Skip to main content

Auto DefenceX : Autonomous Cybersecurity Monitoring Tool Using Swarm Intelligence

Page 1


International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072

Auto DefenceX : Autonomous Cybersecurity Monitoring Tool Using Swarm Intelligence

1,2,3

Dept. of Artificial Intelligence and Machine Learning, DY Patil Polytechnic, Ambi, Pune, Maharashtra, India 4(Guide) Assistant Professor, Department of Artificial Intelligence and Machine Learning, DY Patil Polytechnic, Ambi, Pune, Maharashtra, India

Abstract - The increasing reliance on interconnected digital infrastructures has significantly exposed small and medium-scale organizations to Cybersecurity threats such as unauthorized access, open-port exploitation, insider misuse, and advanced persistent threats (APTs). Conventionalsecuritymechanismsoftenoperateinisolation and lack integrated automated response capabilities, while enterprise-grade solutions remain financially and operationallycomplexforsmallerenvironments.

This paper presents AutoDefenceX, an autonomous Cybersecurity monitoring tool based on swarm intelligence principles. The proposed system integrates deterministic LAN-based device discovery using synchronous ARP execution, structured port-level vulnerability assessment, and secure real-time alert dissemination through authenticated WebSocket communication. A dedicated SwarmAgentmodulefunctionsastheorchestrationengine, enablingdistributedendpointmanagementandAutomated Incident Response Orchestration (AIRO), including node isolation and structured incident notification during threat detection.

The architecture follows a three-tier model comprising a React-based presentation layer, an asynchronous FastAPI backend, and a relational database layer. The system incorporates secure authentication mechanisms usingJSON Web Tokens (JWT), role-based access control (RBAC), and email-based two-factor verification. A hybrid monitoring model combining real-time host telemetry and structured internal vulnerability mapping enhances operational stabilityanddemonstrationreliability.

Experimental validation in a controlled LAN environment demonstrates consistent device discovery, secure communication handling, and responsive threat visualization, making the system suitable for small and medium-scaleenterprisedeployments.

Key Words: Autonomous Cybersecurity, Swarm Intelligence, Incident Response Orchestration, LAN Discovery, WebSocket Security, Role-Based Access Control, Threat Intelligence, Network Monitoring

1. INTRODUCTION

The rapid expansion of digital infrastructures has significantly increased Cybersecurity risks for small and medium-scale enterprises (SMEs). Common threats include unauthorized access, open-port exploitation, insider misuse, and advanced persistent threats (APTs). Many organizations rely on isolated monitoring tools that generate alerts but lack automated response capabilities. Enterprise-grade SIEM and SOAR solutions are often costly and complex, making them unsuitable for smaller environments.

In addition to technical vulnerabilities, human error remains a major contributor to security breaches due to insufficient awareness integration within operational systems.

To address these challenges, this paper proposes AutoDefenceX, an autonomous Cybersecurity monitoring tool based on swarm intelligence principles. The system integrates deterministic LAN-based discovery, structured vulnerability assessment, secure WebSocket-based realtime alerting, and automated incident response orchestration within a three-tier architecture. The objectiveistoprovideascalable,secure,andcost-effective CybersecurityframeworktailoredforSMEenvironments.

1.1 Problem Statement

Small and medium-scale organizations often lack affordable and autonomous Cybersecurity monitoring mechanisms.Existingtoolseitherprovideisolatedalerting systems or require complex infrastructure and financial investment.

Key challenges include:

 Lackofautomatedincidentresponse.

 Fragmentedendpointmonitoring.

 Delayedthreatvisualization.

 Limitedaccesscontrolenforcementacross distributedsystems.

 Inabilitytocoordinatemultipleendpoints underaunifiedmonitoringmodel.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072

There is therefore a need for an integrated Cybersecurity frameworkcapableofdeterministicLAN discovery,secure real-time communication, distributed endpoint coordination,andautomatedthreatmitigation.

1.2 Objective

The primary objective of AutoDefenceX is to develop an autonomous Cybersecurity monitoring framework that integrates real-time detection and automated response mechanisms.

Specificobjectivesinclude:

• ToimplementdeterministicLAN-baseddevice discovery.

• Toperformstructuredport-levelvulnerability assessment.

• TodesignaSwarmAgentcapableofdistributed endpointcoordination.

