AI-Based Network Attack Forecasting from Network Traffic Data — SIH26153 (NTRO)
Browser / UI
│ HTTP
▼
Flask app
│
├──▶ Database — SQLite
└──▶ ML models — scikit-learn, XGBoost
- Language: Python
- Backend: Flask
- Frontend: Web frontend (frontend)
- Database: SQLite
- ML: scikit-learn, XGBoost
- Deployment: Docker container / Render (render.yaml)
- Python 3.10+
- Docker (optional, for container runs)
git clone https://github.com/SabarishR08/ai-network-attack-forecasting.git
cd ai-network-attack-forecastingpython -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install -r requirements.txtcp .env.example .env # then fill in valuesEnvironment variables used: FLASK_SECRET_KEY, FLASK_DEBUG, PORT, ENABLE_FORECASTING_MODEL, ENABLE_KILLCHAIN.
Most features work without keys; integrations activate when keys are set.
python integration/app.pypython run.pydocker compose up --buildDefined in render.yaml (web service netwatch-sih26153-api) with autoDeploy enabled — pushes to the default branch trigger a Render deploy.
AI-Based Network Attack Forecasting from Network Traffic Data — SIH26153 (NTRO)
Browser / UI
│ HTTP
▼
Flask app
│
├──▶ Database — SQLite
└──▶ ML models — scikit-learn, XGBoost
- Language: Python
- Backend: Flask
- Frontend: Web frontend (frontend)
- Database: SQLite
- ML: scikit-learn, XGBoost
- Deployment: Docker container / Render (render.yaml)
- Python 3.10+
- Docker (optional, for container runs)
git clone https://github.com/SabarishR08/ai-network-attack-forecasting.git
cd ai-network-attack-forecastingpython -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install -r requirements.txtcp .env.example .env # then fill in valuesEnvironment variables used: FLASK_SECRET_KEY, FLASK_DEBUG, PORT, ENABLE_FORECASTING_MODEL, ENABLE_KILLCHAIN.
Most features work without keys; integrations activate when keys are set.
python integration/app.pypython run.pydocker compose up --buildDefined in render.yaml (web service netwatch-sih26153-api) with autoDeploy enabled — pushes to the default branch trigger a Render deploy.
Problem statement: AI Based Network Attack Forecasting from Network Traffic Data Problem owner: NTRO Team: Sabarish R et al.
An integrated threat detection and forecasting system that:
- Captures network traffic (real or synthetic)
- Detects anomalies (port scans, brute force, SYN floods, etc.)
- Forecasts escalation probability before attacks fully execute
- Enriches incidents with MITRE ATT&CK kill chain context
- Visualizes everything in a real-time Flask dashboard
- Python 3.10+
- Git
- Npcap (Windows only) — download from https://npcap.com
git clone --recurse-submodules https://github.com/SabarishR08/ai-network-attack-forecasting.git
cd ai-network-attack-forecasting
python -m venv venv
venv\Scripts\activate # Windows
# source venv/bin/activate # macOS/Linux
pip install -r requirements.txt
copy .env.example .env # Windows
# cp .env.example .env # macOS/Linuxpython run.py # Full pipeline + dashboard
# Open http://localhost:5000python run.py --monitor # Windows (run as admin)
# sudo python run.py --monitor # macOS/LinuxFor detailed step-by-step instructions (including Npcap, 3-terminal testing, troubleshooting), see:
# Terminal 1 — Start the IDS
python run.py --monitor
# Terminal 2 — Scan your machine (triggers detection)
python scan_self.py
# Terminal 3 — Watch the dashboard
# Open http://localhost:5000Network Traffic → Anomaly Detection → Feature Extraction → ML Forecasting → Kill Chain → Dashboard
↑ ↑ ↑ ↑ ↑
NTAV repo NTAV repo NEW (ours) NEW (ours) Killchain repo
See docs/ARCHITECTURE.md for the full technical architecture.
| File | Purpose |
|---|---|
run.py |
Main entry point |
integration/ |
Core pipeline (detection, forecasting, dashboard) |
repos/ |
Original source repositories |
data/ |
Runtime data (packets, anomalies, features) |
docs/ |
Architecture, demo script, results |
SETUP.md |
Full setup & testing guide |
simulate_attack.py |
Generate synthetic attack data |
validate_detection.py |
Automated detection validation |
scan_self.py |
Quick self-scan test |
| Command | Description |
|---|---|
python run.py |
Full pipeline + dashboard |
python run.py --no-pipeline |
Dashboard only |
python run.py --pipeline-only |
Pipeline only, then exit |
python run.py --live |
Capture 30s of real traffic |
python run.py --monitor |
Continuous live monitoring |
python validate_detection.py |
Run all 6 detection tests |
python simulate_attack.py |
Generate synthetic data |
python scan_self.py |
Scan your own machine |
The project includes PowerScan as a test traffic generator in repos/network-port-scanner/.
cd repos/network-port-scanner
pip install -r requirements.txt
python portscanergui.py
# Open http://127.0.0.1:5000See SETUP.md for full instructions.
MIT — © 2026 Sabarish R.
MIT — © 2026 Sabarish R.