CyberShieldCyber-physical threat intelligence

CyberShield

The same cyber threat means different things depending on what it hits. A location spoof on a phone is a wrong turn. On an autonomous vehicle it is a collision. CyberShield reads security telemetry with a language model, then scores the real world consequence for the specific system under review.

What are we protecting?

Pick the system under review. Its autonomy, safety criticality, and exposure decide how a cyber threat turns into a physical one.

Asset type

Each asset carries a baseline autonomy and safety weighting.

Detected threats

Classification and framework mapping produced by the analysis engine, cross referenced against the CISA known exploited vulnerabilities catalog.

No analysis yet

Choose an asset and run an analysis on the Assess tab.

What could happen in the real world?

The translation layer. The same threat carries different consequences depending on this asset's autonomy and safety criticality.

No impact assessment yet

Run an analysis to generate the cyber-physical risk score.

Recommended response

Defensive actions ordered by urgency for this asset. Every action is advisory and needs a human to confirm it.

No response plan yet

Run an analysis to generate a response plan.

Incident report

A shareable summary for human review.

No report yet

Run an analysis to generate a report.

Known exploited vulnerabilities

Pulled from the CISA catalog of vulnerabilities confirmed as exploited in the wild. Any CVE found in your telemetry is checked against it.

Loading

About CyberShield

A cyber-physical threat intelligence prototype.

Built by Ansh Saini

A student at South Brunswick High School, New Jersey. CyberShield is a prototype that detects digital, AI, and autonomous system risks and translates them into real world safety impact.

How it works

Classification is done by Google Gemini, which reads the telemetry and returns structured findings, impact projections, and recommended actions. The telemetry is passed to the model as untrusted evidence, so an injection attempt buried in a log is reported as a finding rather than followed as an instruction.

The risk score is not produced by the model. It is a fixed weighted formula over threat severity, asset criticality, autonomy, physical safety relevance, and exposure, reduced by the level of human oversight. Keeping the arithmetic deterministic means the same finding on the same asset always scores the same, and the weighting can be inspected and argued with.

Vulnerability data comes from the live CISA known exploited vulnerabilities catalog.

Disclaimer. This prototype is for educational, research, and decision support purposes only. It does not remove malware, guarantee containment, or replace qualified cybersecurity, vendor, or incident response guidance. Model output can be wrong. All findings require human verification.