• ToimplementAutomatedIncidentResponse Orchestration(AIRO).

• ToensuresecureauthenticationusingJWTand role-basedaccesscontrol.

• Toenablereal-timealerttransmissionusing authenticatedWebSocketcommunication

2. LITERATURE REVIEW

Recent research in cybersecurity monitoring systems has focused on intrusion detection frameworks, centralized log analysis platforms, and automated response mechanisms. Traditional Intrusion Detection Systems (IDS) primarilyrelyonsignature-basedoranomaly-based traffic analysis to detect suspicious activities within a network environment. However, many IDS implementations generate alerts without providing automated mitigation capabilities, requiring manual interventionbysecurityadministrators.

Security Information and Event Management (SIEM) systems have been widely used for centralized log aggregationandeventcorrelation.Theseplatformsenable security analysts to monitor large volumes of system and network events. Despite their capabilities, SIEM solutions often involve complex infrastructure requirements and high operational costs, which limit their usability in small andmedium-scaleenterpriseenvironments.

Recent advancements in cybersecurity research have introduced Security Orchestration, Automation, and Response (SOAR) systems. These frameworks integrate automated workflows to respond to detected security incidents. While SOAR solutions enhance response automation, they frequently depend on predefined playbooksandexternalintegrations,makingthemdifficult todeployinsmallernetworkenvironments.

Swarm intelligence has also been explored in distributed monitoring systems to coordinate multiple nodes for collective decision-making. By applying swarm-based coordination principles, distributed security agents can collaboratively analyse system behaviour and identify anomalouspatternsacrossmultipleendpoints.

Despite these developments, there remains a need for an integrated cybersecurity monitoring system capable of deterministic LAN discovery, real-time alert dissemination, and automated incident response orchestration within a lightweight and scalable architecture.

3. PROPOSED SYSTEM

The proposed AutoDefenceX framework is designed as an autonomous Cybersecurity monitoring tool leveraging swarm intelligence principles for distributed endpoint coordinationandautomatedthreatresponse.

The system performs deterministic LAN-based device discovery using synchronous ARP execution to obtain a stable network snapshot. Identified endpoints are subjectedtostructuredport-levelvulnerabilityassessment todetectpotentiallyexposedservices.

A Swarm Agent module acts as the coordination engine, enablingcentralizedmonitoringofmultipleendpointsasa distributed security cluster. Upon detecting abnormal conditions, the Automated Incident Response Orchestration (AIRO) mechanism initiates structured mitigation workflows such as alert generation and controlledresponsehandling.

Secure communication is ensured through JSON Web Token (JWT) authentication and authenticated WebSocket channelsforreal-timealertdissemination. Theproposedsystemintegratesmonitoring,orchestration, and secure access control within a modular architecture tailoredforSMEenvironments.

4. SYSTEM ARCHITECTURE

TheAutoDefenceXplatformfollowsastructuredthree-tier architecture designed to provide scalable cybersecurity monitoring, distributed endpoint coordination, and automatedincidentresponsecapabilities.Thearchitecture integrates a frontend monitoring interface, a backend orchestration engine, and a centralized data management layertoensureefficientcommunicationandthreatanalysis acrossthemonitorednetworkenvironment.

The presentation layer is implemented using a web-based dashboardthatallowsadministratorsandauthorizedusers to monitor system activity, view alerts, and manage endpoints. The interface provides visualization of security metrics, network status,andreal-time threat notifications.

2395-0056

Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072

This layer acts as the primary interaction point between the user and the underlying cybersecurity monitoring framework.

The application layer functions as the core intelligence component of the system. It is responsible for handling authentication, coordinating endpoint monitoring tasks, performing vulnerability assessments, and executing automated response workflows. The backend services processincomingsystemdata,analyzesecurityevents,and trigger appropriate defensive actions through the AIRO (AutomatedIncidentResponseOrchestration)mechanism. The Swarm Agent model allows multiple endpoints to operate as distributed monitoring nodes, enabling collaborativethreatawarenessacrossthenetwork.

The data layer manages persistent storage of system logs, endpoint information, security policies, and forensic records. A structured relational database maintains records of network scans, detected vulnerabilities, authentication sessions, and historical incident logs. This ensures traceability and enables administrators to review pastactivitiesforforensicanalysis.

