CyberShield
The same cyber threat means different things depending on what it hits. A location spoof on a phone is a wrong turn. On an autonomous vehicle it is a collision. CyberShield reads security telemetry with a language model, then scores the real world consequence for the specific system under review.
What are we protecting?
Pick the system under review. Its autonomy, safety criticality, and exposure decide how a cyber threat turns into a physical one.
Asset type
Detected threats
Classification and framework mapping produced by the analysis engine, cross referenced against the CISA known exploited vulnerabilities catalog.
Choose an asset and run an analysis on the Assess tab.
What could happen in the real world?
The translation layer. The same threat carries different consequences depending on this asset's autonomy and safety criticality.
Run an analysis to generate the cyber-physical risk score.
Recommended response
Defensive actions ordered by urgency for this asset. Every action is advisory and needs a human to confirm it.
Run an analysis to generate a response plan.
Incident report
A shareable summary for human review.
Run an analysis to generate a report.
Known exploited vulnerabilities
Pulled from the CISA catalog of vulnerabilities confirmed as exploited in the wild. Any CVE found in your telemetry is checked against it.
About CyberShield
A cyber-physical threat intelligence prototype.
Built by Ansh Saini
A student at South Brunswick High School, New Jersey. CyberShield is a prototype that detects digital, AI, and autonomous system risks and translates them into real world safety impact.
How it works
Classification is done by Google Gemini, which reads the telemetry and returns structured findings, impact projections, and recommended actions. The telemetry is passed to the model as untrusted evidence, so an injection attempt buried in a log is reported as a finding rather than followed as an instruction.
The risk score is not produced by the model. It is a fixed weighted formula over threat severity, asset criticality, autonomy, physical safety relevance, and exposure, reduced by the level of human oversight. Keeping the arithmetic deterministic means the same finding on the same asset always scores the same, and the weighting can be inspected and argued with.
Vulnerability data comes from the live CISA known exploited vulnerabilities catalog.