SIEM & Hybrid Intrusion Detection System
Figure 1: SIEM & Hybrid Intrusion Detection System Overview
Project Overview
This project is a Hybrid Intrusion Detection System with a SIEM-style, multi-page web dashboard. It is capable of:
- Analyzing real network traffic and detecting threats
- Mapping them to MITRE ATT&CK tactics and techniques
- Pushing real-time alerts via WebSockets to a custom HTML/JS frontend
- Visualizing alerts with actionable security intelligence using ECharts
The system supports:
- Offline packet analysis on Windows using PCAP files
- Real-time live packet capture on Linux (via Scapy)
- Test mode for development using mock packets
- Centralized alert storage and multi-page visualization dashboard
Beyond simple alerting, the platform functions as a security analysis pipeline — it extracts flow-level features, scores anomalies statistically, correlates detections by source and time, and surfaces trends (severity distributions, temporal spikes, attacker profiling, and kill-chain coverage) so that findings can be read as intelligence rather than raw logs.
Objectives
- Detect network-based attacks using signature and anomaly-based techniques
- Provide real-time and offline traffic analysis
- Map detected attacks to the MITRE ATT&CK framework
- Present alerts through a user-friendly, SOC-style multi-page dashboard
- Push real-time alerts to the frontend using WebSockets
- Ensure cross-platform compatibility (Windows and Linux)
Key Features
| Feature | Description |
|---|---|
| Hybrid IDS | Signature + Anomaly (Isolation Forest) detection |
| PCAP Analysis | Offline packet analysis — Windows compatible |
| Live Capture | Real-time sniffing via Scapy — Linux |
| Test Mode | Mock packet injection for development |
| MITRE ATT&CK | Full tactic/technique mapping with kill chain view |
| WebSocket Alerts | Push-based real-time alert delivery |
| ECharts Visuals | Interactive charts (severity, timeline, top IPs, attack types) |
| Export Reports | Export alerts to CSV and PDF (jsPDF) |
| Alert Details Modal | Expandable per-alert detail view with traffic metadata |
| Severity Classification | High / Medium / Low with glow indicators |
| Multi-Page Dashboard | 4 dedicated pages: Dashboard, Alerts, Analytics, MITRE |
| FastAPI Backend | REST API + WebSocket server for alert ingestion/distribution |