// TELEMETRY REPOSITORY & LAB VALIDATION
Engineering dossiers & applied research
Hands-on testbeds in enterprise routing architectures, deep packet forensic dissections, and defensible OT test environments.
LAB-V4.2Core Infrastructure
OSPF CONVERGED
Enterprise Routing Protocol Deployment
Engineered multi-area OSPF, EIGRP dual-stack routing, and RIPv2 fallback topologies with automated metric recalculation and redundant gateway failover.
Sub-Second Failover< 420ms
Route Table Size1,200+ Prefixes
Convergence MetricZero Loss State
Engineering Highlights
- Multi-Area OSPF Area 0 Backbone summarization
- EIGRP feasible successor calculation tuning
- Dynamic cost-metric load balancing & BFD integration
OSPFv3EIGRP Dual-StackRIPv2BGP-EdgeGNS3Cisco IOSWiresharkBash Automation
Validated Telemetry
LAB-V3.8Core Infrastructure
VLAN SEGREGATION VERIFIED
VLAN Segmentation & 802.1Q Trunking Architecture
Architected secure inter-VLAN routing with 802.1Q encapsulation, strict Access Control Lists (ACLs), DHCP snooping, and dynamic ARP inspection.
VLAN Isolation100% Policy Bound
Broadcast Domain8 Subnets
Switchport HardeningPort Security Enforced
Engineering Highlights
- Router-on-a-Stick and Layer 3 Switch SVI implementations
- Standard and Extended ACL policy enforcement on gateways
- Spanning Tree PortFast & BPDU Guard perimeter lockdown
IEEE 802.1QRSTP 802.1wLACP 802.3adInter-VLANCisco Packet TracereNSPSNMPPowerShell
Validated Telemetry
LAB-V5.1Threat Forensics
ANOMALY CAPTURE ACTIVE
Deep Packet Inspection & Wireshark Forensic Analysis
Performed deep layer-4 to layer-7 trace dissections, uncovering TCP half-open attacks, malformed DNS tunneling attempts, and latency waterfall bottlenecks.
Capture Velocity10 Gbps Monitored
Malicious Flag Rate99.4% Captured
Jitter Variance< 1.2ms
Engineering Highlights
- TCP sequence/acknowledgment gap analysis & retransmission tracing
- DNS exfiltration entropy scoring across Base64 payloads
- Comparative protocol latency benchmarking via SNMP streams
TCP/IPDNS TunnelingTLS 1.3ICMP FloodWiresharkPython ScapyTcpdumpKali Linux
Validated Telemetry
LAB-V2.4ICS/SCADA
SCADA DEFENSE ARMED
OT & ICS Security Testbed Experiments
Constructed isolated industrial control testbeds evaluating Modbus and DNP3 communications, air-gap security controls, and PLC payload verification.
Boundary DefenseAir-Gap Emulated
SCADA TelemetryReal-Time Verified
Command TamperingZero false Positives
Engineering Highlights
- Industrial honeypot and Modbus telemetry register validation
- Detection of unauthorized function code injections (Code 0x05/0x06)
- Strict zero-trust segmentation between IT and OT demilitarized zones
Modbus TCPDNP3ProfinetOPC-UALabshock OT LabGNS3PythonKali Linux
Validated Telemetry
PIPELINE ARCHITECTURE // FYP METHODOLOGY
Machine learning and threat detection workflow
A verified 5-stage engineering pipeline translating raw packet captures and URL payloads into deterministic machine learning classification with sub-12ms inference.
PHASE_01 // INGESTIONSTEP 01
Dataset Ingestion & Traffic Collection
Captures raw benign network traffic and malicious phishing telemetry from controlled testbeds, public repositories (CIC-IDS), and live packet captures.
PCAP Engine:Wireshark / tcpdump
Sampling Rate:10,000 pkts/sec
Dataset Size:480K Samples
PCAP ParsingBenign BaselineThreat Feeds
PHASE_02 // SANITIZATIONSTEP 02
Preprocessing & Signal Sanitization
Cleans noisy headers, imputes incomplete packet flows, normalizes port addressing, and applies one-hot categorical encoding across protocol structures.
Missing Values:Zero-loss Impute
Encoding:One-Hot / Scaled
Scaling Range:StandardScaler [0,1]
IP/Port NormOutlier RemovalData Cleanse
PHASE_03 // ENGINEERINGSTEP 03
Feature Extraction & Domain Engineering
Derives critical behavioral vectors including payload entropy, TCP flag distributions, flow duration, and domain URL structural token lengths.
Vector Count:78 Dimensions
Entropy Check:Shannon Metric
Time Delta:Inter-Arrival (IAT)
Shannon EntropyFlow WindowsTCP Heuristics
PHASE_04 // OPTIMIZATIONSTEP 04
Model Architecture & Training Protocol
Constructs a hybrid deep learning neural network paired with ensemble tree classifiers, optimized using Adam with stratified 5-fold cross-validation.
Architecture:Hybrid DNN + Tree
Optimizer:Adam (lr=0.001)
Validation:5-Fold Stratified
PyTorch / ScikitEarly StoppingDropout 0.3
PHASE_05 // EVALUATIONSTEP 05
Performance Evaluation & Live Inference
Executes rigorous model benchmarking across unseen adversarial payloads with sub-12ms inference turnaround per sampled network stream.
Latency:<11.8ms per flow
Loss (BCE):0.0318
Deployment:Real-time Gateway
Zero-Day GuardConfusion MatrixLive Stream
Verified Model Performance Telemetry
Hybrid URL phishing classification results
Final Year Project testbed evaluation against 120,000 holdout adversarial vectors.
Accuracy99.4%
BASELINE 95.0%+4.4% OVER TARGET
Precision99.1%
BASELINE 95.0%+4.1% OVER TARGET
Recall98.8%
BASELINE 95.0%+3.8% OVER TARGET
F1-Score98.9%
BASELINE 95.0%+3.9% OVER TARGET
Designed, trained, and benchmarked by Fara Yahya at Faculty of Computing and Informatics, Universiti Malaysia Sabah.
SYS STATUS: OPERATIONALContact for details