๐ก๏ธ Network Guardian AI
Multi-Tenant Security-as-a-Service Platform
๐ Table of Contents
- ๐ Overview
- ๐น๏ธ Core Features
- ๐๏ธ System Architecture
- ๐ง Intelligence Layers
- ๐ฅ Multi-Tenancy
- ๐ณ Billing & Subscriptions
- ๐ Developer API
- ๐จ UI Components
- ๐ Getting Started
- ๐งช Testing
๐ Overview
Network Guardian AI is a real-time network security platform with multi-tenant support. It intercepts DNS queries via AdGuard, performs multi-layered behavioral analysis, and provides threat intelligence through a modern dashboard UI.
Security-as-a-Service: Ready for commercial offering with tenant isolation, billing integration, and tier-based access control.
๐น๏ธ Core Features
- Real-time Threat Detection: Live stream of DNS requests with risk assessments
- Manual Domain Analysis: On-demand analysis with Gemini AI and ML heuristics
- 12-Panel Stats Dashboard: Comprehensive metrics overview (Overview, ML, Alerts, Blocklist, Settings)
- Admin Dashboard: CRM-style tenant management interface
- Usage Tracking: Per-tenant usage analytics and rate limiting
- Developer Portal: API key generation and endpoint documentation
๐๏ธ System Architecture
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Docker Compose โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ โโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ Network Guardian โ โ AdGuard Home โ โ
โ โ (Backend + UI) โ โ (DNS Interceptor) โ โ
โ โ Port: 8000 โ โ Port: 8080, 53 โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Components:
- Frontend: React/TypeScript, served from backend static
- Backend: Python 3.11 / FastAPI
- Database: SQLite with multi-tenant support
- DNS Interceptor: AdGuard Home
- AI: Google Gemini (with local heuristic fallback)
๐ง Intelligence Layers
| Layer | Method | Purpose |
|---|
| Layer 1 | Shannon Entropy | Detects random DGA strings locally |
| Layer 2 | Isolation Forest (ML) | Unsupervised anomaly detection |
| Layer 3 | Gemini AI | Semantic threat analysis |
| Layer 4 | Blocklist Lookup | Known threat database |
๐ฅ Multi-Tenancy
Tenant Management
- Complete Isolation: Each tenant has separate data, API keys, and configurations
- Tenant Middleware: Automatic tenant identification via subdomain, headers, or API key
- Dashboard Switching: TenantSelector component for quick context switching
Subscription Tiers
| Tier | Features | Rate Limit |
|---|
| Free | 100 requests/min | Basic ML heuristics |
| Pro | Unlimited + Gemini AI | Full analysis pipeline |
| Enterprise | Custom + SLA | Priority support |
๐ณ Billing & Subscriptions
Stripe Integration
- Checkout Sessions: One-click subscription upgrade
- Customer Portal: Self-service billing management
- Webhook Handling: Automated tier updates on payment events
- Usage Tracking: Daily and overall stats per tenant
API Endpoints
POST /billing/checkout - Create Stripe checkout session
POST /billing/portal - Get customer portal URL
POST /billing/webhook - Stripe webhook handler
GET /billing/tiers - List subscription tiers
๐ Developer API
Authentication
- API Keys: Per-tenant API key generation
- JWT Support: Token-based authentication
- Rate Limiting: Tier-based request limits
Endpoints
POST /api/v1/analyze - Analyze domain
GET /api/v1/stats - Get tenant statistics
GET /api/v1/history - Get threat history
WS /ws/public - Real-time updates
Rate Limits
| Tier | Requests/Minute |
|---|
| Free | 100 |
| Pro | 1000 |
| Enterprise | Unlimited |
๐จ UI Components
Stats Dashboard (12 Panels)
- Blocklist KB / Known Threats
- Ollama Models / Local AI
- Total Decisions / Analyzed Domains
- Autonomy Score / Local Analysis Rate
- Patterns Learned / ML Model
- Active Alerts / Pending
- Anomaly Model / Training Status
- Sources Active / Blocklist Sources
- Vector Embeddings / Threat Storage
- Entropy Threshold / Dynamic
- Activity Trend Chart
- Category Distribution Pie Chart
Pages
- Dashboard: Main threat monitoring view
- Admin: Tenant management, CRM interface
- Usage: Per-tenant usage analytics
- Pricing: Subscription tier information
๐ Getting Started
1. Environment Setup
cp .env.example .env
# Edit .env with your API keys:
GEMINI_API_KEY=your_key
STRIPE_API_KEY=sk_live_...
