A full-stack academic network-monitoring project that makes network performance and statistical analysis visible in one responsive operations console. Live Mode uses real Windows ICMP checks for latency, packet loss, and reachability, and reads this computer's adapter traffic rate. Simulation Mode remains available for presentations without a lab network.
- React + TypeScript dashboard with responsive dark UI, traffic/latency charts, device inventory, live alert actions, and reports.
- Express + TypeScript REST API with live Windows ping checks, local interface traffic measurement, optional simulation, a 30-second monitoring cycle, KPI aggregation, health score, alert evaluation, and on-demand checks.
- Statistics: mean, median, variance, standard deviation, coefficient of variation, P25/P50/P75/P90/P95/P99, moving average, trend, Pearson correlation, and Z-score/IQR anomalies.
- MySQL schema including indexed
network_metrics, users, devices, alerts, alert rules, and monitoring logs; a seven-day seed script is included. - Authentication uses bcrypt-backed bootstrap credentials and JWT bearer tokens. Development defaults to
admin@network.local/admin123; setADMIN_EMAIL,ADMIN_PASSWORD, and a strongJWT_SECRETbefore use outside local development. Optional viewer credentials can be configured withVIEWER_EMAILandVIEWER_PASSWORD.
React client → REST API → Express monitoring service → live Windows ICMP probes
└──────────────────────────→ MySQL historical data
The browser accesses only the API. Login is required for all API routes except /api/auth/login; administrator credentials are required for device creation, alert changes, simulation runs, and settings changes. The current session token is held in browser session storage and expires after eight hours. Monitoring state is still in memory; MySQL persistence is planned for the next phase.
- Copy
.env.exampleto.env, set a strongJWT_SECRETand non-defaultADMIN_PASSWORD, and changeMONITORED_TARGETSto IP addresses or hostnames you are authorized to monitor. For example:192.168.1.1,192.168.1.10,google.com. - Run
npm installin the project root. - Run
npm run dev. - Open
http://localhost:5173.
The backend is available at http://localhost:4000. Live Mode is the default (SIMULATION_MODE=false); it monitors 127.0.0.1 if no targets are configured. Set SIMULATION_MODE=true for the built-in demo scenario. To create the database, run mysql -u root -p < database/schema.sql then mysql -u root -p < database/seed.sql.
| Area | Endpoint |
|---|---|
| Dashboard | GET /api/dashboard |
| Devices | GET, POST /api/devices; GET /api/devices/:id |
| Monitoring | GET /api/monitoring/:deviceId; POST /api/monitoring/check/:deviceId |
| Analytics | GET /api/analytics/:deviceId/statistics?metric=latencyMs&method=zscore |
| Alerts | GET /api/alerts; PUT /api/alerts/:id/acknowledge; PUT /api/alerts/:id/resolve |
| Simulation | POST /api/simulation/run |
| Reports | GET /api/reports/daily; GET /api/reports/weekly |
All endpoints except POST /api/auth/login require Authorization: Bearer <token>. The login limiter allows five attempts per IP/email key within fifteen minutes. The current bootstrap users are environment-based; database-backed users will be introduced with persistence.
health = availability×0.30 + latency×0.20 + packet-loss×0.20 + bandwidth×0.20 + errors×0.10.
Latency and packet-loss factor scores are normalized to 0–100 before weighting. Z-score flags |x - μ| / σ > 3; IQR flags values outside Q1 - 1.5×IQR and Q3 + 1.5×IQR. Correlation is Pearson's r and is explicitly presented as association, not causation.
In Simulation Mode, use Run network simulation repeatedly to move the designated access point through normal operation, elevated latency, packet-loss anomaly, offline state, and recovery. In Live Mode, the button becomes Run all checks.
LiveMonitoringService.check() now performs Windows ICMP probes. Download/upload figures are the aggregate rate of the computer running the server—not its maximum internet-plan speed or per-device consumption. They will be near zero while the machine is idle and rise while you stream or download. Per-device traffic requires SNMP counters from managed switches/routers or an installed monitoring agent. Persist checks to network_metrics with parameterized mysql2 queries before production use.
When Windows Mobile Hotspot is enabled, the Hotspot client traffic panel identifies clients on HOTSPOT_SUBNET (by default 192.168.137.0/24) and calculates their own download and upload rates from captured packet bytes. It requires Npcap and Wireshark's tshark.exe. Set TSHARK_PATH if Wireshark is installed elsewhere. The collector does not synthesize client traffic or alter a device's ping-based status.
- Never use the development password or JWT fallback in production. Production startup fails when
JWT_SECRETorADMIN_PASSWORDis missing. - Only monitor systems you own or are authorized to test. Target allowlisting and stronger SSRF protections will be added with the live monitoring repository work.
- Logs contain request method, path, status, and a generic error message; passwords, tokens, and request bodies are not logged.
Database repository integration, persistent history, CSV export, websocket delivery, configurable rules UI, and a topology graph adapter are natural next steps.