Lightweight Network Anomaly Detector

Job ID: 40081178

Budget: $250 – $750 USD

I want to commission a compact, resource-friendly network anomaly detection tool that small business sites, MSP-managed customer networks, and isolated enterprise segments can run without a full Security Operations Center. The purpose is simple: watch day-to-day traffic, learn what “normal” looks like, and raise the flag the moment scanning attempts, lateral movement, or any other unusual connection pattern shows up.

Key capabilities I need built in
• Baseline learning: continual profiling of hosts, ports, and flow volumes so the system becomes smarter—without manual tuning—over the first few days.
• Event detection: rule- or model-based logic that spots the three behaviours above early, before they blossom into an incident.
• Alerting: every finding must land simultaneously in the local system log, an emailed notification, and a lightweight web or GUI dashboard so a non-SOC administrator can act right away.
• Footprint: must install on modest hardware (think a small VM or a Raspberry Pi-class box) and stay lean on CPU and memory.
• Deployment flexibility: the same build should slide into those three network types with only minor config changes.

Technology is up to you—Suricata, Zeek, a Python or Go service backed by scikit-learn or similar; just keep it open, auditable, and easy to maintain. Deliverables are:
1. Source code or reproducible build scripts.
2. Installation guide that a junior admin can follow.
3. A quick-start playbook showing how to verify baseline learning, trigger a test scan, and observe email, log, and dashboard alerts.

I’ll test acceptance by spinning it up in a lab, feeding pcap traffic, and confirming the tool detects the defined behaviours with low false-positive noise. If that sounds in your wheelhouse, let’s talk timeline and milestones.