STRIPE_WEBHOOK_SECRET=whsec_...
2. Start Services
# Build and start
docker compose up --build -d
# Or just start (if image exists)
docker compose up -d
3. Access
4. Environment Variables
# Core
GEMINI_API_KEY=your_gemini_key
ADGUARD_URL=http://adguard:80
ADGUARD_USER=admin
ADGUARD_PASS=your_password
# Stripe Billing
STRIPE_API_KEY=sk_live_...
STRIPE_WEBHOOK_SECRET=whsec_...
STRIPE_PRO_PRICE_ID=price_...
STRIPE_ENTERPRISE_PRICE_ID=price_...
# Ollama (optional)
OLLAMA_ENABLED=false
OLLAMA_BASE_URL=http://host.docker.internal:11434
OLLAMA_MODEL=nomic-embed-text
OLLAMA_CHAT_MODEL=llama3.2
# Multi-Tenancy
ENVIRONMENT=development # Set to production for production
API_RATE_LIMIT_PER_TENANT=100
DEFAULT_TENANT_ID=1
๐งช Testing
# All tests
PYTHONPATH=. python -m pytest Tests_AI/ -v
# Single test
PYTHONPATH=. python -m pytest Tests_AI/test_heuristics.py -v
# With coverage
PYTHONPATH=. pytest Tests_AI/ -v --cov=backend
# Linting
ruff check backend/ && ruff check backend/ --fix
mypy backend/ --ignore-missing-imports
๐ Project Structure
network-guardian-ai/
โโโ backend/
โ โโโ api/ # FastAPI routes
โ โ โโโ stats.py # Statistics endpoints
โ โ โโโ chat.py # Chatbot
โ โ โโโ billing.py # Stripe billing
โ โ โโโ tenant_router.py
โ โ โโโ developer_router.py
โ โโโ core/
โ โ โโโ config.py # Settings
โ โ โโโ tenant_middleware.py
โ โ โโโ websocket_manager.py
โ โโโ db/
โ โ โโโ models.py # SQLAlchemy models
โ โ โโโ repository.py # Data access
โ โ โโโ database.py # DB connection
โ โโโ logic/
โ โ โโโ ml_heuristics.py
โ โ โโโ anomaly_engine.py
โ โ โโโ metadata_classifier.py
โ โโโ services/
โ โโโ adguard_poller.py
โ โโโ gemini_service.py
โ โโโ blocklist_loader.py
โโโ frontend/
โ โโโ components/
โ โ โโโ Dashboard.tsx
โ โ โโโ StatsPanel.tsx # 12-panel overview
โ โ โโโ AdminDashboard.tsx
โ โ โโโ LoginPage.tsx
โ โ โโโ TenantSelector.tsx
โ โโโ services/
โ โ โโโ tenantService.ts
โ โ โโโ websocketService.ts
โ โโโ App.tsx
โโโ docker-compose.yml # Production
โโโ docker-compose.dev.yml # Development with hot-reload
โโโ Dockerfile # Multi-stage build
โโโ Tests_AI/ # pytest tests
๐ค Built With
- AI/ML: Google Gemini, Scikit-Learn, Shannon Entropy
- Backend: Python 3.11, FastAPI, SQLAlchemy
- Frontend: React 19, TypeScript, Tailwind CSS, Recharts
- Database: SQLite (development), PostgreSQL-ready
- Billing: Stripe
- DNS: AdGuard Home
๐ System Status
- โ
Multi-tenant isolation with complete data separation
- โ
Stripe billing integration with webhook handling
- โ
Developer API with rate limiting
- โ
12-panel stats dashboard
- โ
Admin CRM interface
- โ
Real-time WebSocket updates
- โ
Production Docker deployment