High-performance, passive, unidirectional cyber threat detection platform engineered for high-security, air-gapped network perimeters behind hardware data diodes.
Operating strictly behind an isolated optical hardware data diode, NetSentinel performs real-time threat detection on simplex, receive-only IP network traffic streams with zero transmission capability, sub-millisecond classification, and bounded memory footprint.
Physical / Virtual Tap (Optical Diode / Rx-Only)
│
▼
Zeek + Suricata Engines
│
▼
Normalized Telemetry Stream
(TSV conn/dns/ssl + Suricata EVE JSON)
│
▼
┌───────────────────────────────────────┐
│ Fast Behavioral Gate (<1 µs) │
│ (L4/L7 Header Screening & Heuristics)│
└───────────────────┬───────────────────┘
│
┌─────────────────────┴─────────────────────┐
│ PASS_NORMAL │ SUSPICIOUS / UNKNOWN
▼ ▼
┌───────────────────┐ ┌───────────────────┐
│ Welford O(1) │ │ 54-D Vectorized │
│ Flow State │ │ Feature Extractor│
│ (Moments & Jitter│ │ (Contiguous Pool)│
└───────────────────┘ └─────────┬─────────┘
│
▼
┌───────────────────┐
│ Inlined Fast │
│ Z-Score Scaler │
└─────────┬─────────┘
│
▼
┌───────────────────┐
│ ONNX Runtime RF │
│ (100 Trees SIMD) │
└─────────┬─────────┘
│
┌─────────┴─────────┐
rf_conf >= 0.75 │ │ rf_conf < 0.75
(High Certainty) ▼ ▼ (Ambiguous Anomaly)
┌────────────────┐ ┌────────────────┐
│ Bypass Iso- │ │ Selective Iso- │
│ Forest (0 ms) │ │ Forest Engine │
└────────┬───────┘ └────────┬───────┘
│ │
└─────────┬──────────┘
│
▼
┌───────────────────┐
│ Prioritized Threat│
│ Fusion Resolver │
└─────────┬─────────┘
│
▼
┌───────────────────┐
│ Security Alert │
│ Deduplication │
└─────────┬─────────┘
│
┌─────────────┴─────────────┐
▼ ▼
FastAPI Streaming REST/WS Streamlit SOC Dashboard
(http://localhost:8000) (http://localhost:8501)
__slots__, eliminating Python dynamic dict overhead and cutting per-flow memory by 56.9% (down to $3,175\text{ bytes/flow}$).intra_op_num_threads=1).POST /api/ai/explain-alert) to generate structured, four-part advisory explanations for human SOC operators.Evaluated on the exact same CPU-only hardware environment across all 6 realistic replay scenarios (1,618 events, 613 active flows):
| Metric | Baseline (Scikit-Learn) | Optimized (Integrated ONNX) | Improvement Factor |
|---|---|---|---|
| Pipeline Replay Duration | $71.02\text{ s}$ | $35.47\text{ s}$ | 2.0x faster |
| Throughput (Replay) | $22.8\text{ evt/s}$ | $45.6\text{ evt/s}$ | 2.0x higher |
| Throughput (Synthetic Burst) | $5,800\text{ evt/s}$ | $131,442\text{ evt/s}$ | 22.6x higher |
| End-to-End Latency ($p50$) | $42.66\text{ ms}$ | $21.58\text{ ms}$ | 1.98x faster |
| End-to-End Latency ($p95$) | $50.16\text{ ms}$ | $23.32\text{ ms}$ | 2.15x faster |
| End-to-End Latency ($p99$) | $63.88\text{ ms}$ | $27.51\text{ ms}$ | 2.32x lower tail jitter |
| Random Forest Inference ($p50$) | $15.898\text{ ms}$ | $0.0815\text{ ms}$ | 195x faster |
| Memory per 5,000 Active Flows | $35.10\text{ MB}$ | $15.14\text{ MB}$ | 56.9% memory savings |
| Cold Start to First Prediction | $0.2222\text{ s}$ | $0.0427\text{ s}$ | 5.2x faster startup |
| Model Size on Disk (RF) | $309.7\text{ KB}$ | $105.1\text{ KB}$ | 2.95x smaller |
| Feature Schema Parity | 54 / 54 Dimensions | 54 / 54 Dimensions | 100% Identical |
open(..., 'rb') iterators and generator streams.send(), sendto()).The repository enforces modular separation between the headless sensor appliance and the management plane:
| Tier | Requirements File | Target Environment | Footprint |
|---|---|---|---|
| Core Passive Sensor | requirements-sensor.txt |
Headless Data Diode Sensor Appliance | < 85 MB (6 packages: numpy, pydantic, onnxruntime, scikit-learn, joblib, dpkt) |
| Full SOC & Management | requirements.txt |
Central SOC, Streamlit Dashboard, FastAPI Server | Standard deployment with UI, AI Explainer & benchmark suites |
To enable the “Explain with Claude” feature in the analyst dashboard:
cp .env.example .env
.env (or set as environment variable):
ANTHROPIC_API_KEY=sk-ant-api03-...
