file entropy as content is encrypted. When the pattern crosses a threshold it suspends the offending process, and the whole experiment runs on a disposable VM with benign simulators, never live ransomware.
What makes it stand up
Module breakdown
Captures create, modify and rename events with metadata.
Computes entropy, write bursts and rename rates in windows.
Scores activity and confirms with a debounce threshold.
Suspends the culprit process and snapshots the evidence.
Benign simulators that mimic encryption behaviour safely.
After this, you will be able to
Technology stack
You receive
Keep looking
Cybersecurity
Machine-learning anomaly detection over live network traffic