Trinetra
Open console

TRINETRA · SIH 2026 · Problem statement 26145

See the threat. Never touch the network.

TRINETRA reads copied traffic across a one-way boundary and turns behavioural signals into explainable incidents. It has no return path toward the network it watches, so the analysis can be trusted even where the network cannot be reached.

The scene above, read left to right.Source entities on the left — network devices and endpoints. A single boundary plane in the centre. The analysis enclave on the right, holding one fin per detector. Traces cross the boundary once and only once. Nothing returns, so the enclave is isolated from the network it observes.

One-way by construction
Copied traffic arrives on a receive-only interface with a host-enforced ingress drop. There is no socket, route or credential pointing back at the monitored network.
Nine detectors, one contract
RULE, STATISTICAL, SUPERVISED and HYBRID are all first-class. Every result records its technique, so an alert never overstates how much a model was involved.
Evidence travels with the alert
Observations are kept separate from the thresholds and baselines they were compared against, alongside detector, model and schema versions.
Models are promoted, not shipped
A champion has to be evaluated, gated and promoted by a person. Live traffic can only ever become a training candidate.

Product principles

Four commitments, each one checkable.

A passive product has to earn trust differently. TRINETRA states its limits up front, and every one of them is a property of the deployment rather than a promise in the documentation.

Passive

TRINETRA observes copied traffic. It does not probe, scan, complete a handshake, block, filter or mitigate, and it never decrypts — TLS is analysed as handshake metadata only.

How it is enforcedThe analysis modules open no sockets toward captured addresses. A test parses the AST of every module that touches captured data and fails if one imports socket, requests, urllib, httpx, subprocess, http or ftplib, or calls eval, exec, system or popen.

One-way

There is no return path toward the monitored network. Signals cross the boundary once; nothing crosses back, and nothing TRINETRA runs sits on the far side of it.

How it is enforcedThe live sensor runs on an unbridged veth pair with an all-protocol ingress drop installed while both ends are still down, and it holds NET_RAW and nothing else. The API reports sensor.read_only true and boundary_state HOST_BLOCKED.

Explainable

An alert is not a score. It carries what was observed, what it was compared against, the reason codes that fired, and the detector, model and schema versions needed to reproduce the decision.

How it is enforcedObservations are split from baseline comparisons by feature name, so a reader can tell measurement from reference. One threat class is an alert; two or more distinct classes on one subject inside 300 seconds become an incident.

Governed

A model is evaluated, gated and promoted by a person. Live traffic can only ever become a training candidate — no code path writes to a champion at runtime.

How it is enforcedTraining registers a CANDIDATE. Drift emits signals and calls nothing. Shadow inference is persisted for comparison and dropped by fusion, so a challenger can never become an alert. Every promotion is recorded with its actor, reason and gate results.

Detection coverage

Nine detectors. Rules, statistics and models side by side.

Every detector implements one contract and is fault-isolated, so one raising an exception does not stop the others seeing the window. technique is recorded on every result, so an alert never overstates how much a model was involved. Select a family to see its threat class, what it measures and the reason codes it can emit.

anomaly

BENIGN · STATISTICAL · 20260928-1

Behavioural outlier detector. It scores how far an entity's window sits from its own baseline and contributes corroboration. On its own it reports BENIGN, so it never becomes a threat verdict by itself.

Entity
HOST / DESTINATION / PAIR
Headline field
anomaly.anomaly_score
Compared against
anomaly.anomaly_threshold
Reason code
NETWORK_BEHAVIOUR_OUTLIER
Detector version
1.0.0 · schema 1.2.0

Reason codes

ANOMALY:NETWORK_BEHAVIOUR_OUTLIER

Explainable detection

Six detectors agreed. Here is what each one saw.

An isolated signal is not a verdict. Fusion records which detectors contributed, by how much, and the analyst can open every reading back to the threshold or baseline it was compared against.

Worked example. One stored incident, reproduced from the evidence the API returned for it: subject 172.20.0.10, observed from 2026-09-29T20:11:42Z to 2026-09-29T20:29:36Z, feature schema 1.2.0. Every number below is a measurement from that incident. The DGA entry is the one whose own alert carried severity: CRITICAL.

c2_beacon

C2_BEACONSTATISTICALno model

interarrival_mean

6.119

interarrival_stdev

0.054

interarrival_cv

0.0088 · threshold 0.25

interarrival_count

9 · minimum 6

periodicity_score

0.991 · threshold 0.7

beacon_port

4444

C2_BEACON:PERIODIC_INTERVALS · C2_BEACON:STABLE_PAYLOAD_SIZE · C2_BEACON:EXTERNAL_DESTINATION

recon

RECONRULEno model

unique_dst_ports_60s

1001 · threshold 20

unique_dst_ips_60s

1 · origin-only capture

dst_port_entropy_60s

9.97

mean_origin_bytes_per_flow

60.3 · probe threshold 256

RECON:VERTICAL_PORT_SCAN · RECON:WIDE_TARGET_SPREAD_ORIGIN_ONLY · RECON:SMALL_ORIGIN_PROBES

exfiltration

EXFILTRATIONSTATISTICALno model

bytes_out_total_300s

52 753 086 · threshold 10 000 000

bytes_out_per_sec_60s_zscore

3.20 · threshold 4.0

bytes_out_per_sec_60s_baseline_mean

78 924.7

bytes_out_per_sec_60s_baseline_p95

875 143.6

outbound_flow_bytes_baseline_mean

344.9

outbound_flow_bytes_baseline_observations

17 944

EXFILTRATION:HIGH_OUTBOUND_VOLUME · EXFILTRATION:OUTBOUND_FLOW_SIZE_DEVIATION · EXFILTRATION:ORIGIN_ONLY_CAPTURE

dga

DGASUPERVISED20260928-1

dga_probability

1.00

dns_char_entropy

3.98

dns_payload_length

26

dns_longest_label_length

26

DGA:DGA_MODEL_POSITIVE · DGA:HIGH_NAME_ENTROPY

dns_tunnel

DNS_TUNNELHYBRIDno model

dns_domain_length

84 · threshold 60

dns_char_entropy

4.75 · threshold 3.6

dns_payload_length

70

dns_query_count_60s

43

dns_hex_ratio

0.386

dns_txt_ratio_60s

0.302

DNS_TUNNEL:OVERSIZED_QUERY_NAME · DNS_TUNNEL:HIGH_QUERY_ENTROPY · DNS_TUNNEL:DEEP_ENCODED_SUBDOMAIN · DNS_TUNNEL:EXCESSIVE_TXT_QUERIES

tls_malware

TLS_MALWARERULE20260929-1

tls_malware_confidence

0.75

ja4_list_count

3

ja4s_list_count

0 · origin-only capture

tls_sni_present

1

TLS_CURATED_JA4_MATCH · MALICIOUS_JA4_FINGERPRINT · FINGERPRINT_REPEATED_IN_LIST · JA4_MATCH:t12d180700_4b22cbed5bed_2dae41c691ec

One incident, with the arithmetic attached

Six distinct threat classes on one subject inside a 300-second window became one incident. Confidence is combined from the detectors that actually fired; severity is scored separately, because a small event can be certain and still low impact.

confidence = min(0.99, primary + 0.08 × distinct corroborating detectors)

Resolved record: confidence 0.99 · confidence_basis FUSION · severity HIGH · 7 alerts · status NEW. Lineage: detector versions anomaly 1.0.0, c2_beacon 1.0.0, recon 1.0.0, exfiltration 1.1.0; model versions anomaly 20260928-1; event schema 1.1.0; pipeline run 6ec65193bd01. Enough to reproduce the decision, and enough to tell a reader which parts were counted and which were modelled.

The one-way guarantee

A technical property, not a promise.

The boundary is enforced by the absence of a path, and checked by a test that parses the source of every module that touches captured data.

The one-way boundaryCopied traffic moves one way, left to right: monitored network, a boundary plane with a hard stop, then the sensor, the analysis enclave and the operator. A return path is drawn from the sensor side back toward the monitored network and terminates in a block, because no such path exists.Monitored networknothing runs here for TRINETRAcopied ingressOne-way boundarySensorreceive onlyread_only trueHOST_BLOCKEDAnalysis enclavedetection meshOperatorno return path — no socket, no route, no credential

No return path

The intended deployment has no route back into the monitored production network. Signals cross the boundary once. Nothing crosses it the other way, so there is no channel for an attacker who reaches the enclave to use.

No listening socket toward the source

Analysis modules do not open sockets to captured addresses, never probe, never scan and never complete a handshake. It cannot query a source system even if something asked it to.

No credential path

There is no credential to store, rotate, expire or leak toward the protected environment, and no device-control code with a protocol to speak. The output is security intelligence and nothing else.

No decryption

Encrypted traffic is analysed as handshake metadata only: JA4 and JA4S fingerprints, SNI shape, offered ciphers, version, certificate attributes, and size and timing envelopes. Payload content is never present in any stored field.

What the guarantee does not claimThe live demonstration is a software enforcement boundary, not physical diode certification. A trusted privileged host controller provisions the receive interface and reconciles its lifecycle, and a Docker administrator can alter either — both are assumed not to be compromised. The reported boundary state is an infrastructure assertion supported by peer-capture and lifecycle proofs, not a cryptographic attestation. Deployments on TAP/SPAN or real diode hardware need their own boundary verification.

Built for

Networks where there is nothing to install and nothing to answer.

The one-way constraint is not a limitation worked around here. In these environments it is the deployment model, and it is the reason an analysis enclave can be trusted with a copy of the traffic.

Government and defence
Compartmented networks are the canonical unidirectional case. There is no route to push an indicator inward, so detection has to arrive from outside the boundary and be legible to an analyst who cannot query the source.
Critical infrastructure
Process and control networks often cannot carry an agent or tolerate a probe. A passive tap on a mirrored link is the only kind of deployment that fits the equipment as it already is.
OT and ICS
Long patch cycles and flat vendor networks produce long-lived beaconing. Inter-arrival regularity is measurable from copies alone, and the devices never learn that anything is watching them.
Data centres
East-west traffic is where a compromised workload talks to its controller. A span port on the internal fabric sees it. Nothing has to be deployed onto the host, so there is no agent to harden or attest.
Banking and telecom
Segmentation rules and change freezes make inline deployment expensive and slow. Copy-then-analyse keeps the monitored side untouched, which is usually the only option that clears review.
SOC and CERT operations
An analyst needs the evidence and the thresholds behind an alert, not a score. Every result ships with reason codes, baseline comparisons and lineage, so a decision can be defended and re-checked.
Cyber R&D
The detection mesh, the feature contract and the promotion gates are inspectable. A detector is a small program you can read end to end, and a rejected candidate leaves an audit record.

What the constraint rules out

The system cannot act
No inline path and no device-control code. It cannot block, filter or mitigate, and it will not claim to have.
The enclave cannot be pushed into
Indicators, patches and blocks are not delivered outward. TRINETRA publishes; the operator applies, on a network the operator controls.
Nothing is decrypted
Content never leaves the wire. What is read is handshake shape and size, which is also why a TLS match is a lead rather than a verdict.
No model changes itself
Live traffic becomes a candidate and stops there. A champion is a person’s decision, written to the registry with its actor and gate results.

The console

One screen per question an analyst actually asks.

These are the routes in this build, with the endpoints each one reads. Open any of them in the console against your own data — the store, the detector registry and the incident ledger are all live.

Designed around the one-way boundary.

The architecture page walks the whole path — sensor, normalisation, streaming feature engine, baselines, the detection mesh, fusion, evidence — and states where each guarantee comes from.