AI-Based Detection of Cyber Threats in Unidirectional IP Traffic across Hardware Optical Data Diodes
In critical national infrastructureβincluding nuclear power facilities, electrical power grid SCADA enclaves, aerospace ground stations, and high-security defense networksβperimeter isolation is physically enforced using hardware optical data diodes.
A hardware data diode couples a transmitting laser/LED to a receiving photodiode across an optical fiber barrier, allowing light pulses to travel in strictly one direction. This guarantees mathematically that no attacker can pivot back into the protected enclave.
While hardware diodes provide absolute physical perimeter protection, they create a devastating failure mode for conventional Network Intrusion Detection Systems (NIDS) such as Snort, Suricata, and standard stateful firewalls:
- No Bidirectional Handshakes: Reverse packets (TCP SYN-ACK, HTTP server responses, DNS resolution answers) never cross the diode.
- Missing Timing & Metric Ratios: Round-Trip Time (RTT), inbound-to-outbound byte ratios, and handshake completion latencies are physically non-existent.
- Failure of Traditional NIDS: Conventional engines either crash, timeout waiting for return flows, or fabricate false zeros that trigger catastrophic false alarm fatigue.
Sentinel OneWay is a high-throughput, streaming cyber-defense platform designed from first principles for passive, unidirectional network telemetry. It infers threat behavior strictly from observable forward traffic without fabricating missing return data or decrypting encrypted payloads.
flowchart LR
A["Monitored Production Network"] -->|"Optical Fiber Splitter"| B["Hardware Optical Data Diode"]
B -->|"Unidirectional Forward Only"| C["Ingestion & Normalization Engine"]
C --> D["Sliding & Tumbling Window Manager"]
D --> E["Feature Extraction & 4-State Mask"]
E --> F["Multi-Model ML Ensemble"]
F --> G["Quality-Weighted Bayesian Risk Fusion"]
G --> H[("PostgreSQL 17 Persistence")]
G --> I["FastAPI SSE Stream Engine"]
I --> J["React 18 Cyber Operations Console"]
- Production Observation: Mirrored traffic from an optical tap duplicated without electrical return coupling.
- Hardware Data Diode: Enforces physical one-way air-gap protection; nothing ever crosses backward.
- Ingestion & Normalization: Fast parser transforming frames into canonical directional 5-tuple records.
- Sliding & Tumbling Windows: Aggregates flows across 1s micro-burst, 5s session, and 60s host windows.
- Feature Engine & Availability Mask: Computes directional entropy, velocity, and timing while tagging absent fields.
- Multi-Model ML Ensemble: Parallel evaluation via deterministic rules, supervised XGBoost, and Isolation Forest.
- Bayesian Risk Fusion: Fuses threat scores weighted by evidence completeness to prevent false positives.
- Persistence & Operations Console: Stores forensic JSONB records in PostgreSQL 17 and broadcasts real-time SSE updates to the React UI.
Instead of fabricating zeros for missing return metrics, Sentinel OneWay assigns every feature an explicit provenance mask:
AVAILABLE: Directly observed in the forward telemetry stream.DERIVED: Mathematically computed from forward-direction aggregations.OPTIONAL: Present only in specific transport handshakes.UNAVAILABLE: Physically absent due to the diode boundary (e.g. SYN-ACK latency, RTT). Classifiers explicitly accommodate this mask rather than guessing.
The engine operates in 100% passive eavesdropping mode. It issues zero ICMP/SNMP probes, injects zero TCP RST resets, and executes zero active mitigation commands back through the ingest boundary. The monitored production network remains mathematically unalterable.
With modern enterprise traffic heavily encrypted via TLS 1.3 and QUIC (HTTP/3), payload decryption is neither feasible nor desirable. Sentinel OneWay inspects unencrypted transport handshakes (TLS ClientHello cipher suites, extensions, ALPN, elliptic curves, JA4 fingerprints) and models statistical Sequence of Packet Lengths and Inter-Arrival Times (SPLT).
- Deterministic Rules: Instant sub-millisecond filtering for volumetric floods.
- Supervised Classifiers: Calibrated Random Forest & XGBoost with Platt Scaling probability calibration.
- Unsupervised Anomaly Detection: Isolation Forest for detecting novel zero-day C2 channels and stealth exfiltration.
- Evidence-Weighted Fusion: Risk scores are automatically moderated if feature availability is degraded, eliminating alert fatigue.
Backed by PostgreSQL 17 with asynchronous connection pools (SQLAlchemy 2.0 + asyncpg) and native JSONB storage preserving forensic provenance. The platform includes a zero-dependency in-memory fallback mode that honestly reports durable=False if the database becomes unreachable.
Built with React 18, Vite, and Tailwind CSS design tokens, featuring:
- Midnight Tactical Dark Mode for 24/7 dark SOC rooms.
- Executive Slate Light Mode with crisp contrast for high-glare projectors.
- 3D Isometric Pipeline Walkthrough with animated telemetry flow arrows.
