Project 3 of the triptych

NetSentry-IoT

An autonomous software probe for anomaly detection and IoT protocol auditing. Positioning: regulatory compliance (NIS2 / GDPR) and cyber hardening of distributed industrial sensor fleets.

Phase: framing — structure initialized
< 5 ms
malicious packet detection and isolation at the edge
No Cloud
local detection, no dependency on a hosted signature database

Project card

  • Developed by — Helveticore OÜ (Estonia)
  • Maturity — CMMI Level 3 “Defined”
  • Compliance — NIS2 / GDPR
  • Analysis engine — Scapy (deep inspection)

Sub-projects (src/)

  • packet-engine/ — packet analysis based on Scapy.
  • protocol-inspection/ — deep inspection of MQTT, HTTP, Zigbee.
  • attack-simulator/ — traffic generator and attack-source simulator.
  • anomaly-detection/ — local behavioral analysis: spoofing and DoS.

Milestones & risks

Milestones

  • 1 · Virtual test bench: simulated IoT traffic + replayable attack scenarios.
  • 2 · MQTT/HTTP/Zigbee protocol inspection on replayed captures.
  • 3 · Spoofing/DoS behavioral detection with latency measurement.
  • 4 · < 5 ms isolation and NIS2 / GDPR compliance reports.

Key risks (RSK)

  • False positives — mitigated by local learning/calibration and traceable thresholds.
  • Detection evasion on encrypted protocols — to be documented as a limitation.
  • Probe network/CPU footprint — < 5 ms detection requires a fast path.
Current state: the project's CMMI structure is initialized (requirements, design, test bench, performance) and the sub-projects are defined. Detailed artifacts remain to be written.