Skip to content

Latest commit

Β 

History

21 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ CRIDAP

Cyber Risk Intelligence & Adaptive Defense Platform

A unified AI-powered cybersecurity system that monitors threats, correlates attack chains, scores risk dynamically, and recommends adaptive defenses β€” in real time.

Python FastAPI ML License Status


πŸ“Œ Overview

With increasing complexity of cyber threats, organizations need intelligent systems capable of detecting attacks, prioritizing risks, and protecting sensitive data in real time.

CRIDAP integrates behavioural analytics, dynamic risk scoring, and incident correlation into a single unified cybersecurity solution β€” going beyond traditional SIEM tools by reconstructing full attack chains and recommending adaptive defenses β€” all visualized through a live SOC intelligence dashboard.


✨ Key Features

Module Description
πŸ”Ž Multi-Layer Activity Monitor Ingests network, auth, and application logs
πŸ€– Behavioural Anomaly Detection ML-based detection using Isolation Forest
πŸ”— Attack Chain Correlation Links isolated events into full attack timelines
πŸ“Š Dynamic Risk Scoring Per-user, per-device, per-service risk scores (0–100)
πŸ” Privacy Risk Monitor Detects unauthorized data access and exfiltration
⚠️ Adaptive Defense Advisor Context-aware mitigations (MFA, isolation, patching)
πŸ“‘ SOC Intelligence Dashboard Live 3D cybersecurity visualization with real data

πŸ—οΈ Architecture

Data Sources (Network / Identity / Application Logs)
                      ↓
           [ Preprocessing & Normalization Layer ]
                      ↓
       [ Behavioural ML Anomaly Detection Engine ]
                Isolation Forest | LSTM
                      ↓
         [ Alert Correlation & Chain Builder ]
                      ↓
         [ Dynamic Cyber Risk Scoring Module ]
           User Score | Device Score | Service Score
                      ↓
    [ Privacy Monitor ]     [ Defense Advisor ]
                      ↓
    [ FastAPI REST Backend Β· http://127.0.0.1:8000 ]
                      ↓
         [ Live SOC Intelligence Dashboard ]

πŸ“ Project Structure

cyber-risk-platform/
β”œβ”€β”€ src/
β”‚   β”œβ”€β”€ ingestion/          # Log parsers and data collectors
β”‚   β”œβ”€β”€ detection/          # Isolation Forest anomaly detection
β”‚   β”œβ”€β”€ correlation/        # Attack chain correlation engine
β”‚   β”œβ”€β”€ scoring/            # Dynamic risk scoring logic
β”‚   β”œβ”€β”€ privacy/            # Privacy risk monitoring (5 rules)
β”‚   β”œβ”€β”€ advisor/            # Adaptive defense recommendation engine
β”‚   └── dashboard/          # FastAPI REST backend
β”œβ”€β”€ data/
β”‚   └── sample_logs/
β”‚       └── sample_events.json   # 40 events Β· 22 entities
β”œβ”€β”€ output/                 # Pipeline results (auto-generated)
β”œβ”€β”€ tests/                  # 10 unit tests
β”œβ”€β”€ scripts/
β”‚   └── run_pipeline.py     # Main pipeline runner
β”œβ”€β”€ docs/
β”‚   └── architecture.md
β”œβ”€β”€ index.html              # Live SOC Dashboard (frontend)
β”œβ”€β”€ requirements.txt
β”œβ”€β”€ docker-compose.yml
└── README.md

πŸš€ How to Run

Follow these steps every time you want to start the project.

Prerequisites

  • Python 3.10+
  • Git

Step 1 β€” Clone the repository

git clone https://github.com/Hack-Break/cyber-risk-intelligence-platform.git
cd cyber-risk-platform

Step 2 β€” Create and activate virtual environment

python -m venv venv

Windows (PowerShell):

venv\Scripts\activate

Mac / Linux:

source venv/bin/activate

Step 3 β€” Install dependencies

pip install numpy pandas scikit-learn loguru fastapi uvicorn pydantic

Step 4 β€” Run the detection pipeline

python scripts/run_pipeline.py --log-dir data/sample_logs/

Expected output:

πŸ›‘οΈ  Starting Cyber Risk Intelligence Pipeline
πŸ“₯ Step 1: Ingesting logs...       β†’ 40 events loaded
πŸ€– Step 2: Anomaly detection...    β†’ 2 anomalies detected
πŸ”— Step 3: Attack chains...        β†’ 0 chains identified
πŸ“Š Step 4: Risk scoring...         β†’ 22 entities scored
πŸ” Step 5: Privacy monitoring...   β†’ 86 privacy signals
⚠️  Step 6: Defense advisor...     β†’ 6 recommendations
βœ… Pipeline complete. Results saved to output/results.json

Step 5 β€” Start the API server

uvicorn src.dashboard.api:app --reload

Expected output:

INFO:     Uvicorn running on http://127.0.0.1:8000
INFO:     Application startup complete.

Step 6 β€” Open the dashboard

Open index.html in your browser. The API status bar at the bottom will show 🟒 API Connected and all widgets will populate with live data.


⚑ Quick Start (One Block)

cd cyber-risk-platform
venv\Scripts\activate
python scripts/run_pipeline.py --log-dir data/sample_logs/
uvicorn src.dashboard.api:app --reload

Then open index.html in your browser.


