Each multi-anomaly event is logged in Redis with a flag escalated. An operator can manually escalate an event. In the future, integration with email, Slack, or Telegram will be added.
Web Interface Features
- Full multilingual support (Russian & English);
- Tooltips and modals explaining system logic;
- Auto-refresh;
- Multi-anomaly log with escalation controls.
Conclusion & Future Plans
We built a modular AI platform for analyzing Suricata data that combines statistical learning, machine intelligence, and intuitive visual feedback.
Next Steps:
- Support for other sources (Zeek, Wazuh, etc.);
- Integration with SIEM and alerting platforms;
- Complex correlation rules and chained multi-alerts;
- Distributed/cloud deployment support.
💡 AI helps not just detect anomalies — it allows us to truly understand the behavior of the network. And that is vital in a world of complex threats.