Don’t Just Detect the Attack. Forecast Where It’s Heading.
An AI-powered temporal world model that learns evolving network behaviour and forecasts future attack progression for proactive cyber defence.
Prototype interface for SIH 2026 — all figures shown are simulated demo data.
Behaviour Timeline
- 01Normal Behaviour
- 02Suspicious Behaviour
- 03Rising Risk
- 04Predicted Attack
Live Attack Forecast
Simulated K-step forecast output from the temporal world model.
Session Forecast
flow-id: 8f3c1a · window: 10s
Current Risk
72%
Status
High Risk
Forecast Horizon: Next 50 seconds
Predicted Next Stage
Lateral Movement
MITRE ATT&CK · T1021 — Remote Services
Forecast Risk Trajectory
probability of malicious progression (%)Now
18%
+10s
31%
+20s
48%
+30s
67%
+40s
81%
+50s
89%
All values above are hard-coded mock data for presentation purposes. No model inference, PCAP parsing or network data is processed in this prototype.
Why Did the Risk Increase?
A forecast is only useful if a defender can see what drove it. The system surfaces the traffic behaviours that contributed most to the predicted progression.
The final system will use model-derived attention/feature attribution to explain the forecast.
Percentages below are illustrative demo values chosen for the presentation. They are not real attribution scores from a trained model.
Feature Contribution
Demo data- SYN Rate82%
Scan-style handshake volume
- Port Diversity67%
Wide destination port spread
- Connection Burst54%
Short-window connection spikes
- IAT Variation41%
Inter-arrival time instability
- RST Activity29%
Abrupt reset / teardown ratio
How It Works
From raw network telemetry to an explained, forward-looking risk timeline.
- 01
Traffic Input
PCAP / CSV network telemetry
Zeek / CICFlowMeter style flow records
- 02
Network State
Convert traffic into time-windowed state vectors
Sliding windows over flow statistics
- 03
Temporal AI
LSTM + Attention learns state-transition dynamics
Sequence model over network behaviour
- 04
Future Forecast
Roll out multiple future states and estimate attack probability
K-step ahead probability trajectory
- 05
Defender Output
MITRE ATT&CK stage + explanation + risk timeline
Actionable, attributable alert
network traffic → feature extraction → time-windowed network states → temporal AI / world model → future-state forecasting → attack probability → predicted attack stage → MITRE ATT&CK mapping → explainable defender alert
Why It Matters
Traditional intrusion detection answers “is this traffic malicious?” This system also answers “where is it heading?”
Predictive Defence
Forecast attack progression before critical stages.
Explainable Security
Show which traffic behaviours are influencing the prediction.
Proactive Response
Give security teams a future-oriented risk timeline instead of only a reactive alert.
The end system is intended to support PCAP / CSV input, attack-stage mapping, explainability and offline inference on a defender workstation.
Built for SIH26153
Blockchain & Cybersecurity · SIH 2026
- Problem Statement
- AI Based Network Attack Forecasting from Network Traffic Data
- Organization
- NTRO — National Technical Research Organisation
- Team
- Elite Execution