I. ABSTRACT — Synapstream engineers the next generation of data infrastructure for public sector entities and enterprise conglomerates. By leveraging state-of-the-art computational models, high-throughput stream processing, and scalable distributed architecture, we bridge the widening gap between legacy government systems and modern analytical frameworks. Our proprietary ecosystems are mathematically verified to deliver highly secure, fault-tolerant, and robust solutions, ensuring absolute data integrity and zero-downtime scalability at an unprecedented global scale.
II. SERVICES & WORK — Our core competencies encompass massive-scale data ingestion, distributed database architecture, out-of-core pipeline engineering, and bespoke creative software design. We continuously synthesize complex, highly fragmented data pipelines into intuitive, hyper-performant front-end applications tailored specifically for mission-critical operations. By unifying raw, unstructured telemetry with advanced real-time visualization heuristics, we empower agencies and enterprise stakeholders with instantaneous, actionable intelligence.
A research-grade network intrusion detection dataset capturing genuine threat actor behavior from the live internet. Powered by a MikroTik honeypot and a continuous 18-Billion flow pipeline, it serves as a foundational replacement for synthetic legacy benchmarks.
Architected robust ISP infrastructure and custom enterprise billing software, currently powering and managing network services for more than 5,300 active clients.
Technical OverviewThis dataset utilizes a proprietary Deterministic Labeling Architecture (DLA) integrated deeply with Zeek Deep Packet Inspection (DPI) to extract complex network semantics in real-time. By applying a NAT-immune, 5-minute bucketed 6-tuple merge, it produces mathematically pure malicious labels with a verified 0% false positive rate for Tier 1 attacks. Additionally, the project features a specialized Feature as a Counter (FaaC) time-series dataset. Engineered via highly parallelized out-of-core DuckDB aggregations, this FaaC pipeline is natively optimized for training complex volumetric LSTM anomaly detectors on massive data scales without memory bottlenecks.
Deployment SpecsThis large-scale deployment completely automates and orchestrates core ISP infrastructure, currently managing robust network operations for over 5,300 active enterprise clients. The architecture integrates a fully custom billing framework with an advanced RADIUS server, ensuring seamless client provisioning, automated usage tracking, and instantaneous policy enforcement. Designed for high availability, the infrastructure guarantees zero-downtime scalability while providing deep operational analytics to optimize overall bandwidth distribution.
A Software and Data Engineering firm working with
Governments, World-Class Datasets and Creative Software solutions.



Dataset Overview — APEX-IDS2026 Architecture
APEX-IDS2026 is a research-grade network intrusion detection dataset engineered directly on live production network infrastructure. Breaking away from the synthetic laboratory environments that produced legacy benchmarks like NSL-KDD, UNSW-NB15, and CIC-IDS2017, this dataset captures genuine, unstructured threat actor behavior directly from the internet background radiation. Utilizing a NAT-immune, 5-minute bucketed 6-tuple merge, our pipeline correlates raw volumetric NetFlows with Zeek Deep Packet Inspection metadata (including payload entropy and inter-arrival times). The result is a mathematically pure, 5-Tier Deterministic Labeling Architecture that guarantees a 0% false positive rate for honeypot-verified Tier 1 attacks.
Implementation — Usage Guidelines
Designed explicitly to circumvent the Out-of-Memory (OOM) failures inherent to traditional Pandas workflows, APEX-IDS2026 provides a highly optimized DuckDB Partitioned Parquet architecture capable of scaling to 18 billion flows natively. For Volumetric Anomaly Detection (such as LSTMs and Transformers), engineers should load the TimeSeries FaaC (Feature as a Counter) partitioned directories to leverage 1-minute bins combined with maximum entropy and kurtosis metrics. For binary or multi-class attack detection architectures, the optimal configuration combines Tier 1 (Honeypot-Verified) positive classes with Tier 4 and 5 (Benign Baseline) negative classes, achieving an evasion-resistant, zero-noise ground truth for modern model training.
Purified dataset available via Zenodo • Raw volumetric data available on request
About this file
This dataset contains verified, volumetric malicious network flows captured directly by Synapstream's deterministic honeypot architecture. These labels are mathematically verified with a 0% false-positive rate, tracking real threat-actor behavior from the live internet.
Data Explorer
Version 1.0 (465 GB)
Summary
APEX-IDS2026 is currently being built as the next-generation gold standard for network intrusion and anomaly detection modeling. The official published purified dataset is available on Zenodo (DOI: 10.5281/zenodo.22013914). We also provide access to the raw volumetric data upon request for specialized academic and enterprise research.
We refuse to build on synthetic foundations. The future of data infrastructure demands absolute mathematical certainty, zero-downtime global scalability, and a brutalist adherence to native performance. We reengineer legacy systems into deterministic data pipelines capable of ingesting the internet's raw background radiation without a single dropped packet. This document serves as the absolute specification of our operational, engineering, and ethical directives.
