shubham.
Resume ↗
Projects/Security

CryptoLens

TLS evidence collection, ML-assisted configuration risk scoring and actionable remediation.

2026

Seven protocol, certificate and transport-security features.

TLS evidence to configuration risk

CryptoLens collects TLS/HTTP configuration evidence, encodes seven features and presents ML-assisted risk assessment with actionable remediation. Python scanning/extraction feeds scikit-learn classifiers; Streamlit provides scan and result views with SQLite/SQLAlchemy persistence.

Protocol/cipher support, certificate properties and HSTS information remain visible alongside the model score. The included evaluation uses demonstration data with synthetic augmentation.

Scan to investigation

  1. TLS probe
  2. Feature extraction
  3. Model inference
  4. Stored scan
  5. Remediation

A shared feature schema connects the scanner, training pipeline and application.

Seven configuration features

Scroll horizontally to compare.

Seven configuration features
FeatureWhat it captures
TLS versionThe negotiated protocol generation.
Cipher suiteThe selected cryptographic suite.
Weak-cipher flagWhether a configured weak-cipher condition is detected.
Forward secrecyThe handshake’s key-exchange characteristic.
Certificate key lengthThe size of the public key represented by the certificate.
Certificate expiry daysThe remaining certificate lifetime.
HSTS supportWhether the HTTP strict-transport header is present.

Model comparison

Gradient Boosting0.9823ROC AUC
Random Forest0.9756ROC AUC

Recorded evaluation on the project’s included synthetic/augmented demonstration dataset. Gradient Boosting was selected by the training workflow.

Engineering decisions

Numerical and categorical encoding provides a consistent feature contract. Random Forest and Gradient Boosting compare decision boundaries over that representation; the included Random Forest has 300 trees. The extractor connects input attributes back to scanner evidence.

Remediation is rule-based guidance tied to weak configuration signals. Stored assessments support review and comparison. Risk scoring prioritizes attention, while protocol versions, certificate details and transport headers explain the configuration itself. Keeping model metadata, feature encoding and evidence separate makes the comparison understandable. The ROC AUC comparison uses the included synthetic/augmented dataset.

↑ ↓ Browse · Enter Open · Esc Close