___                 ___                 ___         __          ___         ___         ___         ___     
     /  /\    __         /  /\    ___        /  /\       |  |\       /  /\       /  /\       /  /\       /  /\    
    /  /::\  |  |\      /  /::|  /__/\      /  /::\      |  |:|     /  /::\     /  /::\     /  /::\     /  /::\   
   /__/:/\:\ |  |:|    /  /:|:|  \  \:\    /  /:/\:\     |  |:|    /__/:/\:\   /  /:/\:\   /  /:/\:\   /  /:/\:\  
  _\_ \:\ \:\|  |:|   /  /:/|:|__ \__\:\  /  /::\ \:\    |__|:|__ _\_ \:\ \:\ /  /::\ \:\ /  /:/  \:\ /  /::\ \:\ 
 /__/\ \:\ \:|__|:|__/__/:/ |:| /\/  /::\/__/:/\:\_\:__ /__/::::/__/\ \:\ \:/__/:/\:\_\:/__/:/_\_ \:/__/:/\:\ \:\
 \  \:\ \:\_\/  /::::\__\/  |:|/:/  /:/\:\__\/  \:\/:\__\::::/~~~\  \:\ \:\_\\__\/  \:\/:\  \:\__/\_\\  \:\ \:\_\/
  \  \:\_\:\/  /:/~~~~   |  |:/:/  /:/__\/    \__\::/   |~~|:|    \  \:\_\:\      \__\::/ \  \:\ \:\  \  \:\ \:\  
   \  \:\/:/__/:/        |__|::/__/:/         /  /:/    |  |:|     \  \:\/:/      /  /:/   \  \:\/:/   \  \:\_\/  
    \  \::/\__\/         /__/:/\__\/         /__/:/     |__|:|      \  \::/      /__/:/     \  \::/     \  \:\    
     \__\/               \__\/               \__\/       \__\|       \__\/       \__\/       \__\/       \__\/    


SIEM & Hybrid Intrusion Detection System

View on GitHub (SIEM_IDS_1.0) →
SIEM and Hybrid IDS Architecture
Figure 1: SIEM & Hybrid Intrusion Detection System Overview

Project Overview

This project is a Hybrid Intrusion Detection System with a SIEM-style, multi-page web dashboard. It is capable of:

  • Analyzing real network traffic and detecting threats
  • Mapping them to MITRE ATT&CK tactics and techniques
  • Pushing real-time alerts via WebSockets to a custom HTML/JS frontend
  • Visualizing alerts with actionable security intelligence using ECharts

The system supports:

  • Offline packet analysis on Windows using PCAP files
  • Real-time live packet capture on Linux (via Scapy)
  • Test mode for development using mock packets
  • Centralized alert storage and multi-page visualization dashboard

Beyond simple alerting, the platform functions as a security analysis pipeline — it extracts flow-level features, scores anomalies statistically, correlates detections by source and time, and surfaces trends (severity distributions, temporal spikes, attacker profiling, and kill-chain coverage) so that findings can be read as intelligence rather than raw logs.

Objectives

  • Detect network-based attacks using signature and anomaly-based techniques
  • Provide real-time and offline traffic analysis
  • Map detected attacks to the MITRE ATT&CK framework
  • Present alerts through a user-friendly, SOC-style multi-page dashboard
  • Push real-time alerts to the frontend using WebSockets
  • Ensure cross-platform compatibility (Windows and Linux)

Key Features

Feature Description
Hybrid IDS Signature + Anomaly (Isolation Forest) detection
PCAP Analysis Offline packet analysis — Windows compatible
Live Capture Real-time sniffing via Scapy — Linux
Test Mode Mock packet injection for development
MITRE ATT&CK Full tactic/technique mapping with kill chain view
WebSocket Alerts Push-based real-time alert delivery
ECharts Visuals Interactive charts (severity, timeline, top IPs, attack types)
Export Reports Export alerts to CSV and PDF (jsPDF)
Alert Details Modal Expandable per-alert detail view with traffic metadata
Severity Classification High / Medium / Low with glow indicators
Multi-Page Dashboard 4 dedicated pages: Dashboard, Alerts, Analytics, MITRE
FastAPI Backend REST API + WebSocket server for alert ingestion/distribution

← Back to Projects