SIH 2026 • Prototype Preview

Suraksha Drishti

AI-Powered IPsec VPN Protocol Analyzer & Security Assessment Framework

An evidence-aware cybersecurity platform designed to transform encrypted IPsec traffic into actionable protocol intelligence, security findings, risk scores and assessment reports.

SIH26160NTROBlockchain & CybersecuritySoftware
suraksha-drishti-engine-preview
Encrypted Tunnel
Security Analysis
Risk Assessment
Conceptual Pipeline Representation

The Challenge

Navigating the Encryption Blind Spot

Limited Visibility

Encryption hides useful traffic characteristics from conventional monitoring systems.

Manual Protocol Inspection

IKE, ESP/AH and tunnel characteristics often require specialist packet-level analysis.

Fragmented Security Assessment

Packet analysis, crypto evaluation and security checks are commonly handled separately.

Limited Explainability

Security findings need clear evidence explaining what was observed and why it matters.

Slow Investigation

Turning raw PCAP/network telemetry into actionable security reports is time-consuming.

Our Approach

Comprehensive IPsec Intelligence

01

IPsec Traffic Analysis

Detect and analyse IKE, ESP and AH traffic from PCAP or network telemetry.

02

Protocol & Crypto Intelligence

Extract IKE version, VPN mode, algorithms, authentication and security parameters.

03

Lightweight AI Engine

Use lightweight machine learning for encrypted-traffic classification and anomaly detection.

04

Evidence-Aware Security Assessment

Combine protocol evidence, standards-based rules, risk scoring and remediation guidance.

System Workflow

Data to Actionable Intelligence

Planned End-to-End Architecture
PCAP / Live Traffic
IPsec Detection
IKE / ESP / AH Analysis
Feature Extraction
AI / ML Classification
Anomaly Detection
Security Rules & Assessment
Risk Score + Findings
PDF Security Report

Key Capabilities

IKEv1 / IKEv2 Analysis
ESP / AH Detection
VPN Mode Identification
Cryptographic Parameter Analysis
Flow & Packet Feature Extraction
Random Forest Classification
Planned ML Layer
Isolation Forest Anomaly Detection
Planned ML Layer
Risk Scoring
Evidence Mapping
Security Findings
Remediation Recommendations
PDF Report Generation

Technology

Architecture Design

Architecture designed for lightweight deployment on commodity hardware.

INPUT LAYER
PCAPLive Network Traffic
PARSER LAYER
TSharkScapyPacket Parser
FEATURE LAYER
Flow FeaturesPacket FeaturesProtocol FeaturesCrypto Features
ML LAYER
Random ForestIsolation Forest
SECURITY ENGINE
NIST / RFC Based RulesRisk AssessmentSeverity Classification
EVIDENCE ENGINE
ObservedInferredUnknownConfidence
OUTPUT LAYER
DashboardFindingsRisk ScorePDF Report

Security Assessment

Illustrative assessment interface — live analysis engine under development.

Security Score

Illustrative
72/ 100

Risk Level

Illustrative
MEDIUM

IPsec Protocol

IKEv2

Traffic Status

Encrypted

Sample Findings

Illustrative
Weak / Deprecated Algorithm Detected
HIGH
Weak DH Group Configuration
MEDIUM
PFS Configuration Missing
REVIEW

Expected Output Pipeline

Input

PCAP / Network Traffic

Analysis

Protocol Intelligence

Findings

Evidence-backed

Risk Score

Quantified Threat

Report

Executive + Technical PDF

From Encrypted Traffic to Actionable Security Intelligence

Transforming raw network data into comprehensive security reports with clear evidence, empowering defense teams.

Faster Security Assessment
Explainable Findings
Lightweight Deployment
Reduced Manual Investigation
Standards-Based Evaluation
Better SOC Visibility
Scalable Architecture
Stronger Cyber Resilience

Target Deployment Contexts

Enterprise NetworksSOC / NOCCritical InfrastructureGovernment Networks

*Note: Real-world deployment architectures are planned post-prototype completion.

Prototype Status

Frontend Preview

The system is currently in the active development phase.

01Solution Architecture
DONE
02Frontend Overview
DONE
03PCAP Analysis Engine
IN DEVELOPMENT
04ML Classification
IN DEVELOPMENT
05Security Assessment Engine
IN DEVELOPMENT
06Integrated Prototype
UPCOMING