OptoxShield โ€บ Security Orchestration โ€บ Live Monitor Wizard

Dashboard

MONITORING

Threat Analysis Center Dashboard

Real-time PBX threat telemetry, anomaly detection, and automated SIP mitigation

๐ŸŒ MANAGED PBX SERVER INSTANCES โ— FLEET HEALTH: 100% OPTIMAL
๐Ÿ“ž
โ†‘ 10%
Total Assets / Today Calls
0
๐ŸŽ›๏ธ
โ†‘ 10%
Investigating (60s Windows)
0
โš ๏ธ
โ†“ 0%
Action required (Threats)
0
๐Ÿ›ก๏ธ
โ†‘ 10%
Resolved (Firewall Drops)
LOW
Account Health Summary View All โ†’
0 Total
36 issues
20 Snoozed / Drops
44 Good health
Top alert categories
Malware & INVITE Floods 15
Runtime Detections & Scanners 7
Potentially Unwanted SIP Activity 10
Mobile & Remote Softphone Devices 5
Security Exceptions (Drop Policies) 14
50 100 150 200 250 300 350 400 450 500
Top alert categories & Real-time Call Telemetry Histogram
๐Ÿ“œ CALL LOGS & TELEMETRY STREAM (YESTERDAY & TODAY FROM SQLITE DB)
Date & Time Caller ID Extension Method Context & Source IP Call Status / Hangup State Response
Loading historical call logs from SQLite Database...
๐Ÿ›ก๏ธ
All Systems Normal & Secure SYSTEM SECURE
Attacking Source IP: None | AI Confidence: 100% | Vector: Normal Traffic (No Active Anomaly)
๐Ÿšจ LIVE DETECTED SECURITY INCIDENTS & THREAT HISTORY
Time Attacking IP Threat Class Anomaly Vectors AI Confidence Mitigation Status Action
๐Ÿ›ก๏ธ No active security incidents. System is completely secure.
๐Ÿ›ก๏ธ Active Threat Analysis & Vector Matrix
Threat Class Detection Rule Trigger Threshold Mitigation
INVITE_FLOODHigh-density burst of SIP INVITEs> 15 / 60sAutomated iptables DROP
SIP_SCANNERUser-agent probing (SIPCli / Sipvicious)Pattern MatchAutomated iptables DROP
REGISTER_BRUTE_FORCEFailed SIP extension auth attempts> 3 failed auth / 60sIP Ban (30 Days)
EXTENSION_ENUMERATIONSequential extension range probing> 5 extensions / 60sIP Ban (30 Days)
OPTIONS_FLOODContinuous OPTIONS keep-alive flood> 20 / 60sRate Throttling
TOLL_FRAUDAbnormal international call duration spikesDuration > 180sChannel Hangup
๐ŸŸข Whitelisted IP & Trunk Subnets
Whitelisted IP / CIDR Subnet Security Status Action
Loading whitelisted subnets...
๐Ÿšซ BLACKLISTED CALLER IDS & PHONE NUMBERS AUTOMATED & MANUAL TELECOM REJECTION
Blacklisted Phone Number / Caller ID Security Status Action
Loading blacklisted phone numbers...
๐Ÿง  LightGBM Neural Feature Importance
invite_count_60s
failed_count_60s
register_count_60s
request_rate
unknown_caller_ratio
short_call_ratio
toll_dest_flag
๐Ÿ“Š LightGBM Classifier Architecture
Model EngineLightGBM Decision Trees
Sliding Window Size60 Seconds Window
Inference Step Speed< 2ms Prediction Time
Feature Vector Dimension14 Continuous Features
Training Dataset Size250,000 SIP Packets
Validation Accuracy99.90% Precision
Storage PersistenceSQLite DB (optox_events.db)
๐Ÿ”ฌ Feature Vectors & Anomaly Metrics Breakdown
Feature Name Data Type Weight Signal Target Vector Threshold
invite_count_60sIntegerHIGH (88%)> 15 INVITE requests / 60s
register_count_60sIntegerMEDIUM (75%)> 3 failed auth / 60s
failed_count_60sIntegerHIGH (82%)> 3 authentication 401/403 errors
toll_dest_flagBooleanCRITICAL (92%)International premium prefix (+881 / +882)
short_call_ratioFloat (0-1)INFO (58%)Duration < 5s with unanswered SIP 200
๐Ÿ“Š 48-Hour Call Volume & Threat Metrics

Historical metrics aggregated over 48-hour monitoring windows

Peak Hourly Volume
142 Req / hr
โ†‘ 12.4% normal load
Avg Call Duration
245.5 Sec
Normal PSTN duration
Mitigated Threats
100% Success
0 Dropped legitimate calls
Carriers Monitored
11 Subnets
Plivo & AWS Gateways
๐Ÿ“‘ Security Compliance & Audit Reports

Generate and export official security audit reports for regulatory compliance:

Audit Period Total Events Analyzed Threats Blocked System Health Action
Today (Live) SQLite DB Telemetry Logs 100% MITIGATED HEALTHY
๐Ÿ–ฅ๏ธ Managed Asterisk PBX Backend Servers
๐Ÿ” Operator Access & Password Security

Manage the credentials used to log into this Optox Shield SOC Console.

โš™๏ธ Global Protection Settings
DRY RUN MODE (Active Banning)

When OFF, Optox Shield active mode executes iptables & AMI caller ID hangups.

ACTIVE BANNING (DRY_RUN = FALSE)
IP & CALLER ID BAN DURATION

Automatic ban duration for malicious IPs and blacklisted phone numbers.

30 Days (43,200 Minutes)