Communication between the frontend and backend components occurs through secure API endpoints, while real-time alerts and monitoring updates are delivered through authenticated WebSocket channels. This communication model enables continuous monitoring withoutrequiringmanualrefreshoperations.

Overall, the architecture ensures modular design, scalable monitoring capabilities, and secure interaction between distributed network components. By combining swarmbased endpoint coordination with automated response mechanisms, AutoDefenceX provides a unified framework for proactive cybersecurity monitoring and incident management.

4.1 Swarm Coordination Mechanism

The AutoDefenceX platform implements a swarm-based coordination model to enhance distributed threat awareness and operational scalability. Each connected endpoint operates as a lightweight monitoring agent that continuously reports system metrics, security events, and anomaly indicators to a centralized Swarm Controller. Ratherthanfunctioningasapurelycentralizedmonitoring system, the controller aggregates intelligence from multiplenodesandperformscontextualthreatcorrelation acrosstheentirenetwork.

This swarm-oriented design enables synchronized defensive behaviour, where detection on one node can influence monitoring sensitivity or response actions on other connected endpoints. The architecture reduces dependency on a single detection source and improves resilience against partial system compromise. By supporting distributed intelligence aggregation and centralized orchestration, the swarm mechanism allows the system to scale efficiently across multiple endpoints while maintaining coordinated and real-time defensive capabilities.

4.2 Autonomous Incident Response Validation

ToevaluatetheoperationalreliabilityoftheAutoDefenceX platform, controlled threat simulations were conducted within a monitored LAN environment. The validation scenarios included privilege escalation attempts, unauthorized access outside defined operational hours, suspicious process execution,and abnormal network port exposure. These scenarios were intentionally triggered to test the real-time detection accuracy and automated responsecapabilitiesoftheAIROengine.

During testing, the system demonstrated the ability to detect anomalous behavior and initiate automated containment procedures without manual intervention. Upon threat confirmation, the AIRO module executed predefined defensive actions, including endpoint isolation logic, forensic data capture initiation, and administrative alert generation. Response latency was measured from eventdetectiontocontainmentexecution,confirmingthat thesystemperformsactivedefensiveorchestrationrather thanpassivealertmonitoring.

The validation results establish that AutoDefenceX not only identifies potential security threats but also enforces immediate corrective measures, strengthening network resilience and minimizing the impact window of internal securityincidents.

Fig -1:SystemArchitectureofAutoDefenceX

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072

4.3 Threat Model and Security Assumptions

The threat model of AutoDefenceX is defined based on realistic security risks commonly observed in small and medium-scale enterprise environments. The system assumes the presence of internal and semi-trusted users operating within a controlled Local Area Network (LAN). Potential threats include unauthorized access attempts, privilege escalation by authenticated users, lateral movement between endpoints, abnormal process execution,andexposureofvulnerableserviceports.

The model considers that endpoints may be partially compromised but remain reachable within the monitored network. The Swarm Agent framework is designed to detect anomalous behavior patterns across distributed nodes rather than relying solely on isolated endpoint alerts. Trust boundaries are established between authenticated administrative users and monitored endpoints through JWT-based verification and role-based accesscontrolenforcement.

It is assumed that the underlying operating system and networkinfrastructureremainoperationalandthatsecure communication channels are protected through HTTPS and authenticated WebSocket connections. While the system focuses on internal network monitoring and coordinated response, external distributed denial-ofservice (DDoS) attacks and large-scale internet-facing adversarial campaigns fall outside the immediate operationalscopeofthecurrentimplementation.

This threat modelling approach ensures that AutoDefenceX addresses practical internal security risks while maintaining realistic operational assumptions for SME-levelCybersecuritydeployments.

5. METHODOLOGY

ThedevelopmentofAutoDefenceXfollowsastructured andsystematicapproach:

 Requirement Analysis – Identification of SME Cybersecuritychallengesandsystemobjectives.

 System Design – Development of layered architectureandsecurecommunicationmodel.

 Swarm Intelligence Model Design –Implementation of distributed endpoint coordinationlogic.

 Security Integration – Deployment of JWT authentication, RBAC enforcement, and secure WebSocketvalidation.

 Implementation – Development using FastAPI backend, React frontend, and relational database structure.

 Testing and Evaluation – Validation under controlled LAN environments for device

discovery, vulnerability detection, and alert response.

