Inspiration

Modern networks are increasingly complex, but the tools used to understand them are still fragmented, technical, and reactive. Traditional tools like Nmap provide raw data, but not context or clarity, making it difficult for users to understand what actually matters.

We wanted to build something that goes beyond scanning—a system that interprets network data, highlights real risks, and presents everything in a way that is immediately actionable.

A simple idea inspired Shards: what if you could see your network the way an attacker does—clearly, instantly, and intelligently?

What it does

Shards is an AI-powered network security mapper and defender that transforms raw scan data into actionable insight.

  • Discovers all devices on a network with details like IP, OS, and open ports
  • Assigns each device a risk score based on real security factors
  • Visualizes the entire network as an interactive graph
  • Detects anomalies and highlights potential threats in real time
  • Enables natural language queries for network investigation
  • Provides evidence-backed insights using AI

In seconds, users go from scan → understanding → action.

How we built it

We built Shards as a modular full-stack system combining deterministic security analysis with AI reasoning.

Backend

  • Python + FastAPI
  • Network scanning using Scapy and Nmap
  • Risk scoring and threat detection engine
  • SQLite for structured data storage
  • ChromaDB for vector-based retrieval (RAG)

Frontend

  • Next.js + React + TypeScript
  • D3.js for interactive network visualization
  • WebSockets for real-time updates
  • Tailwind CSS for a clean UI system

AI Layer

  • Retrieval-Augmented Generation (RAG) for context-aware responses
  • Support for both local LLMs (Ollama) and cloud models (Claude)
  • Provider-agnostic abstraction layer

This architecture keeps the system fast, reliable, and scalable while enhancing it with AI where it adds the most value.

Challenges we ran into

Real-time performance vs depth
Collecting detailed network data while keeping scans fast was challenging.
→ Solved through optimized scanning workflows and efficient data handling.

LLM abstraction complexity
Supporting both local and cloud models required a flexible design.
→ Solved with a clean abstraction layer separating AI providers from core logic.

Network visualization
Representing dynamic network topology in a clear and intuitive way was difficult.
→ Solved using a force-directed graph with real-time updates and layout tuning.

System coordination
Keeping backend, frontend, and AI layers in sync required careful design.
→ Solved with modular architecture and clear data boundaries.

Accomplishments that we're proud of

  • Fully functional real-time network mapping system
  • Interactive visualization of network topology
  • Deterministic risk scoring with consistent results
  • AI-powered natural language investigation
  • Seamless integration of traditional security tools with modern AI
  • Clean and intuitive UI for complex data

What we learned

Technical

  • Strong system design is critical for scalability
  • Decoupling components makes development faster and cleaner
  • Combining deterministic logic with AI leads to better reliability

Product

  • Raw data is not enough—context is everything
  • Visualization dramatically improves usability
  • Simplicity is key for adoption in security tools

System Design

  • Clear boundaries between layers reduce complexity
  • Real-time systems require careful performance tradeoffs
  • AI should enhance, not replace, core logic

What's next for Shards

Short-term

  • Improve detection accuracy and risk scoring models
  • Add deeper anomaly detection capabilities
  • Enhance UI for better exploration and filtering

Expansion

  • Multi-network and distributed scanning support
  • Shared dashboards across teams and organizations
  • Compliance reporting (NIST, HIPAA, etc.)

Long-term

  • City-scale network visibility and shared threat intelligence
  • Collaborative cyber defense platform
  • Continuous monitoring with automated response suggestions

Shards — because your network should be understood, not just scanned.

Built With

Share this project:

Updates

Submission history