Skip to content
SIH Buddyby Ganeev Singh
Dev

๐Ÿ”ฅ Roast My Pick ยท SIH26155

AI-Driven Multi-Vendor Network Security Compliance Auditor

National Technical Research Organisation (NTRO)

Mild18/100

Good pick. Genuinely. Now sit down, because the judges are going to try anyway โ€” and this is what they will try.

Strong pick. Well-specified and genuinely useful โ€” do two or three vendors deeply and frame the normalisation layer as the extensible core, because chasing the full vendor list guarantees shallow coverage of a problem whose whole point is breadth. Roughly 70โ€“160 teams are expected to go here.

The receipts

Every red flag on this statement, in full. These are the four places it bites.

  1. Exhibit A

    Every vendor's config syntax differs, and the normalisation layer is slow linear work, so a tool covering two vendors has visibly under-answered a problem framed around many

  2. It gets worse

    The benchmarks contain hundreds of controls, and encoding a meaningful subset correctly is more work than teams expect

  3. Still reading?

    A false compliance verdict on a production device config is consequential, so parsing accuracy and rule correctness matter more than breadth

  4. And the finisher

    The AI-assisted parsing risks misreading a config, which in a security audit produces confidently wrong findings

The damage report

Every score this statement earned, and what each one actually costs you.

  • Feasibility

    3/5

    Buildable. Not comfortably. There is a week in here you have not planned for yet.

    The frameworks are public and config parsing plus rule evaluation is achievable, but every vendor uses different config syntax and the description asks for effectively any vendor, so the normalisation layer across heterogeneous formats is the real, unglamorous bulk of the work and it scales linearly with vendor coverage.

  • Innovation scope

    3/5

    Mildly interesting. The novelty will not carry the room; the build has to.

    The audit logic is dictated by the published benchmarks, so your room is in the vendor-normalisation abstraction and in using AI to extend parsing to unfamiliar vendors, rather than in the compliance rules themselves.

  • Clarity

    5/5

    The ask is unambiguous, which quietly removes your favourite excuse.

    The frameworks are named and linked, the vendor landscape is enumerated in detail, and the goal โ€” audit heterogeneous device configs against these benchmarks โ€” is stated precisely, making the requirement unusually complete.

  • Acceptance potential

    4/5

    Strong footing before you have written a line. Try not to waste it.

    Genuinely valuable and well-specified, the vendor-agnostic angle is a real gap that expensive tools fill poorly, and the demo is clean โ€” the honest constraint is that supporting many vendors is slow linear work, so a team that does two or three vendors well and frames the normalisation as extensible succeeds where one chasing full coverage does not.

  • Effort

    Massive

    A semester of work wearing a hackathon costume. Something is getting cut; decide what now, not in week five.

    A normalisation layer across many vendor config syntaxes plus machine-encoded rule sets for multiple frameworks plus reporting is a large effort where each additional vendor and framework multiplies the work.

  • Demo-ability

    Easy

    Easy to demo โ€” and so is everyone else's. Working is the floor here, not the achievement.

    Uploading two different vendors' configs and watching the same rule catch the same weakness in both, with the exact control cited, is a clean and immediately convincing demonstration of the core value.

The demo they will have already seen

Somewhere around 70โ€“160 teams are heading here, and the description is doing the choosing for most of them. They will read the same brief, reach the same architecture, and build a version of the same demo you are planning. Being correct is the floor. If your five minutes could be swapped with the team before you and nobody in the room would notice, you have not picked badly โ€” you have built predictably, which costs exactly the same and hurts more.

What survives

The ground worth standing on when the questions start.

  • CIS Benchmarks and STIGs are public and precise, so your audit rules come from authoritative published standards rather than invention
  • The same-rule-across-two-vendors demo directly proves the vendor-agnostic value that distinguishes this from vendor-locked tools
  • The AI-assisted parsing angle is a genuine differentiator for extending to vendors you did not hand-build

Nothing here is fatal. It is just the list of places this statement pushes back, and you now get to push there first.

The framing is a joke. The findings are not โ€” they are the same analysis on the statement page, and every line above is attached to a score or a fact in the record. It is one opinion with its reasoning attached, so argue with it before you trust it.