🌐 API Endpoints

Endpoint Description
GET / Health check
GET /docs Interactive Swagger UI
GET /summary Pipeline run summary
GET /risk-scores All entity risk scores
GET /privacy-alerts Privacy risk signals
GET /attack-chains Correlated attack chains
GET /recommendations Defense recommendations
GET /entity/{name} Full profile for an entity

🧠 ML Models

Technique Use Case
Isolation Forest Unsupervised anomaly detection on tabular log data
Rule-Based Correlation Attack chain linking from correlated alerts
Statistical Thresholds Privacy violation signal detection

πŸ“Š Risk Scoring Formula

Each entity is assigned a dynamic risk score from 0 to 100:

Risk Score = 0.35 Γ— Anomaly_Severity
           + 0.20 Γ— Alert_Frequency
           + 0.15 Γ— Privilege_Level
           + 0.20 Γ— Data_Sensitivity_Accessed
           + 0.10 Γ— Historical_Incident_Rate
Score Range Risk Level
80 – 100 πŸ”΄ CRITICAL
60 – 79 🟠 HIGH
35 – 59 🟑 MEDIUM
0 – 34 🟒 LOW

πŸ” Privacy Risk Rules

Rule Signal Severity
PRIV-001 Bulk data download > 200 MB HIGH
PRIV-002 Off-hours privileged access MEDIUM
PRIV-003 New device accessing sensitive data HIGH
PRIV-004 High API call rate + bulk data transfer CRITICAL
PRIV-005 Lateral movement + data access CRITICAL

⚠️ Defense Recommendations

Trigger Action
Score β‰₯ 80 Enforce MFA + alert SOC
Lateral movement detected Isolate endpoint immediately
Score β‰₯ 60 Force password reset
Bulk data exfiltration Block session + flag for review
Score β‰₯ 35 + high privilege Revoke elevated privileges

πŸ“‘ Sample Dataset

The platform ships with 40 real-world-simulated events across 22 entities:

Entity Type Count Examples
Users 17 john.doe, mike.chen, carlos.mendez
Services 5 svc_api_gateway, svc_ml_pipeline
High-risk actors 4 mike.chen (score 40), raj.patel, carlos.mendez
Clean users 10 alice.smith, priya.sharma, grace.lee

❗ Common Errors & Fixes

Error Fix
ModuleNotFoundError: No module named 'src' Run from project root folder
venv\Scripts\activate not working Run PowerShell as Administrator
uvicorn: command not found Run pip install uvicorn
Dashboard shows β€” dashes Run pipeline first, then start server
API status bar shows πŸ”΄ red Start uvicorn server in a separate terminal
sample_events.json empty error Re-download sample_events.json from repo

πŸ§ͺ Testing

pytest tests/ -v

All 10 tests should pass:

βœ… TestAnomalyDetector::test_returns_list
βœ… TestAnomalyDetector::test_empty_input
βœ… TestAnomalyDetector::test_anomaly_has_required_fields
βœ… TestRiskScorer::test_scores_computed
βœ… TestRiskScorer::test_score_range
βœ… TestRiskScorer::test_risk_levels_valid
βœ… TestPrivacyMonitor::test_bulk_download_flagged
βœ… TestPrivacyMonitor::test_clean_event_no_alerts
βœ… TestDefenseAdvisor::test_critical_score_triggers_mfa
βœ… TestDefenseAdvisor::test_low_score_no_critical_actions

πŸ“„ Abstract

With the increasing complexity of cyber threats, organizations require intelligent systems capable of detecting attacks, prioritizing risks, and protecting sensitive data in real time. This project proposes a Cyber Risk Intelligence and Adaptive Defense Platform (CRIDAP) that integrates behavioural analytics, risk scoring, and incident correlation into a unified cybersecurity solution.

The platform continuously monitors multi-layer system activity including network traffic, authentication events, and application usage patterns. Machine learning based anomaly detection techniques are employed to identify suspicious behaviour such as abnormal login patterns, unusual data transfers, and network reconnaissance activities. Unlike traditional alerting systems, the proposed solution correlates multiple security events to reconstruct potential attack chains, enabling better situational awareness for security teams.

A dynamic cyber risk scoring engine evaluates threat severity associated with users, devices, and services to support prioritized incident response. Additionally, a privacy risk monitoring module detects potential data exposure scenarios and unauthorized access to sensitive resources. Based on contextual threat intelligence, the platform provides adaptive defense recommendations such as enforcing MFA, isolating compromised endpoints, or prioritizing vulnerability patching.


πŸ‘¨β€πŸ’» Team

Name Role Links
Aishwary Vansh Full Stack Developer & System Architect LinkedIn Β· GitHub
Sujai Shukla Machine Learning Engineer & Threat Analytics Specialist LinkedIn Β· GitHub

πŸ† Built For

This project was developed as a hackathon submission targeting real-world cybersecurity challenges in enterprise environments.


🀝 Contributing

  1. Fork the repository
  2. Create your feature branch (git checkout -b feature/new-module)
  3. Commit your changes (git commit -m 'Add new detection module')
  4. Push to the branch (git push origin feature/new-module)
  5. Open a Pull Request

πŸ“œ License

This project is licensed under the MIT License β€” see LICENSE for details.


CRIDAP Β· Cyber Risk Intelligence & Adaptive Defense Platform
Built with ❀️ for Hackathon 2025

About

Unified ML-based Cyber Risk Intelligence & Adaptive Defense System

Resources

Contributing

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages