Skip to content

Usage Guide

SecureNet IDS edited this page Aug 31, 2026 · 1 revision

πŸš€ Usage Guide


Starting the System

Start Backend

# From project root
python backend/main.py

The FastAPI server starts on http://localhost:8000

Start Frontend Dashboard

cd securenet-ui
npm run dev

The React dashboard opens on http://localhost:5173


Dashboard Pages

🏠 Dashboard (Home)

  • Live packet counters (total, malicious, normal)
  • Real-time threat activity chart
  • Active alerts summary
  • System health status

🚨 Alerts

  • Live WebSocket-streamed attack alerts
  • Historical alerts from database
  • Filter by risk level, attack type, time range
  • Manual IP block button on each alert
  • CSV export

🌐 Network Monitor

  • Live traffic table (source IP, dest IP, protocol, size)
  • IP reputation status (monitored, blocked, suspicious)
  • Incoming/outgoing traffic trend chart
  • Admin view: all IPs + full control
  • User view: personal session traffic only

πŸ“‹ System Logs

  • Real-time system event log
  • Filter by level: ALL / INFO / WARNING / ERROR
  • Search by keyword
  • Admin view: system-wide logs
  • User view: personal activity logs

🧠 AI Analysis

  • ML prediction confidence trends
  • Attack type distribution (Pie chart)
  • Model accuracy metrics
  • Threat intelligence summary

πŸ“Š Reports

  • Generate PDF/CSV reports
  • Time range selection
  • Alert, log, and statistics summaries

πŸ”’ Audit Logs (Admin only)

  • Full administrative action trail
  • Filter by action, user, date range
  • CSV export for compliance

πŸ‘₯ Admin Panel (Super Admin only)

  • Organization management (create, suspend, activate)
  • User management (create, assign roles, deactivate)
  • Role-based access control

Starting & Stopping Monitoring

Via Dashboard

  • Click the β–Ά Start Monitoring button on the Dashboard
  • Click ⏹ Stop Monitoring to pause

Via API

# Start monitoring
curl -X POST http://localhost:8000/start-monitoring

# Stop monitoring
curl -X POST http://localhost:8000/stop-monitoring

# Check status
curl http://localhost:8000/status

IP Blacklist Management

Block an IP from the Dashboard

  1. Go to Alerts page
  2. Click the 🚫 Block IP button on any alert
  3. The IP is immediately added to the blacklist

Block an IP via API

curl -X POST http://localhost:8000/blacklist \
  -H "Content-Type: application/json" \
  -d '{"ip_address": "198.51.100.1", "reason": "Brute force attack"}'

Check IP Reputation

curl -X POST http://localhost:8000/check-ip \
  -H "Content-Type: application/json" \
  -d '{"ip_address": "8.8.8.8"}'

WebSocket Real-Time Feed

Connect to the live event stream:

const ws = new WebSocket("ws://localhost:8000/ws");

ws.onmessage = (event) => {
  const data = JSON.parse(event.data);
  // data.type: "alert" | "status" | "stats" | "log"
  console.log(data);
};

Data Export

# Export alerts as CSV
curl http://localhost:8000/export/alerts -o alerts.csv

# Export audit logs as CSV
curl http://localhost:8000/api/v1/reports/audit-logs/export -o audit.csv