Thismethodologyensuresreliability,modularity,and secureoperationalbehaviouroftheproposedsystem

6. SYSTEM REQUIREMENTS

Hardware Requirements:

TheproposedAutoDefenceXsystemisdesignedtooperate on standard computing infrastructure suitable for small and medium-scale enterprise environments. A multi-core processor such as Intel Core i5 or equivalent is recommended to support concurrent network scanning andbackendprocessingtasks.

A minimum of 8 GB RAM is required to ensure smooth execution of asynchronous services, WebSocket communication, and database operations. For efficient storage of scan logs, forensic records, and endpoint data, atleast256GBSSDstorageisrecommended.

The system does not mandate dedicated GPU hardware; however, optional GPU support can enhance performance ifadvancedneural-basedthreatsimulationsareintegrated infutureexpansions.

Software Requirements:

The frontend of the system is developed using React.js to provide an interactive and responsive monitoring interface. The backend is implemented using Python with the FastAPI framework to support asynchronous request handlingandsecureAPIcommunication.

The system utilizes SQLAlchemy as an Object-Relational Mapping (ORM) layer for structured database interaction. Secure authentication is implemented using JSON Web Tokens(JWT)andemail-basedtwo-factorverification. The platform can be deployed on a standard Linux-based server environment with support for HTTP and HTTPS protocols.

7. INNOVATION AND CORE CONTRIBUTION

The proposed AutoDefenceX system introduces a novel autonomous swarm-based Cybersecurity monitoring frameworktailoredforsmallandmedium-scaleenterprise environments. Unlike traditional monitoring tools that operate in passive detection mode, the proposed system integrates distributed coordination and automated responsemechanismswithinaunifiedarchitecture.

The primary innovation lies in the Swarm Agent model, which enables coordinated endpoint monitoring across multiple network nodes. Instead of treating endpoints

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072

independently, the system applies swarm intelligence principles to collectively evaluate threat patterns and generatestructuredincidentresponses.

Another significant contribution is the implementation of AutomatedIncidentResponseOrchestration(AIRO).Upon detection of suspicious behavior, the system can trigger predefined response mechanisms, reducing dependency onmanualadministrativeintervention.

Additionally, the secure WebSocket authentication handshake mechanism ensures real-time alert propagation while maintaining strict token validation, enhancingcommunicationintegrity.

The hybrid monitoring approach combining deterministic LAN discovery with structured internal vulnerability mappingfurtherstrengthensreliabilitywithoutrelyingon externalAPIdependencies.

These contributions collectively differentiate AutoDefenceX from conventional monitoring systems by introducing autonomy, distributed coordination, and secure real-time orchestration within SME-level Cybersecurityframeworks.

8. RESULT AND DISCUSSIONS

The AutoDefenceX framework was implemented and evaluated within a controlled Local Area Network (LAN) environment to validate device discovery, vulnerability

assessment, real-time alerting, and incident response orchestration.

The deterministic ARP-based discovery mechanism successfully identified active endpoints within the network snapshot, as illustrated in Fig. 5. The system demonstrated stable endpoint enumeration without dependencyonexternalscanningtools.

The administrative monitoring dashboard (Fig. 4) provides centralized visualization of endpoint status, session activity, and security posture metrics. The Swarm Agent coordination logic enabled structured evaluation of distributedendpointsunderaunifiedmonitoringmodel.

The Digital Forensics module (Fig. 6) recorded structured event logs including login attempts, user actions, and systemactivities,ensuringaccountabilityandtraceability. TheSecurityIntelligenceDashboard(Fig.2)confirmsrealtime threat visualization and authenticated WebSocketbasedalertpropagationacrosssecuredsessions.

The secure multi-factor authentication interface (Fig. 3) demonstrates enforced access control prior to dashboard interaction,ensuringprotectedadministrativeaccess. Performance evaluation results summarized in Table 1 indicate stable LAN discovery time, responsive alert propagation (<1 second), and high WebSocket connection reliability. The system maintained secure access enforcement using JWT authentication and role-based accesscontrolmechanisms.

The experimental validation confirms that the proposed architecture provides reliable monitoring, coordinated endpoint management, and secure real-time threat visualization suitable for SME-level Cybersecurity environments.