- Deterministic Replay Console with SHA-256 fixture verification.
| Threat Class | Directional Mathematical Features | Unidirectional Detection Methodology |
|---|---|---|
| 1. Volumetric SYN Flood | SYN packet rate ( |
Detects high-rate SYN bursts across distributed pseudo-random sources targeting specific services without requiring SYN-ACK responses. |
| 2. UDP Reflection / Amplification | Directional byte volume ( |
Flags asymmetric burst volumes originating from known reflection ports over bounded sliding windows. |
| 3. Spoofed-Source Flooding | Source IP cardinality per destination, subnet dispersion index, IP header TTL variance, Bogon filtering. | Evaluates extreme source cardinality against narrow destination targets; random spoofed addresses exhibit maximal entropy |
| 4. Reconnaissance & Port Sweeps | Horizontal fan-out (distinct destination IPs per source), vertical fan-out (distinct ports per IP), probe timing regularity. | Graph degree expansion tracking in sliding windows; distinguishes rapid aggressive port scans from stealth low-and-slow sweeps. |
| 5. Domain Generation Algorithms (DGA) | DNS query name Shannon entropy, vowel-to-consonant ratios, consonant cluster n-gram probabilities, TLD rarity. | Evaluates query string randomness; algorithmic names (e.g. xrkjqw94bfa.top) exhibit high entropy ( |
| 6. DNS Data Tunnelling | TXT/NULL record query frequency, subdomain length distribution, base32/base64 character frequency, unique query ratio. | Identifies covert exfiltration channels over UDP port 53 by tracking payload lengths ( |
| 7. C2 Botnet Beaconing | Inter-arrival time (IAT) autocorrelation, Fourier transform (FFT) frequency peaks, low coefficient of variation ( |
Isolates automated heartbeat periodicity (Cobalt Strike, Sliver) from human browsing jitter ( |
| 8. Encrypted Data Exfiltration | Cumulative directional byte volume over rolling historical baselines, off-hours volumetric spikes, destination rarity index. | Identifies asymmetric outbound data transfers by comparing volume against 24-hour host baseline profiles. |
| Layer | Technology | Details |
|---|---|---|
| Backend Core | Python 3.12+, FastAPI, Uvicorn | Asynchronous ASGI REST API & Server-Sent Events (SSE) streaming |
| Data & ML Engine | Scikit-Learn, XGBoost, NumPy, Pandas, SciPy | Sliding window aggregations, FFT frequency analysis, calibrated classifiers |
| Database & ORM | PostgreSQL 17, SQLAlchemy 2.0 (Async), Asyncpg, Alembic | ACID persistence, JSONB evidence storage, non-blocking connection pools |
| Frontend UI | React 18, Vite 7, TypeScript, Tailwind CSS, Phosphor Icons | Dual-theme cyber console, 3D isometric pipeline, WCAG AA accessibility |
| Testing & Quality | Pytest, pytest-asyncio, Vitest, Testing Library, ESLint | 142 backend tests (100% passing), 19 frontend tests (100% passing), strict typing |
- Python 3.12+
- Node.js 20+ and pnpm
- PostgreSQL 17 (Optional: the backend automatically runs in in-memory mode if PostgreSQL is not configured)
git clone https://github.com/asadullah098/sentinel-oneway.git
cd sentinel-oneway# Create and activate virtual environment
python -m venv .venv
.\.venv\Scripts\Activate.ps1 # Windows
# source .venv/bin/activate # Linux/macOS
# Install dependencies
pip install -e .
# (Optional) Run Database Migrations if PostgreSQL is available
alembic upgrade head
# Start FastAPI Server on port 8000
python -m uvicorn sih_oneway.api.app:app --host 127.0.0.1 --port 8000Verify backend readiness at: http://127.0.0.1:8000/api/v1/health/ready
cd frontend
pnpm install
pnpm dev --host 127.0.0.1 --port 5173Open http://localhost:5173/ in your browser.
The codebase enforces strict test-driven development and quality gates:
# Run 142 Backend Pytests (including live PostgreSQL integration tests)
pytest -q
# Run 19 Frontend Vitest Integration Tests
pnpm --dir frontend test
# Run TypeScript Typecheck & ESLint
pnpm --dir frontend typecheck
pnpm --dir frontend lint
# Run Production Build
pnpm --dir frontend buildQuality Status:
- Backend:
142 passed, 13 subtests passed (100% pass rate) - Frontend:
19 passed (100% pass rate) - Static Analysis:
0 TypeScript errors, 0 ESLint warnings
.
βββ src/sih_oneway/ # Core Python package
β βββ alerts/ # Deduplication, generation, and alert models
β βββ api/ # FastAPI routes, contracts, and SSE publisher
β βββ benchmarking/ # Execution and latency benchmarks
β βββ capture/ # PCAP transformation & directionality policy
β βββ detectors/ # High-speed deterministic rule engines
β βββ features/ # Sliding window engine & availability mask
β βββ models/ # Supervised XGBoost & Isolation Forest models
β βββ persistence/ # PostgreSQL 17 async repositories & models
β βββ replay/ # Synthetic attack scenario bundles & checksums
β βββ risk/ # Quality-weighted Bayesian risk fusion
β βββ streaming/ # Bounded asyncio queues & event-time windows
βββ frontend/ # React 18 + Vite cyber operations console
β βββ src/components/ # AppShell, theme toggle, tables, risk meters
β βββ src/pages/ # Overview, Replay, Alerts, Architecture, System
β βββ src/styles.css # Token-based CSS architecture (Dark/Light)
βββ docs/ # Architectural specifications & runbooks
β βββ presentation/ # Official SIH Presentation DOCX & 5-Min Video Script PDF
βββ migrations/ # Alembic PostgreSQL database migrations
βββ tests/ # 142 automated unit, integration, and security tests
βββ pyproject.toml # Build metadata & dependency definitions
For evaluators and jury members reviewing this project:
- Pitch Deck & Master Project Report: Available in
docs/presentation/Sentinel_OneWay_SIH26145_Complete_Project_Report_and_PPT_Guide.docx - 5-Minute Video Demonstration Script & Storyboard: Available in
docs/presentation/Sentinel_OneWay_SIH26145_5Min_Demo_Video_Script.pdf
This project is licensed under the MIT License - see the LICENSE file for details.