A comprehensive Network Security Operations Center (SOC) dashboard that combines real-time attack detection, visualizations, ChatOps, and automated email escalation.
- 🛡️ Real-time Attack Detection: Uses trained GHF-ART model to detect network attacks
- 📊 Interactive Visualizations: Charts and graphs for attack analysis
- 💬 ChatOps Integration: AI-powered chatbot for security analysis
- 📧 Email Escalation: Automated email alerts to network administrators
- 🔴 Live Alert Feed: Real-time monitoring and alerting system
- Python 3.8+
- Trained GHF-ART model (
ghf_art_model.pkl) - Network logs data (
network_logs_processed.csv)
-
Install dependencies:
pip install -r requirements.txt
-
Train the model (if not already done):
python train_model.py
-
Configure environment variables:
- Copy
env_template.txtto.env - Fill in your email credentials and API keys
cp env_template.txt .env
Edit
.envwith your credentials:SMTP_SERVER=smtp.gmail.com SMTP_PORT=587 SENDER_EMAIL=your_email@gmail.com SENDER_PASSWORD=your_app_password ADMIN_EMAIL=admin@example.com EMAIL_ENABLED=true ANTHROPIC_API_KEY=your_key_here - Copy
streamlit run network_security_dashboard.pyThe dashboard will open in your browser at http://localhost:8501
- 📊 Dashboard: Visual analytics and statistics
- 🔴 Live Alerts: Real-time attack detection and alerts
- 💬 ChatOps: AI assistant for security queries
- ⚙️ Settings: System configuration and status
- Enable monitoring from the sidebar
- Click "Analyze New Traffic Sample" to test detection
- Critical/high severity attacks trigger email alerts (if enabled)
The ChatOps assistant provides intelligent security analysis using rule-based AI (no external API required). It analyzes network logs and provides insights about security threats.
Supported Queries:
General Analysis:
- "Give me a security status summary"
- "What's the overall threat level?"
- "Show me the security overview"
Threat Investigation:
- "Show critical alerts"
- "Show me critical alerts"
- "What attack patterns were detected?"
- "Analyze recent suspicious activity"
- "Show high severity threats"
Time-Based Queries:
- "What happened in the last 2 hours?"
- "Show me today's security events"
- "Recent activity in the last 6 hours"
- "Activity in the last 24 hours"
Specific Analysis:
- "Which services are most targeted?"
- "Analyze protocol distribution"
- "Show attack patterns"
- "What protocols are being attacked?"
Quick Actions: The ChatOps tab includes quick action buttons for common queries:
- Security Summary: Get overall security status
- Critical Alerts: View high-severity threats
- Attack Patterns: Analyze detected attack vectors
- Clear Chat: Reset conversation history
Note: The ChatOps assistant automatically cleans HTML content from responses to ensure proper display. All responses are formatted as markdown for better readability.
CN_Proj/
├── network_security_dashboard.py # Main unified dashboard
├── train_model.py # Model training script
├── requirements.txt # Python dependencies
├── env_template.txt # Environment variables template
├── README.md # Project documentation
├── start_dashboard.bat # Windows launcher script
├── start_dashboard.sh # Linux/Mac launcher script
├── ghf_art_model.pkl # Trained model (generated)
├── network_logs_processed.csv # Processed network data (generated)
├── attack_alerts.json # Alert log (generated)
└── kddcup.data_10_percent_corrected # Training dataset
- Enable 2-Factor Authentication
- Generate an App Password:
- Go to Google Account → Security → 2-Step Verification
- Generate App Password for "Mail"
- Use the app password in
.envasSENDER_PASSWORD
Update SMTP_SERVER and SMTP_PORT in .env:
- Outlook:
smtp-mail.outlook.com:587 - Yahoo:
smtp.mail.yahoo.com:587 - Custom: Check your email provider's SMTP settings
The GHF-ART model is trained on the KDD Cup 1999 dataset:
python train_model.pyThis generates:
ghf_art_model.pkl: Trained modelnetwork_logs_processed.csv: Processed network data with predictions
- Run
python train_model.pyfirst - Ensure
ghf_art_model.pklexists in the project directory
- Check
.envfile exists and has correct credentials - Verify
EMAIL_ENABLED=true - Check SMTP server settings
- For Gmail, ensure App Password is used (not regular password)
- Ensure
network_logs_processed.csvexists - Run
train_model.pyto generate the data file - The ChatOps assistant uses rule-based AI (no API key required)
- If you see HTML tags in responses, refresh the page - responses are automatically cleaned
- The dashboard automatically removes HTML tags from ChatOps responses
- All responses are displayed as clean markdown text
- If HTML appears, it's automatically stripped before display
- Ensure all dependencies are installed:
pip install -r requirements.txt - Check that Streamlit is installed:
pip install streamlit - Verify Python version:
python --version(should be 3.8+)
- New Visualizations: Add to Dashboard tab in
network_security_dashboard.py - New Alert Types: Modify
detect_attack()function - ChatOps Commands: Extend
claude_chatbot.py
Test individual components:
# Test model training
python train_model.py
# Test dashboard (includes all features: monitoring, ChatOps, visualizations)
streamlit run network_security_dashboard.py
This project is for educational and research purposes.
For issues or questions, please check:
- All dependencies are installed
- Model is trained (
ghf_art_model.pklexists) - Data file exists (
network_logs_processed.csv) .envfile is configured correctly