Fig -4 AdministrativeDashboardforReal-TimeEndpoint Monitoring

Volume: 13 Issue: 03 | Mar 2026 www.irjet.net

9. CONCLUSIONS

AutoDefenceX presents an autonomous swarm-based Cybersecurity monitoring framework designed for small and medium-scale enterprise environments. The system integrates deterministic LAN discovery, structured vulnerability assessment, and real-time alert disseminationwithinasecurethree-tierarchitecture.

The Swarm Agent model and Automated Incident Response Orchestration (AIRO) mechanism enable coordinated endpoint monitoring and structured threat mitigation, reducing reliance on manual intervention. Secure JWT authentication and authenticated WebSocket communication ensure integrity and controlled access acrossdistributedcomponents.

Experimental evaluation in a controlled LAN setup demonstrates stable device discovery, responsive alert propagation, and secure session management. The proposed framework provides a scalable, cost-effective, and autonomous Cybersecurity solution suitable for SME deployments.

ACKNOWLEDGEMENT

The authors would like to express their sincere gratitude to Prof. Akshay Bhabad, Department of Artificial Intelligence and Machine Learning, DY Patil Polytechnic, Ambi, Pune, for his continuous guidance, constructive feedback, and technical mentorship throughout the developmentoftheAutoDefenceXframework.Hisinsights insystemdesign,Cybersecurityprinciples,andstructured research methodology significantly contributed to the successfulcompletionofthiswork.

The authors are also thankful to the Department of Artificial Intelligence and Machine Learning and DY Patil Polytechnic, Ambi, Pune, for providing the necessary infrastructure, laboratory facilities, and academic environment required to carry out experimentation, implementation, and validation under controlled network conditions.

The graphical outputs presented in Fig. 2–5 demonstrate theoperationalworkflowoftheproposedsystem.TheLAN discovery interface visualizes active network endpoints, while the vulnerability panel highlights detected open portsandassociatedrisk levels.TheSwarmAgentmodule generates structured automated responses during simulated threat conditions. Real-time alert notifications confirmsecureandimmediatethreatdisseminationacross authenticatedsessions.

Furthermore, the authors appreciate the support and encouragement provided by faculty members and peers, which helped in refining the architecture, testing procedures, and documentation of the proposed autonomousCybersecuritymonitoringsystem.

REFERENCES

[1] J. Kennedy and R. Eberhart, “Particle Swarm Optimization,” Proceedings of IEEE International Conference on Neural Networks, vol. 4, pp. 1942–1948, 1995.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072

[2]IETF,“TheWebSocketProtocol,”RFC6455,Dec.2011.

[3]M.Jones,J.Bradley,andN.Sakimura,“JSONWebToken (JWT),”RFC7519,May2015.

[4]W.Stallings, Network SecurityEssentials:Applications andStandards,6thed.,Pearson,2017.

[5]GartnerResearch,“SecurityOrchestration,Automation andResponse(SOAR)MarketGuide,”2020.

[6]S. Kumar, A. K. Singh, and R. Kumar, “Advanced Persistent Threat Detection Using Behavioral Analysis,” IEEEAccess,vol.8,pp.123456–123468,2020.

[7] MITRE Corporation, “MITRE ATT&CK Framework,” Available:https://attack.mitre.org

[8] FastAPI Documentation, “FastAPI Framework,” Available:https://fastapi.tiangolo.com

BIOGRAPHIES

MR. KARTIK BORADE

 Final Year Diploma Student, Artificial Intelligence andMachineLearning

 DYPatilPolytechnic,Ambi,Pune

 Interested in Cybersecurity, Network Monitoring, andAI-basedSecuritySystems

MR. SWAPNIL KOLSE

 Final Year Diploma Student, Artificial Intelligence andMachineLearning

 DYPatilPolytechnic,Ambi,Pune

 Interested in UI/UX Design and Frontend Development

MR. SHUBHAM DHOKRAT

 Final Year Diploma Student, Artificial Intelligence andMachineLearning

 DYPatilPolytechnic,Ambi,Pune

 Interested in Secure System Design and Database Management

PROF. AKSHAY BHABAD

 Head Of Department and Assistant Professor ArtificialIntelligenceandMachineLearning

 DYPatilPolytechnic,Ambi,Pune

 AcademicGuide

Turn static files into dynamic content formats.

Create a flipbook
Auto DefenceX : Autonomous Cybersecurity Monitoring Tool Using Swarm Intelligence by IRJET Journal - Issuu