Suricata
Local network-event detection at the routed edge.
SentinelBox is an explainable network-defense appliance that turns scattered security events into device-level risk—and makes every response visible, proportional, and reversible.
192.168.40.27Small organizations can see firewall and intrusion alerts, but often lack the people and tooling to connect weak signals over time, identify the device that matters, and choose a safe response.
Isolated alerts become noise. Risk stays hidden until the damage is obvious.
SentinelBox does not treat a single alert as a verdict. It gathers evidence, correlates behavior by device, and moves through bounded policy states. Select a stage to inspect the model.
Suricata observes network behavior at the routed edge. The original event remains available as evidence instead of disappearing into an opaque score.
source=suricata · class=dns-anomaly · device=workstation-07
INNOVATION CLAIM“SentinelBox combines multiple Suricata events into a persistent risk score for each device. It explains why the score changed, then applies only the reversible policy allowed for that risk state.”
A repurposed Dell OptiPlex Micro sits inline between the internet connection and the protected network. Two interfaces create a controlled observation and response point—without endpoint agents or cloud dependence.
Local network-event detection at the routed edge.
Correlation, risk state, evidence, and audit history.
Local event search and supporting investigation.
Graduated controls with administrator release.
SentinelBox is an active academic prototype—not an enterprise SIEM, endpoint detection platform, firewall replacement, managed cloud service, or production security guarantee.
The project begins with a functioning routed-appliance foundation. The SIP work turns that base into a testable risk-to-response system.
This simplified demonstration shows the principle: evidence accumulates, risk is bounded, and policy changes remain visible. Add or clear signals to see the resulting state.
— No active signals
Four academic milestones keep the innovation measurable and the prototype scope realistic.
Requirements, threat model, architecture, and test plan.
Routed appliance, Suricata ingestion, device inventory, and persistent events.
Correlation, risk decay, policy states, and administrator override.
Dashboard, containment tests, performance evidence, and showcase demo.
SentinelBox focuses on organizations that need clear answers without a dedicated security operations center.
Needs an understandable answer to “which device needs attention, and why?”
Needs focused evidence and safe controls—not another stream of disconnected alerts.
Needs a repeatable local view for triage across resource-constrained client networks.
SentinelBox builds on proven network-security patterns. Its research focus is the explainable path from multiple observations to a proportional device response.
Network Security student at the University of Advancing Technology. SentinelBox brings together network engineering, secure systems design, and threat detection in a practical, testable appliance.