Skip to content
SIH Buddyby Ganeev Singh
Dev

๐Ÿ”ฅ Roast My Pick ยท SIH26145

AI-Based Detection of Cyber Threats in Unidirectional IP Traffic

National Technical Research Organisation (NTRO)

Mild12/100

Good pick. Genuinely. Now sit down, because the judges are going to try anyway โ€” and this is what they will try.

Strong pick. One of the best-specified security problems in the set โ€” the traffic-generation tools are named so you own your data, and the passive constraint is a clean framing NTRO will respect, so build the per-class detectors well and take false positives seriously. Roughly 70โ€“160 teams are expected to go here.

The receipts

Every red flag on this statement, in full. These are the four places it bites.

  1. Exhibit A

    Flow-based detectors trained on lab traffic often fail on real traffic because lab attacks are cleaner and more separable than real ones, so your accuracy will look better than it would deploy

  2. It gets worse

    C2 beaconing detection by periodicity produces false positives on legitimate periodic traffic like software update checks, and handling that is the real challenge

  3. Still reading?

    The passive constraint means you can never confirm a detection, so precision and evidence quality matter more than recall and a naive high-recall detector floods the analyst

  4. And the finisher

    Encrypted DNS increasingly hides the query names your DGA and tunnelling detection depends on, a limitation worth acknowledging

The damage report

Every score this statement earned, and what each one actually costs you.

  • Feasibility

    4/5

    Actually buildable, which on this slate is rarer than it sounds. Do not squander it on scope.

    The description names the exact tools to generate training traffic โ€” iperf3, hping3, Slowloris โ€” and public datasets like CIC-IDS exist, the detection methods for each threat class are well-documented, and the passive-only constraint actually simplifies the problem by ruling out active response.

  • Innovation scope

    3/5

    Mildly interesting. The novelty will not carry the room; the build has to.

    The threat classes and the statistical signals for each are named in the description, so your room is in the detection models and in fusing the per-class detectors into a coherent scored alert stream rather than in choosing what to detect.

  • Clarity

    5/5

    The ask is unambiguous, which quietly removes your favourite excuse.

    The description explains the data-diode constraint precisely, enumerates the exact threat classes with the observable signal for each, names the traffic-generation tools, and specifies the output as scored alerts with evidence โ€” an exceptionally complete specification.

  • Acceptance potential

    4/5

    Strong footing before you have written a line. Try not to waste it.

    A strong pick โ€” the specification is complete, the traffic-generation tools are named so you can build your own labelled data, the passive constraint is a genuinely interesting framing rather than a limitation, and NTRO judges will value a detector that respects the one-directional reality most IDS work ignores.

  • Effort

    Heavy

    Heavy. Somebody on this team is not sleeping in week three. Pick who, on purpose.

    Generating a realistic labelled traffic corpus, building the per-class detectors and fusing them into a scored dashboard is focused, well-bounded work with clear sub-tasks.

  • Demo-ability

    Easy

    Easy to demo โ€” and so is everyone else's. Working is the floor here, not the achievement.

    Replaying a capture and watching distinct attacks light up with the specific statistic that flagged each is a clean, self-explanatory demo that a security judge reads instantly.

The demo they will have already seen

Somewhere around 70โ€“160 teams are heading here, and the description is doing the choosing for most of them. They will read the same brief, reach the same architecture, and build a version of the same demo you are planning. Being correct is the floor. If your five minutes could be swapped with the team before you and nobody in the room would notice, you have not picked badly โ€” you have built predictably, which costs exactly the same and hurts more.

What survives

The ground worth standing on when the questions start.

  • The description names the exact tools to generate benign and attack traffic, so you can build a fully labelled dataset yourself with no data-sourcing risk
  • The passive one-directional constraint is a genuinely interesting framing that rules out active response and forces a cleaner detection problem
  • Each threat class comes with its observable signal already identified, so your detector design has a defensible basis

Nothing here is fatal. It is just the list of places this statement pushes back, and you now get to push there first.

The framing is a joke. The findings are not โ€” they are the same analysis on the statement page, and every line above is attached to a score or a fact in the record. It is one opinion with its reasoning attached, so argue with it before you trust it.