Network security monitoring · College capstone
AutoDefender
AutoDefender started as my capstone project in my senior year of college (fall 2025), and I still maintain it. It monitors Suricata network logs in real time or analyzes historical log files, maps each threat to MITRE ATT&CK, explains it in plain English with a local AI model through Ollama, and recommends responses, including firewall rules that only run after a person approves them.
- Python
- Streamlit
- Suricata
- Ollama
- SQLite
- MITRE ATT&CK
Screenshots
Screenshots use AutoDefender's built-in demo data, which is synthetic: documentation and private IP ranges, documentation AS numbers and fictional organizations. Click a screenshot to open it full size. Use the arrows, or select the gallery and press ← →.
How it works
- Read the logs: tail one or more Suricata
eve.jsonfiles in real time, handling log rotation and partial lines, or batch-analyze historical logs. - Detect and enrich: rate each event's severity, detect port scans and suspicious patterns, tag threats with MITRE ATT&CK techniques, and optionally add location data from offline MaxMind GeoLite2 databases.
- Explain: HIGH and CRITICAL threats go to a local Ollama model for a plain-English explanation, on a small worker pool with a per-minute call budget.
- Respond: playbooks bundle a drop rule, a log entry and a webhook notification into one approval. Rules are backed up before every change and can be unblocked or set to expire.
- Review: in the Streamlit web console (dashboard, incidents, threat analysis, actions, IP lists, playbooks, audit log) or the terminal UI.
Security decisions
- Humans approve firewall changes. Rules are written only after approval unless auto-approval is explicitly turned on, and dry-run mode logs proposed rules without writing them.
- Safe rule writing. Only single-IP drop rules are written. AI-suggested rules must target the threat's own source IP, rules for
any, loopback or whitelisted IPs are refused, and AutoDefender assigns the rule IDs itself. - Log data is untrusted. Log fields and AI output are escaped before display, fenced off in AI prompts, and neutralized in CSV exports so they can't become spreadsheet formulas.
- Everything stays local. Analysis, AI explanations and GeoIP lookups run on your machine. Nothing leaves unless you configure a webhook, and webhooks must use https to a public host.
- Hardened sign-in. An optional password is compared in constant time. More than 5 failures in 5 minutes locks that client, even across restarts, and idle sessions sign out after 30 minutes.
- Tamper-evident audit log. Kept in its own database, so clearing threats never clears it.