Skip to content

Repository files navigation

IoT Shield - Cybersecurity Threat Detection System

Python Flask TensorFlow

IoT Shield is an AI-powered cybersecurity platform designed to analyze and detect threats in real-time. It analyzes URLs and file payloads using trained Machine Learning models (TensorFlow/Keras) alongside carefully tuned heuristic overrides to prevent false-positive biases, providing accurate classifications for Phishing, Malware, and Benign entities.

🚀 Features

  • URL Threat Detection: Scans URLs and uses an AI model to classify them as Benign, Phishing, or Malicious. Incorporates heuristic overlays to enforce deterministic rules on well-known safe domains and clear phishing indicators.
  • Malware File Analysis: Inspects file contents, extracts features (entropy, size, suspicious keywords, hash signatures), and uses a secondary AI model to classify payloads as Malicious or Benign.
  • Heuristic Bias Suppression: A dual-layered approach where deterministic heuristic logic safeguards ML model predictions, actively reducing false positives on safe files/domains and false negatives on obvious threats.
  • RESTful API: Allows external integrations to submit URLs or file payloads for immediate risk predictions.
  • User Authentication: Secure user registration and login system backed by SQLite.

🛠️ Tech Stack

  • Backend: Python, Flask, Flask-SQLAlchemy, Flask-CORS
  • Machine Learning: TensorFlow / Keras, NumPy, Scikit-learn (Joblib), h5py
  • Database: SQLite (Local storage)

📦 Installation & Setup

  1. Clone the repository (after pushing to your GitHub)
git clone https://github.com/YourUsername/CyberSecurityProject.git
cd CyberSecurityProject
  1. Set up a Virtual Environment (Recommended)
python -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate
  1. Install Dependencies
pip install flask flask-cors flask-sqlalchemy tensorflow numpy joblib h5py
  1. Run the Server
python app.py

The server will start on http://localhost:5001.

🔗 Key API Endpoints

  • POST /register: Register a new user account.
  • POST /login: Authenticate an existing user.
  • POST /predict_url: Submit a list of URLs for threat classification.
  • POST /predict_file: Upload a file or submit its SHA256 hash for malware analysis.

🧠 ML Models Integration

The project relies on pre-trained serialized .h5 and .keras models along with their respective tokenizers and feature scalers. If a model fails to load, the system intelligently drops down to a fully functioning Rule-Based Fallback Engine to ensure uninterrupted threat detection.

About

IoT Shield is an AI-powered cybersecurity platform that uses Machine Learning (TensorFlow/Keras) and heuristic algorithms to scan, detect, and classify malicious URLs and malware file payloads in real-time.

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages