UAT // STUDENT INNOVATION PROJECTLOCAL-FIRST

See the signal.
Understand the risk.
Control the response.

SentinelBox is an explainable network-defense appliance that turns scattered security events into device-level risk—and makes every response visible, proportional, and reversible.

DESIGNED FOR5–100 endpoints
DEPLOYMENTOn-premises edge
DECISION MODELDeterministic
DEVICE RISK / LIVE MODELLOCAL
⌂
DEVICEworkstation-07192.168.40.27
72RISK SCORE
POLICY STATERESTRICTED
WHY THIS CHANGED03 SIGNALS
  1. Repeated DNS anomaly+18
  2. Outbound scan pattern+27
  3. Known-risk signature+32
APPLIED RESPONSELimit outbound accessReversible · Administrator override enabled
EVENT → SIGNAL → CORRELATION → RISK → POLICY → RESPONSESBX-01

Alerts are plentiful.
Answers are not.

Small organizations can see firewall and intrusion alerts, but often lack the people and tooling to connect weak signals over time, identify the device that matters, and choose a safe response.

[ CONSEQUENCE ]

Isolated alerts become noise. Risk stays hidden until the damage is obvious.

02 THE SENTINELBOX METHOD

One decision chain.
Every step explainable.

SentinelBox does not treat a single alert as a verdict. It gathers evidence, correlates behavior by device, and moves through bounded policy states. Select a stage to inspect the model.

STAGE 01

Security event enters locally

Suricata observes network behavior at the routed edge. The original event remains available as evidence instead of disappearing into an opaque score.

source=suricata · class=dns-anomaly · device=workstation-07
INNOVATION CLAIM

“SentinelBox combines multiple Suricata events into a persistent risk score for each device. It explains why the score changed, then applies only the reversible policy allowed for that risk state.”

03 PROTOTYPE ARCHITECTURE

Defense at the edge.
Evidence stays local.

A repurposed Dell OptiPlex Micro sits inline between the internet connection and the protected network. Two interfaces create a controlled observation and response point—without endpoint agents or cloud dependence.

WANInternet edge
NIC 1
SENTINELBOX
Dell OptiPlex Micro · Debian
NIC 2
LANProtected devices
DETECT

Suricata

Local network-event detection at the routed edge.

DECIDE

Go + SQLite

Correlation, risk state, evidence, and audit history.

INVESTIGATE

Gravwell CE

Local event search and supporting investigation.

RESPOND

nftables

Graduated controls with administrator release.

DELIVERABLE BOUNDARY

SentinelBox is an active academic prototype—not an enterprise SIEM, endpoint detection platform, firewall replacement, managed cloud service, or production security guarantee.

04 PROTOTYPE STATUS

Working foundation.
Focused next build.

The project begins with a functioning routed-appliance foundation. The SIP work turns that base into a testable risk-to-response system.

FOUNDATIONIMPLEMENTED
  • ✓Routed WAN/LAN pathInline Debian gateway behavior
  • ✓Strict configuration validationRejects invalid operating state
  • ✓SQLite persistenceDevice, event, and audit storage
  • ✓Service health monitoringLocal operational visibility
05 RESPONSE MODEL

Try the decision logic.

This simplified demonstration shows the principle: evidence accumulates, risk is bounded, and policy changes remain visible. Add or clear signals to see the resulting state.

DEVICE / DEMO-CLIENT-01NORMAL
WATCHRESTRICTCONTAIN
0/ 100 RISK

— No active signals

RESPONSEObserve baseline traffic
06 SIP DELIVERY ROADMAP

From design to defended demo.

Four academic milestones keep the innovation measurable and the prototype scope realistic.

SIP 311DEFINE

Design the system

Requirements, threat model, architecture, and test plan.

SIP 312BUILD

Establish the edge

Routed appliance, Suricata ingestion, device inventory, and persistent events.

SIP 401DECIDE

Implement the innovation

Correlation, risk decay, policy states, and administrator override.

SIP 409PROVE

Test and demonstrate

Dashboard, containment tests, performance evidence, and showcase demo.

07 WHO IT SERVES

Built for the security gap.

SentinelBox focuses on organizations that need clear answers without a dedicated security operations center.

01

Small-business owner

Needs an understandable answer to “which device needs attention, and why?”

02

IT generalist

Needs focused evidence and safe controls—not another stream of disconnected alerts.

03

MSP technician

Needs a repeatable local view for triage across resource-constrained client networks.

08 PRIOR ART

A distinct decision layer.

SentinelBox builds on proven network-security patterns. Its research focus is the explainable path from multiple observations to a proportional device response.

SYSTEMESTABLISHED STRENGTHSENTINELBOX FOCUS
FirewallaConsumer / SMB network appliance and device controlsOngoing multi-event risk for known and unknown devices, with visible reasoning and graduated states
OPNsense IPSSuricata-based alerting and traffic blockingCorrelate multiple events over time before selecting a reversible device policy
Security OnionBroad network monitoring and investigation platformA focused decision engine for one small inline network

Chance Butts

Network Security student at the University of Advancing Technology. SentinelBox brings together network engineering, secure systems design, and threat detection in a practical, testable appliance.

UATSTUDENT
INNOVATION
PROJECT