Elite Execution
SIH 2026SIH26153
SIH26153NTROBlockchain & Cybersecurity

Don’t Just Detect the Attack. Forecast Where It’s Heading.

An AI-powered temporal world model that learns evolving network behaviour and forecasts future attack progression for proactive cyber defence.

Prototype interface for SIH 2026 — all figures shown are simulated demo data.

Behaviour Timeline

  1. 01Normal Behaviour
  2. 02Suspicious Behaviour
  3. 03Rising Risk
  4. 04Predicted Attack

Live Attack Forecast

Simulated K-step forecast output from the temporal world model.

Illustrative demo output

Session Forecast

flow-id: 8f3c1a · window: 10s

Current Risk

72%

Status

High Risk

Forecast Horizon: Next 50 seconds

Predicted Next Stage

Lateral Movement

MITRE ATT&CK · T1021 — Remote Services

Forecast Risk Trajectory

probability of malicious progression (%)
025507510018%Now31%+10s48%+20s67%+30s81%+40s89%+50s

Now

18%

+10s

31%

+20s

48%

+30s

67%

+40s

81%

+50s

89%

All values above are hard-coded mock data for presentation purposes. No model inference, PCAP parsing or network data is processed in this prototype.

Why Did the Risk Increase?

A forecast is only useful if a defender can see what drove it. The system surfaces the traffic behaviours that contributed most to the predicted progression.

The final system will use model-derived attention/feature attribution to explain the forecast.

Percentages below are illustrative demo values chosen for the presentation. They are not real attribution scores from a trained model.

Feature Contribution

Demo data
  • SYN Rate82%

    Scan-style handshake volume

  • Port Diversity67%

    Wide destination port spread

  • Connection Burst54%

    Short-window connection spikes

  • IAT Variation41%

    Inter-arrival time instability

  • RST Activity29%

    Abrupt reset / teardown ratio

How It Works

From raw network telemetry to an explained, forward-looking risk timeline.

  1. 01

    Traffic Input

    PCAP / CSV network telemetry

    Zeek / CICFlowMeter style flow records

  2. 02

    Network State

    Convert traffic into time-windowed state vectors

    Sliding windows over flow statistics

  3. 03

    Temporal AI

    LSTM + Attention learns state-transition dynamics

    Sequence model over network behaviour

  4. 04

    Future Forecast

    Roll out multiple future states and estimate attack probability

    K-step ahead probability trajectory

  5. 05

    Defender Output

    MITRE ATT&CK stage + explanation + risk timeline

    Actionable, attributable alert

network traffic → feature extraction → time-windowed network states → temporal AI / world model → future-state forecasting → attack probability → predicted attack stage → MITRE ATT&CK mapping → explainable defender alert

Why It Matters

Traditional intrusion detection answers “is this traffic malicious?” This system also answers “where is it heading?”

Predictive Defence

Forecast attack progression before critical stages.

Explainable Security

Show which traffic behaviours are influencing the prediction.

Proactive Response

Give security teams a future-oriented risk timeline instead of only a reactive alert.

The end system is intended to support PCAP / CSV input, attack-stage mapping, explainability and offline inference on a defender workstation.

Built for SIH26153

Blockchain & Cybersecurity · SIH 2026

Prototype UI
Problem Statement
AI Based Network Attack Forecasting from Network Traffic Data
Organization
NTRO — National Technical Research Organisation
Team
Elite Execution