← Back to work

Undergraduate research · software system

SE4999 / 2025 / KDU

WiFiGuardian.

A research prototype for making authorized Wi-Fi security assessment more approachable on Windows—without hiding the systems engineering required to make it dependable.

128 participant survey 4 architectures evaluated PyQt6 + Python
Final prototype / controlled demonstration
WiFiGuardian dashboard showing a controlled audit result, activity log, and AI-assisted remediation guidance.
Final dashboard with controlled demo data and the AI Vulnerability Advisor.

01 / The question

The hard part was never just the interface.

Linux has powerful wireless-auditing tools, but they often demand specialist knowledge and low-level hardware access that is awkward to reach from a Windows workflow. WiFiGuardian investigates how that gap can be narrowed for people who need understandable, guided security assessment.

“How can an intelligent, user-friendly system orchestrate Linux-based security tools from Windows to detect and help mitigate Wi-Fi threats for non-technical users?”

Research question, WiFiGuardian thesis
73.2%

of the 128-person sample had never used the cited security tools.

80.5%

did not know how to respond to a network compromise.

1 focus

Translate complex audit outcomes into clear defensive action.

Survey figures describe this study’s participant sample; they are not population-wide estimates.

02 / The method

Evidence before implementation.

The project used a pragmatist, mixed-method approach: user input and comparative tool review established the problem, then the software artifact and controlled experiments tested a practical response.

01

Listen

A mixed-method survey of 128 participants surfaced the usability and awareness gap around existing Wi-Fi security tools.

02

Test

Established tools and four Windows-to-Linux architectures were evaluated in a controlled lab environment.

03

Build

The evidence informed a PyQt6 research prototype that joins Windows usability with a headless Linux environment.

04

Refine

Iterative testing, root-cause analysis, and regression checks strengthened state management, parsing, setup recovery, and UI stability.

Flowchart of the WiFiGuardian research methodology from question definition through literature review, questionnaire, practical testing, comparison, and gap identification.
Research method: mixed evidence, practical tool testing, and gap identification.

03 / The architecture

Four paths tested. One path refined.

The central research contribution was architectural: QEMU, Hyper-V, WSL2, and VirtualBox were each examined in the tested environment for the hardware access required by the study. The final answer was not the first working virtual machine, but a deliberately refined hybrid system.

01

QEMU

The tested configuration exposed the adapter, but did not meet the monitor-mode hardware requirement.

Not selected
02

Hyper-V

The guest received an abstracted device rather than the low-level USB access needed for the study.

Not selected
03

WSL2

Generic USB pass-through worked, but the tested adapters could not satisfy the monitor-mode requirement.

Not selected
04

VirtualBox

USB pass-through worked; the final design improved the early network setup with NAT and local SSH forwarding.

Selected path
Final architecture / host-to-guest orchestration
Deployment diagram showing the Windows WiFiGuardian GUI managing VirtualBox, SSH orchestration inside a headless Linux virtual machine, and USB Wi-Fi adapter passthrough.
The selected architecture: a Windows interface orchestrates a headless Linux VM, established security toolchain, and compatible USB Wi-Fi hardware.

01 / Windows interface

A familiar control surface

A PyQt6 dashboard presents discovered networks, guided setup, real-time activity, and readable audit outcomes.

02 / Orchestration

A managed headless environment

The Smart Launcher and VMManager prepare the pre-configured Kali environment, check prerequisites, and attach compatible hardware.

03 / State-aware workflow

Interactive tools, made dependable

A persistent SSH connection and parser coordinate the interactive backend without exposing a terminal workflow to the user.

04 / Defensive guidance

Findings translated into action

The optional AI Vulnerability Advisor turns technical outcomes into prioritized explanations, remediation steps, and good-practice advice.

04 / The software

A guided system—not a terminal wrapper.

WiFiGuardian is designed as a single flow: prepare the environment, discover nearby networks, run an authorized assessment, then turn the outcome into a readable report. The Windows UI owns the experience; the isolated Linux environment performs the specialist work in the background.

Four views of the dark WiFiGuardian dashboard showing network discovery, audit controls, activity logs, and AI-assisted guidance.
Dashboard states across discovery, audit, and vulnerability-guidance workflows.
Multi-stage WiFiGuardian setup wizard validating VirtualBox, preparing the virtual machine, selecting a USB Wi-Fi adapter, and confirming setup completion.
First-run setup checks the environment and guides recovery instead of assuming every prerequisite is ready.

05 / The evaluation

Measured improvement, responsibly framed.

Evaluation followed an iterative loop of execution, failure observation, root-cause analysis, fix verification, and regression testing. These outcomes are thesis-reported results from the controlled test environment—not independent production benchmarks.

Four views of the WiFiGuardian results dialog showing detected risks, security impact, prioritized remediation, and defensive best practices.
~30% → >95%workflow reliability in the thesis test environment
30–60s → <1sfailed VM-start detection and recovery handoff
4 / 4defined AI-advice scenarios passed manual qualitative review
01

Workflow orchestration

State-aware automation replaced a fragile early prototype, raising reported workflow reliability from about 30% to over 95% in the thesis test environment.

02

Failure recovery

Failed virtual-machine starts were reduced from a 30–60 second timeout to an under-one-second detection and guided recovery path.

03

Interface stability

A QThread signal-and-slot model removed the cross-thread UI crashes observed during the executed stability tests.

04

AI advisor review

Four defined scenarios passed a manual, qualitative comparison against a pre-defined remediation “golden standard” after prompt refinement.

06 / Scope & responsibility

The boundaries are part of the research.

WiFiGuardian is a functional academic prototype for assessing networks you own or are explicitly authorized to test. It does not claim to create new cryptographic attacks, kernel drivers, packet-injection frameworks, or a custom machine-learning model.

The host-to-VM orchestration runs locally. If the optional AI Advisor is enabled, audit context is sent to Groq’s hosted API for analysis; it is therefore not a fully local feature.

Current research boundary

  • Authorized Wi-Fi assessment and defensive remediation
  • Windows host with a compatible USB Wi-Fi adapter
  • Controlled evaluation, not large-scale field validation
  • No enterprise SIEM integration or mobile deployment
PythonPyQt6VirtualBoxKali LinuxParamikoWifiteGroq API

Research outcome

A systems problem, made legible.

Explore more work →