๐ฅ Roast My Pick ยท SIH26106
AI-Powered Email Threat Detection, GeoLocation and Forensic Intelligence Platform
All India Council for Technical Education (AICTE)
Good pick. Genuinely. Now sit down, because the judges are going to try anyway โ and this is what they will try.
Strong pick. Build the forensic tracing first and the classifier second, because the header chain is what makes this memorable โ and be explicit that you are surfacing infrastructure indicators rather than identifying a person. Roughly 75โ170 teams are expected to go here.
The receipts
Every red flag on this statement, in full. These are the four places it bites.
Exhibit A
IP geolocation of relay hops is genuinely unreliable โ attackers route through VPNs, compromised hosts and cloud providers, so a confident pin on a map often points at a data centre in Virginia rather than an actor
It gets worse
The description asks to help identify the actor behind the attack, and attribution is a claim with legal weight that no header analysis can actually support โ present infrastructure indicators, not identities
Still reading?
Received headers below the first trusted hop are attacker-controlled and can be forged outright, so a naive chain reconstruction can be led anywhere the sender wants
And the finisher
Phishing detection is a saturated project category, so a submission whose forensic layer is thin will be indistinguishable from a dozen classifiers
The damage report
Every score this statement earned, and what each one actually costs you.
Feasibility
4/5Actually buildable, which on this slate is rarer than it sounds. Do not squander it on scope.
Every input this needs is accessible โ email headers are plain text, SPF, DKIM and DMARC validation has mature libraries, IP-to-ASN and geolocation databases are free at the tier you need, and public phishing corpora like PhishTank and the Nazario collection give you labelled training data.
Innovation scope
3/5Mildly interesting. The novelty will not carry the room; the build has to.
Phishing classification itself is a crowded, well-solved task, so your creative room is almost entirely in the forensic correlation layer โ how you chain the relay path, weigh conflicting geolocation evidence and present attribution confidence.
Clarity
4/5The ask is unambiguous, which quietly removes your favourite excuse.
The description enumerates exactly what must be correlated โ headers, SMTP relay paths, SPF/DKIM/DMARC results, IP reputation, geolocation, domain registration intelligence and behavioural patterns โ leaving little doubt about the required components.
Acceptance potential
4/5Strong footing before you have written a line. Try not to waste it.
The forensic tracing genuinely differentiates this from the many phishing-detector submissions a cybersecurity judge will see, the data is all accessible, and it is one of the more substantial AICTE statements rather than the near-empty ones โ but you must resist letting it collapse into another classifier.
Effort
HeavyHeavy. Somebody on this team is not sleeping in week three. Pick who, on purpose.
The classifier, the header forensics chain, the enrichment integrations and the report generation are four connected pieces, though each rests on existing libraries and public data sources.
Demo-ability
EasyEasy to demo โ and so is everyone else's. Working is the floor here, not the achievement.
Feeding in a genuine phishing email and watching the relay path unfold across a map is immediately legible, and you can source real samples for the demo without any permission.
Data
None suppliedNo dataset comes with this one, so every accuracy figure you quote is a number about labels you invented.
Nothing is provided with the statement. You are sourcing, cleaning and labelling it yourself, and that work is invisible in the demo but very visible in the questions.
The demo they will have already seen
Somewhere around 75โ170 teams are heading here, and the description is doing the choosing for most of them. They will read the same brief, reach the same architecture, and build a version of the same demo you are planning. Being correct is the floor. If your five minutes could be swapped with the team before you and nobody in the room would notice, you have not picked badly โ you have built predictably, which costs exactly the same and hurts more.
What survives
The ground worth standing on when the questions start.
- Email headers are structured plain text, so the forensic half needs no model at all and works deterministically from the first hour
- Public phishing corpora plus your own spam folder give you real labelled samples with zero data-sourcing risk
- The relay-path map is a strong visual that almost no competing phishing project will have, since most stop at a classification score
Nothing here is fatal. It is just the list of places this statement pushes back, and you now get to push there first.
The framing is a joke. The findings are not โ they are the same analysis on the statement page, and every line above is attached to a score or a fact in the record. It is one opinion with its reasoning attached, so argue with it before you trust it.