A lightweight, rule-based IDS/IPS framework for non-traditional IoT/OT environments. Detects SYN floods, data exfiltration, and DDoS activity across the Purdue Model zones using real-world RT-IoT2022 dataset traffic data.
This extension moves the framework beyond static dataset analysis into live network monitoring — connecting directly to physical firewalls, IDS appliances (Snort/Suricata), and compatible cyber security devices for real-time alert ingestion and automated response.