Flows analyzed
63,00042,680 benignStudent cybersecurity analytics project
SOC Analytics Copilot
A network intrusion dashboard that turns attack metrics into analyst-style explanations for people who do not live inside packet logs.
Portfolio demo uses processed sample metrics in-repo. The full academic dataset should be downloaded from the official source and cited in the README.
Malicious flows
20,32032.3% of sampleTop attack
DDoSDominant malicious categoryOverall risk
CriticalRule-based severity scoreAttack types by flow count
Analyst summary
The dashboard analyzed 63,000 network flows and found 20,320 malicious flows. DDoS is the dominant attack type, representing 61% of malicious activity.
Malicious traffic makes up 32.3% of the sample. The latest period is up by 740% compared with the first period, which helps an analyst decide whether the situation is escalating or calming down.
Prioritize DDoS triage, review top source IPs, and apply rate limiting or blocking rules where traffic is not expected.
Malicious trend
Suspicious events ranked by risk
DDoS against 10.42.0.18
- Source
- 172.31.69.25
- Protocol
- TCP
- Flows
- 6,340
- High packet rate
- Repeated destination
- Short flow duration
- SYN-heavy traffic
Prioritize rate limiting and inspect the destination service for availability impact.
