LIVE — DEPLOYED ON OWNED INFRASTRUCTURE

METHAQ

Intelligent Identity & Access Management with Active Defense — a five-node closed-loop cybersecurity system.

UNIVERSITY OF HAFR AL-BATIN · COLLEGE OF COMPUTER SCIENCE & ENGINEERING · MAY 2026

98.87%
ML Accuracy
118ms
Median Latency
4,710+
Attacks Captured
38
Countries
A+
SSL Labs
99.97%
30-Day Uptime
<18min
Closed Loop
● Online
System Status
5
Active Nodes
⚠️

Static Authentication

Traditional MFA applies the same challenge regardless of threat level. A phished one-time password grants identical access to a legitimate user.

🔕

No Adaptive Learning

Firewalls enforce known signatures. They cannot learn from attack patterns they have never seen before.

🏝️

Siloed Intelligence

Honeypots capture attacks. Identity providers grant access. The two systems never share what they know.

💡

The Methaq Answer

A closed loop that couples honeypot-driven attack intelligence with ML risk authentication — so the identity layer learns from every attack it sees.

ATTACK → CLASSIFY → RETRAIN → ENFORCE · TOTAL CYCLE <18 MIN · 1,000× FASTER THAN MANUAL RESPONSE
~5 min
Capture
Cowrie honeypot records live SSH & Telnet attacks
~2 min
Classify
Ensemble model scores each pattern's risk
~12 min
Retrain
Model refreshes on new attack features with SMOTE
~45 sec
Enforce
Updated thresholds deploy to Methaq IAM
NODE 01
THE FORTRESS
Identity & Access Management
A purpose-built IAM identity provider extended with a custom RiskScoreAuthenticator SPI — turning a static gatekeeper into an adaptive enforcement point that queries the ML engine on every login.
OIDC/PKCESAML 2.0PostgreSQL 16Caddy 2.7TLS 1.3
NODE 02
THE SHIELD
WAF & Public Frontend
The system's public face. Nginx reverse-proxies the application behind ModSecurity and the OWASP Core Rule Set — 917 virtual-patch rules inspecting every request in real time.
Nginx 1.24ModSecurity 3.0OWASP CRSfail2banCloudflare
NODE 03
THE BRAIN
ML Risk Engine
A FastAPI service scoring authentication risk from 15 features. A three-model ensemble returns a verdict in a median of 118ms with 98.87% accuracy.
FastAPI 0.109scikit-learnONNX 1.17SMOTEXGBoost
NODE 04
THE TRAP
Active Defense & Honeypot
A Cowrie honeypot emulates a vulnerable server. Kernel-level iptables redirection makes the trap invisible — capturing 4,710+ events from 38 countries in the first week.
Cowrie 2.6.1Docker 24.0iptablesSSH/Telnet
NODE 05
THE STAGE
Demo Banking Application
A realistic banking interface that exercises the full flow end-to-end — login through Methaq IAM, then the live verdict: access granted, TOTP challenge, or access denied.
Next.js 14oidc-client-tsSQLite 3.42PKCE
🛡️

Zero-trust architecture. Every layer is independently hardened — if any single control fails, another stands behind it.

EDGE
Cloudflare DDoS ProxyDNS Protection
PERIMETER
ModSecurity 3.0OWASP CRS v3.3.5 (917 rules)OWASP ZAP verified
ACCESS
fail2ban progressive blockingUFW default-denyAdmin TOTP MFARBAC
TRANSIT
TLS 1.3 all nodesMutual TLS inter-nodeA+ SSL LabsHSTS enforced
AT REST
LUKS2 full-disk encryptionSHA-256 IP hashingArgon2 passwordsAES-256
IZ
PROJECT ADVISOR
Dr. Ibrahim Al-Zahrani
University of Hafr Al-Batin · College of Computer Science & Engineering
AA
Abdulrahman Al-Anazi
Project Leader & System Architect
MA
Mansour Al-Anazi
Application & OIDC Engineer
AA
Abdulmohsen Al-Anazi
Security & Frontend Engineer
AH
Abdullah Al-Harbi
Frontend & WAF Lead
HA
Hamed Salem Al-Anazi
Infrastructure & IAM Lead
FA
Faisal Al-Harbi
Machine Learning Engineer
AA
Abdullah Al-Anazi
Application Tester & Data Engineer
YA
Yousef Al-Anazi
Active Defense Engineer