# Optional: customize model (default: claude-3-5-haiku-20241022)
ANTHROPIC_MODEL=claude-3-5-haiku-20241022
(If unconfigured, NetSentinel runs normally in fully offline mode with clear instructions on alert explanation cards).
git clone https://github.com/adityakharad320-hash/sih-unidirectional-threat-detection.git
cd sih-unidirectional-threat-detection
python -m pip install -r requirements-sensor.txt
python -m pip install -r requirements.txt
python -m pytest backend/tests -v
cd backend
python run_controlled_scenarios.py
cd backend
python run_pipeline_benchmark.py
Start FastAPI Streaming Backend:
cd backend
python -m uvicorn app.main:app --host 0.0.0.0 --port 8000 --reload
Start Streamlit SOC Cybersecurity Dashboard:
streamlit run dashboard/app.py --server.port 8501
Open http://localhost:8501 to view the monitoring interface and inspect alerts with Claude.
sih-unidirectional-threat-detection/
├── .env.example # Template for API credentials & model config
├── backend/
│ ├── app/
│ │ ├── ai/ # Claude Messages API integration (models & explainer)
│ │ ├── alerts/ # SecurityAlert_v2 engine & deduplication
│ │ ├── detectors/ # 6 behavioral detection engines
│ │ ├── ingestion/ # PCAP & raw packet stream readers
│ │ ├── ml/ # Hybrid RF (ONNX) + IF inference & dataset builder
│ │ ├── pipeline/ # In-memory streaming orchestrator (Gate + Welford)
│ │ ├── telemetry/ # Zeek / Suricata log parsers & 54-D feature schema
│ │ └── main.py # FastAPI application & WebSocket router
│ ├── models/
│ │ └── weights/ # Pre-trained weights & random_forest_v2.0.onnx
│ ├── tests/ # 100 automated pytest test cases
│ ├── run_controlled_scenarios.py
│ ├── run_pipeline_benchmark.py
│ └── run_sih_benchmark.py
├── dashboard/
│ ├── app.py # Streamlit application layout
│ ├── api_client.py # Resilient API client with in-process fallback
│ └── components/ # Overview, Alerts, Details ("Explain with Claude"), Analytics, Governance
├── optimized/ # Modular optimized reference implementation
│ ├── gate.py # Fast behavioral screening gate (<1 µs)
│ ├── flow_tracker.py # Welford O(1) statistical flow engine
│ ├── feature_pipeline.py # Zero-copy contiguous 54-D feature buffer
│ ├── inference_engine.py # Vectorized inlined Z-scaler
│ ├── fusion.py # Streamlined threat fusion & IF escalation
│ └── onnx_converter.py # Sklearn-to-ONNX conversion pipeline
├── benchmarks/ # Microsecond profiling harnesses & raw JSON results
├── reports/ # Comprehensive forensic & performance engineering reports
├── requirements.txt # Full platform dependencies (including anthropic)
├── requirements-sensor.txt # Headless passive diode sensor dependencies (<85 MB)
└── docs/ # Technical architecture & compliance specifications
MIT License. NetSentinel — netsentinel.dev • Contact: contact@netsentinel.dev