IoT Shield is an AI-powered cybersecurity platform designed to analyze and detect threats in real-time. It analyzes URLs and file payloads using trained Machine Learning models (TensorFlow/Keras) alongside carefully tuned heuristic overrides to prevent false-positive biases, providing accurate classifications for Phishing, Malware, and Benign entities.
- URL Threat Detection: Scans URLs and uses an AI model to classify them as
Benign,Phishing, orMalicious. Incorporates heuristic overlays to enforce deterministic rules on well-known safe domains and clear phishing indicators. - Malware File Analysis: Inspects file contents, extracts features (entropy, size, suspicious keywords, hash signatures), and uses a secondary AI model to classify payloads as
MaliciousorBenign. - Heuristic Bias Suppression: A dual-layered approach where deterministic heuristic logic safeguards ML model predictions, actively reducing false positives on safe files/domains and false negatives on obvious threats.
- RESTful API: Allows external integrations to submit URLs or file payloads for immediate risk predictions.
- User Authentication: Secure user registration and login system backed by SQLite.
- Backend: Python, Flask, Flask-SQLAlchemy, Flask-CORS
- Machine Learning: TensorFlow / Keras, NumPy, Scikit-learn (Joblib), h5py
- Database: SQLite (Local storage)
- Clone the repository (after pushing to your GitHub)
git clone https://github.com/YourUsername/CyberSecurityProject.git
cd CyberSecurityProject- Set up a Virtual Environment (Recommended)
python -m venv venv
source venv/bin/activate # On Windows: venv\Scripts\activate- Install Dependencies
pip install flask flask-cors flask-sqlalchemy tensorflow numpy joblib h5py- Run the Server
python app.pyThe server will start on http://localhost:5001.
POST /register: Register a new user account.POST /login: Authenticate an existing user.POST /predict_url: Submit a list of URLs for threat classification.POST /predict_file: Upload a file or submit its SHA256 hash for malware analysis.
The project relies on pre-trained serialized .h5 and .keras models along with their respective tokenizers and feature scalers. If a model fails to load, the system intelligently drops down to a fully functioning Rule-Based Fallback Engine to ensure uninterrupted threat detection.