← ALL OPENINGSE4 · THE SICILIAN
PROJECT 01
Eigenguard
Hybrid Intrusion Detection System
0.40
FIG. EIGENGUARDLIVE TRACE
01
THE PROBLEM
Signature-based detection stops what has already been seen. Anything novel walks past the rule set — and a random train/test split hides that fact behind an optimistic score.
02
THE APPROACH
Combine signature-based rules with scikit-learn anomaly detection, then evaluate honestly: leave-one-tool-out instead of a random split.
03
THE ARCHITECTURE
- 01Traffic↓
- 02Feature extraction↓
- 03Signature detection + ML anomaly detection↓
- 04Alert↓
- 05React dashboard
04
THE IMPLEMENTATION
- 01Designed a hybrid IDS combining signature-based rules with machine-learning anomaly detection.
- 02Benchmarked classifiers on CICIDS2017 traffic, with an ML detection pipeline and a React dashboard.
- 03Added an SSH honeypot that captures attacker credentials alongside the detection pipeline.
05
THE RESULTS
- Leave-one-tool-out recall of 0.40 against 0.999 F1 on a random split.
- The gap proved the model had learned path-probing, not injection payloads.
06
WHAT I LEARNED
“Evaluation design is half the security. The split you choose is part of the threat model.”
07
TECH STACK
Python
Scikit-learn
CICIDS2017
React
Machine Learning