← Work03 / NETWORK ANALYSIS / INVESTIGATION2024

SECURITY · REAL-TIME VISUALIZATION / 2024

ThreatSense

A security interface should shorten the distance between signal and decision.

ThreatSense is a real-time network analysis dashboard that turns changing traffic signals into a focused surface for observation and investigation.

Personal project · security research

35%fewer false positivesversus rule-based systems · 5k+ labeled samples

Reported project figures; evaluation limits are explained with the results below.

My contribution
Personal security research project organizing real-time network signals into a dashboard for observation and investigation.
Key constraint
Preserve threat-state hierarchy while multiple signals change; support pause and inspection before a decision.
What this case shows
The source repository is linked below. This case uses a conceptual investigation flow, not a recording of a live system.

What needed to become clear.

Network monitoring produces several simultaneous signals. Volume, suspicious activity, latency, and distribution must be understood together without forcing the operator to assemble the situation from disconnected charts.

APPROACH

The interface organizes investigation around state. It shows what deserves attention first, then presents the analytical views required to understand the signal.

DOMAIN

NETWORK ANALYSIS / INVESTIGATION

The product logic behind the interface.

  1. 01

    Threat state leads the analytical grid.

  2. 02

    Different chart types share cadence, spacing, and hierarchy.

  3. 03

    Pause is part of the product: a changing signal must be inspectable, not merely watched.

  4. 04

    The research environment spans Kali, Ubuntu, and Wireshark.

  5. 05

    The dashboard processed more than 1,000 network flows per second in the evaluated scenario.

A visible path through the system.

01Network flows

Observe changing traffic signals.

02Threat state

Establish what deserves attention first.

03Investigation views

Pause and inspect the analytical context.

04Operator decision

Use that context to understand the signal.

04 / OUTCOME

ThreatSense reached a reported 94% detection accuracy, processed more than 1,000 network flows per second, and reduced false positives by 35% versus rule-based systems. The work also included a dataset of 5,000+ labeled samples for investigating suspicious activity.

Scope of the reported resultsThese are reported project results. This portfolio does not document the detection-accuracy formula or the full evaluation and comparison protocols; the figures should not be read as independently validated benchmarks.

What I learnedAlert hierarchy must be stronger than chart decoration. Real-time interfaces need deliberate pause and inspection states.

STACK / TOOLS IN CONTEXT

PythonDashPlotlyWiresharkNetwork analysisRisk analysis

CONTACT / THE NEXT SIGNAL

Have a complex product?

Talk to me about product architecture, data-rich interfaces, and creative implementation where the experience has to remain clear.