Skip to content

iamkarthik2004/SINGHAM

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

70 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

SINGHAM Matrix Rain

πŸ›‘οΈ SINGHAM

Secure Intelligence for Network Guarding, Hazard Analysis & Monitoring


πŸš€ Overview

SINGHAM is an AI-powered cybersecurity platform designed to help everyday internet users detect and understand digital threats before they become victims.

Instead of relying on multiple disconnected security tools, SINGHAM brings email analysis, malicious URL detection, fake QR code verification, malware detection, and AI-powered explanations into a single intelligent platform.

The goal is to make cybersecurity simple, understandable, and accessible for everyone.


❗ Problem Statement

Modern cyber attacks have become increasingly sophisticated. Every day, users receive phishing emails, click malicious links, scan fake QR codes, and unknowingly download malware.

Most existing security tools focus on only one threat category, forcing users to switch between multiple services while still lacking a complete understanding of why something is dangerous. For non-technical users, distinguishing legitimate content from malicious content has become extremely difficult.

SINGHAM addresses this challenge by providing one unified platform capable of analyzing multiple cyber threats while explaining every prediction in simple language.


πŸ’‘ Solution

SINGHAM combines Machine Learning and Large Language Models to analyze different cybersecurity threats through a single web interface.

Instead of simply labeling something as "Safe" or "Dangerous", the platform also explains why the prediction was made using Explainable AI (XAI). Users receive actionable recommendations that help them make safer online decisions while gradually improving their cybersecurity awareness.


✨ Core Features

πŸ“§ AI Email Phishing Detection

  • Analyze suspicious emails by uploading their text or PDF source.
  • Detect phishing attempts using LLM + RAG powered reasoning.
  • Explain why an email is dangerous with specific red flags.

🌐 Scam URL Detection

  • Detect malicious websites and analyze URL structures.
  • Perform domain feature analysis using Machine Learning classification.

πŸ“± Fake QR Code Detection

  • Decode QR codes and validate destination URLs.
  • Detect phishing redirections and warn before opening websites.

🦠 Malware Detection

  • Scan uploaded files and analyze executable PE structures.
  • Compare file hashes and detect known malware signatures.

πŸ€– Explainable AI (XAI)

  • Transparent reporting on why a threat was flagged.
  • Shows which specific indicators were suspicious.
  • Provides risk level estimation and actionable recommendations.

πŸ—οΈ System Architecture

                               β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                               β”‚ πŸ‘€ User   β”‚
                               β””β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜
                                     β”‚
                                     β–Ό
                      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                      β”‚    SINGHAM Web Platform     β”‚
                      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                     β”‚
         β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
         β–Ό                   β–Ό               β–Ό                   β–Ό
 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚ πŸ“§ Email      β”‚   β”‚ 🌐 URL        β”‚   β”‚ πŸ“± QR Code    β”‚   β”‚ 🦠 Malware    β”‚
 β”‚   Dashboard   β”‚   β”‚   Dashboard   β”‚   β”‚   Dashboard   β”‚   β”‚   Dashboard   β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
         β”‚                   β”‚                   β”‚                   β”‚
         β–Ό                   β–Ό                   β–Ό                   β–Ό
 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚ PyPDF2 Text   β”‚   β”‚ URL Feature   β”‚   β”‚ QR Decoding & β”‚   β”‚ PE Header     β”‚
 β”‚ Extraction    β”‚   β”‚ Extraction    β”‚   β”‚ URL Extract   β”‚   β”‚ Extractor     β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
         β”‚                   β”‚                   β”‚                   β”‚
         β–Ό                   β–Ό                   β–Ό                   β–Ό
 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚ LangChain RAG β”‚   β”‚ XGBoost / RF  β”‚   β”‚ XGBoost / RF  β”‚   β”‚ Random Forest β”‚
 β”‚ Engine        β”‚   β”‚ Classifier    β”‚   β”‚ Classifier    β”‚   β”‚ Classifier    β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
         β”‚                   β”‚                   β”‚                   β”‚
         β–Ό                   β–Ό                   β–Ό                   β”‚
 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”           β”‚
 β”‚ Gemini 3.5    β”‚   β”‚ Explainable AIβ”‚   β”‚ Explainable AIβ”‚           β”‚
 β”‚ Flash & FAISS β”‚   β”‚ (SHAP Engine) β”‚   β”‚ (SHAP Engine) β”‚           β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜           β”‚
         β”‚                   β”‚                   β”‚                   β”‚
         β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                             β”‚
                             β–Ό
              β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
              β”‚   Threat Report Dashboard   β”‚
              β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ› οΈ Technology Stack

Layer Technology Description
Frontend HTML5, CSS3, Vanilla JavaScript Responsive user interface, interactive threat alerts, and dynamic dashboards.
Backend Flask, Gunicorn Lightweight Python web framework and WSGI server for serving APIs and layouts.
Machine Learning XGBoost, Random Forest, Scikit-learn Supervised classification models for predicting phishing URLs and malware.
Explainable AI (XAI) SHAP (SHapley Additive exPlanations) Explains URL classifier predictions by computing the contribution of each feature.
Generative AI Gemini 3.5 Flash, LangChain RAG-based email phishing analysis and natural language explanation generation.
Vector Database FAISS Vector similarity search database used to retrieve documents for email analysis.
Core Libraries Pandas, NumPy, PyPDF2, pefile PE header parsing, data manipulation, and text extraction from PDF files.
VCS & Environments Git, GitHub, Virtualenv Code versioning and isolated execution environments.

