Network malware analysis / Systems
Reading a network as a set of relationships.
A C++ log-analysis project using sorting, search trees, and graph relationships to investigate infection pathways.
- My role
- C++ / algorithms development
- When
- 2024
- Built with
- C++ · Graphs · Binary search trees · Sorting algorithms · File handling

Explore how it works
Try it yourself ↓Follow the connections hidden in a log.
Move through a sample timeline, select a system, and trace its outgoing connections.
| Time | Source | Destination |
|---|---|---|
| 09:01 | 192.0.2.10 | 192.0.2.20 |
| 09:02 | 192.0.2.10 | 192.0.2.30 |
| 09:04 | 192.0.2.20 | 192.0.2.40 |
| 09:05 | 192.0.2.30 | 192.0.2.40 |
| 09:07 | 192.0.2.40 | 192.0.2.50 |
| 09:08 | 192.0.2.50 | 192.0.2.20 |
| 09:11 | 192.0.2.20 | 192.0.2.30 |
| 09:13 | 192.0.2.10 | 192.0.2.50 |
Invented logs and documentation IP addresses explain sorting and graph traversal. A connection is evidence of contact, not proof of infection. No network is scanned.
The challenge
A sequence of log lines can hide the connections between systems. I explored how data structures could organize network events and make possible infection paths easier to investigate.
How I built it
Create a searchable structure
I organized log entries by date and IP address with custom sorting and binary search trees.
Model the connections
Graph structures represented relationships between systems to support tracing potential infection paths and origins.
What came out of it
A practical application of C++ data structures to network-log investigation, with an emphasis on how sorting and graph modeling change the questions a dataset can answer.
Sources & project context
- Original portfolio case study, reviewed October 2026