Student cybersecurity analytics project

SOC Analytics Copilot

A network intrusion dashboard that turns attack metrics into analyst-style explanations for people who do not live inside packet logs.

Dataset directionCSE-CIC-IDS2018 style network-flow sample

Portfolio demo uses processed sample metrics in-repo. The full academic dataset should be downloaded from the official source and cited in the README.

Flows analyzed

63,00042,680 benign

Malicious flows

20,32032.3% of sample

Top attack

DDoSDominant malicious category

Overall risk

CriticalRule-based severity score
Distribution

Attack types by flow count

DDoS12,480
DoS4,380
Brute Force1,740
Botnet920
Web Attack610
Infiltration190
Benign42,680
Explainable assistant

Analyst summary

Critical risk: DDoS activity is the main signal.

The dashboard analyzed 63,000 network flows and found 20,320 malicious flows. DDoS is the dominant attack type, representing 61% of malicious activity.

Malicious traffic makes up 32.3% of the sample. The latest period is up by 740% compared with the first period, which helps an analyst decide whether the situation is escalating or calming down.

Risk level: Critical

Prioritize DDoS triage, review top source IPs, and apply rate limiting or blocking rules where traffic is not expected.

Time series

Malicious trend

08:00
09:00
10:00
11:00
12:00
13:00
Alert queue

Suspicious events ranked by risk

SOC-1042

DDoS against 10.42.0.18

96% confidence
Source
172.31.69.25
Protocol
TCP
Flows
6,340
  • High packet rate
  • Repeated destination
  • Short flow duration
  • SYN-heavy traffic

Prioritize rate limiting and inspect the destination service for availability impact.