Skip to content
SIH Buddyby Ganeev Singh
Dev

๐Ÿ”ฅ Roast My Pick ยท SIH26106

AI-Powered Email Threat Detection, GeoLocation and Forensic Intelligence Platform

All India Council for Technical Education (AICTE)

Mild17/100

Good pick. Genuinely. Now sit down, because the judges are going to try anyway โ€” and this is what they will try.

Strong pick. Build the forensic tracing first and the classifier second, because the header chain is what makes this memorable โ€” and be explicit that you are surfacing infrastructure indicators rather than identifying a person. Roughly 75โ€“170 teams are expected to go here.

The receipts

Every red flag on this statement, in full. These are the four places it bites.

  1. Exhibit A

    IP geolocation of relay hops is genuinely unreliable โ€” attackers route through VPNs, compromised hosts and cloud providers, so a confident pin on a map often points at a data centre in Virginia rather than an actor

  2. It gets worse

    The description asks to help identify the actor behind the attack, and attribution is a claim with legal weight that no header analysis can actually support โ€” present infrastructure indicators, not identities

  3. Still reading?

    Received headers below the first trusted hop are attacker-controlled and can be forged outright, so a naive chain reconstruction can be led anywhere the sender wants

  4. And the finisher

    Phishing detection is a saturated project category, so a submission whose forensic layer is thin will be indistinguishable from a dozen classifiers

The damage report

Every score this statement earned, and what each one actually costs you.

  • Feasibility

    4/5

    Actually buildable, which on this slate is rarer than it sounds. Do not squander it on scope.

    Every input this needs is accessible โ€” email headers are plain text, SPF, DKIM and DMARC validation has mature libraries, IP-to-ASN and geolocation databases are free at the tier you need, and public phishing corpora like PhishTank and the Nazario collection give you labelled training data.

  • Innovation scope

    3/5

    Mildly interesting. The novelty will not carry the room; the build has to.

    Phishing classification itself is a crowded, well-solved task, so your creative room is almost entirely in the forensic correlation layer โ€” how you chain the relay path, weigh conflicting geolocation evidence and present attribution confidence.

  • Clarity

    4/5

    The ask is unambiguous, which quietly removes your favourite excuse.

    The description enumerates exactly what must be correlated โ€” headers, SMTP relay paths, SPF/DKIM/DMARC results, IP reputation, geolocation, domain registration intelligence and behavioural patterns โ€” leaving little doubt about the required components.

  • Acceptance potential

    4/5

    Strong footing before you have written a line. Try not to waste it.

    The forensic tracing genuinely differentiates this from the many phishing-detector submissions a cybersecurity judge will see, the data is all accessible, and it is one of the more substantial AICTE statements rather than the near-empty ones โ€” but you must resist letting it collapse into another classifier.

  • Effort

    Heavy

    Heavy. Somebody on this team is not sleeping in week three. Pick who, on purpose.

    The classifier, the header forensics chain, the enrichment integrations and the report generation are four connected pieces, though each rests on existing libraries and public data sources.

  • Demo-ability

    Easy

    Easy to demo โ€” and so is everyone else's. Working is the floor here, not the achievement.

    Feeding in a genuine phishing email and watching the relay path unfold across a map is immediately legible, and you can source real samples for the demo without any permission.

  • Data

    None supplied

    No dataset comes with this one, so every accuracy figure you quote is a number about labels you invented.

    Nothing is provided with the statement. You are sourcing, cleaning and labelling it yourself, and that work is invisible in the demo but very visible in the questions.

The demo they will have already seen

Somewhere around 75โ€“170 teams are heading here, and the description is doing the choosing for most of them. They will read the same brief, reach the same architecture, and build a version of the same demo you are planning. Being correct is the floor. If your five minutes could be swapped with the team before you and nobody in the room would notice, you have not picked badly โ€” you have built predictably, which costs exactly the same and hurts more.

What survives

The ground worth standing on when the questions start.

  • Email headers are structured plain text, so the forensic half needs no model at all and works deterministically from the first hour
  • Public phishing corpora plus your own spam folder give you real labelled samples with zero data-sourcing risk
  • The relay-path map is a strong visual that almost no competing phishing project will have, since most stop at a classification score

Nothing here is fatal. It is just the list of places this statement pushes back, and you now get to push there first.

The framing is a joke. The findings are not โ€” they are the same analysis on the statement page, and every line above is attached to a score or a fact in the record. It is one opinion with its reasoning attached, so argue with it before you trust it.