πŸ“‚ Project Structure

SINGHAM/
β”œβ”€β”€ backend/                        # Flask backend application
β”‚   β”œβ”€β”€ .env                        # Local environment variables (API keys)
β”‚   β”œβ”€β”€ .env.example                # Example environment variables template
β”‚   β”œβ”€β”€ ML_model/                   # Machine Learning model binaries
β”‚   β”‚   └── malwareclassifier-V2.pkl # Pre-trained malware classifier model
β”‚   β”œβ”€β”€ app.py                      # Main Flask application and API route controllers
β”‚   β”œβ”€β”€ explainability.py           # SHAP explanation calculations for threat analysis
β”‚   β”œβ”€β”€ feature_extraction_malware.py # Portable Executable (PE) file parsing & feature extractor
β”‚   β”œβ”€β”€ featureextraction.py        # URL security feature extraction logic
β”‚   β”œβ”€β”€ knowledge_base.txt          # Reference text/document database for RAG phishing detector
β”‚   β”œβ”€β”€ phishing_model.pkl          # Pre-trained XGBoost/Random Forest URL scanner model
β”‚   └── stats.db                    # SQLite database to track system scan metrics
β”œβ”€β”€ frontend/                       # User Interface resources
β”‚   β”œβ”€β”€ static/                     # Static CSS styling & JavaScript logic files
β”‚   β”‚   β”œβ”€β”€ email/                  # Static assets for the Email Phishing detector
β”‚   β”‚   β”‚   β”œβ”€β”€ script.js
β”‚   β”‚   β”‚   └── style.css
β”‚   β”‚   β”œβ”€β”€ fake_qr/                # Static assets for the Fake QR Code scanner
β”‚   β”‚   β”‚   β”œβ”€β”€ app.js
β”‚   β”‚   β”‚   └── style.css
β”‚   β”‚   β”œβ”€β”€ malware/                # Static assets for the Malware scanner
β”‚   β”‚   β”‚   β”œβ”€β”€ app.js
β”‚   β”‚   β”‚   └── style.css
β”‚   β”‚   └── url_scam/               # Static assets for the Scam URL scanner
β”‚   β”‚       β”œβ”€β”€ app.js
β”‚   β”‚       └── style.css
β”‚   └── templates/                  # Jinja2 HTML pages served by Flask
β”‚       β”œβ”€β”€ email_dashboard.html    # Phishing email scan dashboard
β”‚       β”œβ”€β”€ home.html               # Main landing portal
β”‚       β”œβ”€β”€ malware_dashboard.html  # Malware scanner upload panel
β”‚       β”œβ”€β”€ malware_result.html     # Malware analysis result display
β”‚       β”œβ”€β”€ qr_dashboard.html       # QR scan dashboard
β”‚       └── url_dashboard.html      # URL scan dashboard
β”œβ”€β”€ .gitignore                      # Configuration for Git ignored files
β”œβ”€β”€ Licence                         # Project License agreement
β”œβ”€β”€ matrix.svg                      # Custom Matrix digital rain animation SVG for README.md
β”œβ”€β”€ requirements.txt                # Python backend package dependencies
└── README.md                       # Documentation of the project

βš™οΈ Setup & Installation

Follow these steps to set up and run SINGHAM on your local machine:

1. Prerequisites

Ensure you have Python 3.8+ installed on your system.

2. Clone the Repository

Clone the repository and navigate to the project root directory:

git clone <repository-url>
cd SINGHAM

3. Create a Virtual Environment

Create and activate an isolated Python virtual environment:

  • On Linux/macOS:
    python3 -m venv venv
    source venv/bin/activate
  • On Windows:
    python -m venv venv
    venv\Scripts\activate

4. Install Dependencies

Install all required packages from requirements.txt:

pip install -r requirements.txt

5. Set Up Environment Variables

The Email Phishing analysis system relies on Google Gemini models. You need to configure a Google Gemini API Key:

  1. Copy the .env.example file into the backend/ directory as .env:
    cp .env.example backend/.env
  2. Open backend/.env in your text editor and set GEMINI_API_KEY to your actual API key:
    GEMINI_API_KEY=your_actual_gemini_api_key_here

    [!TIP] You can get a free API Key from Google AI Studio.

6. Run the Application

  1. Navigate to the backend directory:
    cd backend
  2. Launch the Flask development server:
    python app.py
  3. Open your browser and navigate to: http://127.0.0.1:5000/

🎯 Development Roadmap

  • βœ… Project Planning
  • βœ… System Design
  • βœ… Dataset Collection
  • βœ… Frontend Development & UI Refinement
  • βœ… Backend APIs integration
  • βœ… Unified Email Phishing Detection
  • βœ… Unified URL Scam Detection
  • βœ… Unified QR Scam Detection
  • βœ… Unified Malware Detection
  • βœ… AI Explanation (XAI) Engine
  • ⏳ Centralized Threat Report Dashboard
  • ⏳ Production Deployment & Docker Support

Made with ❀️ by Deon George, Karthik Krishnan, Amal Kuriyan Royce, and Joel M Thomas

About

SINGHAM - Secure Intelligence for Network Guarding, Hazard Analysis & Monitoring

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages