SKIP TO CONTENT
← ALL OPENINGSE4 · THE SICILIAN
PROJECT 01

Eigenguard

Hybrid Intrusion Detection System

0.40
leave-one-tool-out recall vs 0.999 random-split F1
PythonScikit-learnCICIDS2017ReactSSH Honeypot
FIG. EIGENGUARDLIVE TRACE
01

THE PROBLEM

Signature-based detection stops what has already been seen. Anything novel walks past the rule set — and a random train/test split hides that fact behind an optimistic score.

02

THE APPROACH

Combine signature-based rules with scikit-learn anomaly detection, then evaluate honestly: leave-one-tool-out instead of a random split.

03

THE ARCHITECTURE

  1. 01
    Traffic
    ↓
  2. 02
    Feature extraction
    ↓
  3. 03
    Signature detection + ML anomaly detection
    ↓
  4. 04
    Alert
    ↓
  5. 05
    React dashboard
04

THE IMPLEMENTATION

  1. 01Designed a hybrid IDS combining signature-based rules with machine-learning anomaly detection.
  2. 02Benchmarked classifiers on CICIDS2017 traffic, with an ML detection pipeline and a React dashboard.
  3. 03Added an SSH honeypot that captures attacker credentials alongside the detection pipeline.
05

THE RESULTS

  • Leave-one-tool-out recall of 0.40 against 0.999 F1 on a random split.
  • The gap proved the model had learned path-probing, not injection payloads.
06

WHAT I LEARNED

“Evaluation design is half the security. The split you choose is part of the threat model.”

07

TECH STACK

Python
Scikit-learn
CICIDS2017
React
Machine Learning