01Macro Vision & Trajectory
Eradicating Synthetic Baselines
The global machine learning and cybersecurity ecosystems are currently starving on legacy, artificially synthesized datasets (e.g., NSL-KDD, UNSW-NB15). These datasets inherently fail to capture the chaotic, adversarial reality of the modern internet. Our absolute vision is to transition global enterprise models to run exclusively on our mathematically pure, live-captured volumetric flows.
By engineering honeypots directly into tier-1 ISP infrastructure, we are capturing the raw truth of the internet. Our trajectory involves scaling this data-capture architecture across five distinct geographical regions, effectively creating a real-time pulse of global threat telemetry that renders synthetic generation obsolete.
- Phase I: Capture and label 50 Billion verified malicious flows with 0% false positive rates.
- Phase II: Open-source the APEX-IDS foundation to academia to force a paradigm shift in baseline evaluations.
- Phase III: Deploy native API integrations for enterprise Security Operations Centers (SOCs) for real-time model retraining.
02Engineering Directives
Zero-Noise Tolerance
We operate under a strict, unforgiving Zero-Noise policy. In our deterministic data pipelines, a single false-positive label is treated as a critical, systemic failure requiring immediate architectural review. We demand perfect entropy tracking, rigorous 6-tuple aggregation merges, and absolute mathematical purity in every output.
All Synapstream infrastructure must be built natively using out-of-core computational standards. We explicitly forbid relying on high-level, memory-bound tooling. Instead, our systems leverage highly parallelized DuckDB aggregations and strictly partitioned Parquet architectures to circumvent the Out-Of-Memory failures inherent to legacy Python data-science stacks.
Core Technical Mandates
- All label extraction must be Deterministically Derived from verified honeypot payload signatures. No heuristics allowed in ground-truth generation.
- Data pipelines must support Out-Of-Core execution by default. Datasets that cannot be queried on machines with 16GB of RAM are considered architecturally flawed.
- All backend services must be written in strongly-typed, memory-safe languages (Rust/Go) or executed within mathematically verified VM environments.
03Operational Standards
Absolute Security & Integrity
Every system deployed by Synapstream is designed security-first, from bare-metal orchestration down to the application layer. Beyond our foundational data pipelines, we engineer highly-optimized, enterprise-grade software applications. Whether we are architecting bespoke, high-frequency billing frameworks for 5,000+ active enterprise clients, building robust internal operational tooling, or deploying stealth deep-packet inspection nodes, we guarantee zero-downtime availability under extreme adversarial conditions.
We optimize exclusively for mission-critical reliability, native bare-metal performance, and mathematically verified data integrity. Our infrastructure is heavily compartmentalized, employing zero-trust methodologies internally. Every API endpoint, database transaction, and inter-service communication is explicitly authenticated and aggressively rate-limited.
- Redundancy Protocol: All active operational services deploy in N+2 high-availability clusters spanning multiple geographically isolated datacenters.
- Auditing Standards: Every configuration change and deployment is immutable and cryptographically signed.
- Client Data Isolation: Enterprise tenant data is cryptographically separated. We do not aggregate or blend proprietary client data under any circumstances.
Domain Expertise
Built for Institutional & Government-Scale Deployments
Enterprise-Scale Storage & Management Systems
Design and deployment of high-throughput database architectures for large-scale institutional data — including spatial databases, GIS-integrated data lakes, and multi-terabyte Parquet-based storage systems optimized for government and urban planning workloads.
Spatial Data Engineering & Metropolitan Analytics
End-to-end engineering of geospatial data pipelines for urban planning authorities. We deliver structured data environments capable of ingesting, normalizing, and serving multi-source metropolitan datasets — from drone-captured aerial surveys to real-time sensor feeds.
Integrated Hardware & Software Solutions
Full-stack procurement and deployment of integrated IT infrastructure — from server-class hardware and network switching to custom enterprise software. All engagements are compliant with government procurement standards and designed for zero-downtime institutional operations.
Custom Software & ITES Delivery
Bespoke software development and IT-enabled services (ITES) for government and semi-autonomous organizations. Our delivery model covers requirements analysis, system architecture, implementation, and long-term maintenance under SLA-bound operational guarantees.
All engagements comply with national e-GP procurement standards
Key Contacts
Business Consultant &
External Operations Manager
Ashraful Ajam Sijan
Senior Legal Advisor
LLB, LLM — Judge Court, Chittagong
Advocate Muntasir Alam
Inquiries — Engineering & Data Solutions
Synapstream engineers mission-critical software solutions and high-throughput data infrastructure for enterprise and government partners. Submit your inquiry to discuss bespoke engineering engagements, API access, or enterprise integration.
Synapstream
Engineering the next generation of data infrastructure and creative software solutions for governments and enterprise conglomerates.
"Debugging Humanity" — Jalal Uddin (ju4700)