Abstract

Rising numbers of cyber threats require real-time, intelligent IDSs that are not only based on signatures or shallow ML models. Such systems often provide poor generalisation and high false alarms, especially in cases involving more complex temporal dependencies in network traffic. Although recent developments in deep learning offer new opportunities, many of these models struggle to capture the geographical and temporal characteristics of cyber threats, making them less applicable in real-time detection environments. In response to these concerns, this study presents CyberNet-IDS, an AI-based framework for detecting cyberattacks in real time, using a simulated deep-learning hybridisation approach. We integrate a 1-dimensional CNN to abstract spatial network data and BiLSTM networks to model temporal dependencies in network traffic in our framework. Stable preprocessing methods, such as normalisation, median imputation, and an XGBoost-based feature selection process, further enhance the model. CyberNet-IDS is deployed using Apache Kafka and TensorFlow Serving, supporting the streaming of real-time packet data and classification. Through extensive experimentation on the CIC-IDS2017 dataset, we demonstrate that CyberNet-IDS outperforms traditional and existing DL-based IDSs. A well-performing detection model with a reduced false alarm rate is obtained, achieving 97.30% classification accuracy, 96.80% precision, 96.20% recall, and 96.50% F1-score. Therefore, this proposed framework addresses the fundamental issues faced by current IDS solutions and provides a scalable, deployable architecture to secure modern networks against ever-evolving cyber threats instantly.

Keywords

Cyber Attack Detection, IDS, DL, CNN-BiLSTM, Real-Time Network Security,

Downloads

Download data is not yet available.

References

  1. M.V.O. De Assis, L.F. Carvalho, J.J.P.C. Rodrigues, J. Lloret, M.L. Proença Jr, A near real-time security system utilizing a convolutional neural network is applied to Software-Defined Networking (SDN) environments in Internet of Things (IoT) networks. Computers & Electrical Engineering, 86, (2020) 106738. https://doi.org/10.1016/j.compeleceng.2020.106738
  2. N. Garcia, T. Alcaniz, A. González-Vidal, J. B. Bernabe, D. Rivera, A. Skarmeta, Distributed real-time SlowDoS attacks detection over encrypted traffic using Artificial Intelligence. Journal of Network and Computer Applications, 173, (2021) 102871. https://doi.org/10.1016/j.jnca.2020.102871
  3. J. Karande, S. Joshi (2020). Real-Time Detection of Cyber Attacks on IoT Devices. 11th International Conference on Computing, Communication and Networking Technologies (ICCCNT), IEEE, India. https://doi.org/10.1109/ICCCNT49239.2020.9225487
  4. S. Tsimenidis, T. Lagkas, K. Rantos, Deep learning in IoT intrusion detection. Journal of Network and Systems Management, 30(1), (2022) 8. https://doi.org/10.1007/s10922-021-09621-9
  5. M.Q. Tran, M. Elsisi, M.K. Liu, V.Q. Vu, K. Mahmoud, M.M. Darwish, A.Y. Abdelaziz, M. Lehtonen, Reliable deep learning and IoT-based monitoring system for secure computer numerical control machines against cyber-attacks with experimental verification. IEEE Access, 10, (2022) 23186 – 23197. https://doi.org/10.1109/ACCESS.2022.3153471
  6. M.S. Abdalzaher, M.M. Fouda, H.A. Elsayed, M.M. Salim, Toward secured IoT-based smart systems using machine learning. IEEE access, 11, (2023) 20827-20841. https://doi.org/10.1109/ACCESS.2023.3250235
  7. M.M. Lopez, S. Shao, S. Hariri, S. Salehi, (2023) Machine learning for intrusion detection: Stream classification guided by clustering for sustainable security in iot. In Proceedings of the Great Lakes Symposium on VLSI, 691 – 696. https://doi.org/10.1145/3583781.3590271
  8. V. Hnamte, H. Nhung-Nguyen, J. Hussain, Y. Hwa-Kim, A novel two-stage deep learning model for network intrusion detection: LSTM-AE. IEEE Access, 11, (2023) 37131-37148. https://doi.org/10.1109/ACCESS.2023.3266979
  9. J. Du, K. Yang, Y. Hu, L. Jiang, NIDS-CNNLSTM: Network intrusion detection classification model based on deep learning. IEEE Access, 11, (2023) 24808-24821. https://doi.org/10.1109/ACCESS.2023.3254915
  10. T. Yi, X. Chen, Y. Zhu, W. Ge, Z. Han, Review on the application of deep learning in network attack detection. Journal of Network and Computer Applications, 212, (2023) 103580. https://doi.org/10.1016/j.jnca.2022.103580
  11. Sydney Mambwe Kasongo, A deep learning technique for intrusion detection systems using a Recurrent Neural Network-based framework. Computer Communications, 199, (2023) 113-125. https://doi.org/10.1016/j.comcom.2022.12.010
  12. A. Abdelkhalek, M. Mashaly, Addressing the class imbalance problem in network intrusion detection systems using data resampling and deep learning: A. Abdelkhalek, M. Mashaly. The journal of Supercomputing, 79(10), (2023) 10611-10644. https://doi.org/10.1007/s11227-023-05073-x
  13. S. Hore, J. Ghadermazi, A. Shah, N.D. Bastian, A sequential deep learning framework for a robust and resilient network intrusion detection system. Computers & Security, 144, (2024) 103928. https://doi.org/10.1016/j.cose.2024.103928
  14. M. Maddu, YN. Rao, Network intrusion detection and mitigation in SDN using deep learning models. International Journal of Information Security, 23(2), (2024) 849-862. https://doi.org/10.1007/s10207-023-00771-2
  15. N.O. Aljehane, H.A. Mengash, M.M. Eltahir, F.A. Alotaibi, S.S. Aljameel, A. Yafoz, R. Alsini, M. Assiri, Golden jackal optimization algorithm with deep learning assisted intrusion detection system for network security. Alexandria Engineering Journal, 86, (2024) 415-424. https://doi.org/10.1016/j.aej.2023.11.078
  16. K. Roshan, A. Zafar, S.B.U. Haque, Untargeted white-box adversarial attack with heuristic defence methods in real-time deep learning based network intrusion detection system. Computer Communications, 218, (2024) 97-113. https://doi.org/10.1016/j.comcom.2023.09.030
  17. H. Sedjelmaci, Cooperative attacks detection based on an artificial intelligence system for 5G networks. Computers & Electrical Engineering, 91, (2021) 107045. https://doi.org/10.1016/j.compeleceng.2021.107045
  18. A.A. AlZubi, M. Al-Maitah, A. Alarifi. (2021). Cyber-attack detection in healthcare using cyber-physical systems and machine learning techniques. Soft Computing, 25(18), 12319–12332. https://doi.org/10.1007/s00500-021-05926-8
  19. S. Zaman, K. Alhazmi, M. A. Aseeri, M. R. Ahmed, R. T. Khan, M. S. Kaiser, M. Mahmud, Security Threats and Artificial Intelligence-Based Countermeasures for Internet of Things Networks: A Comprehensive Survey. IEEE Access, 9, (2021) 94668–94690. https://doi.org/10.1109/ACCESS.2021.3089681
  20. C. Iwendi, S.U. Rehman, A.R. Javed, S. Khan, G. Srivastava. Sustainable Security for the Internet of Things Using Artificial Intelligence Architectures. ACM Transactions on Internet Technology, 21(3), (2021) 1–22. https://doi.org/10.1145/3448614
  21. G.C. Amaizu, C.I. Nwakanma, S. Bhardwaj, J.M. Lee, D.S. Kim. Composite and efficient DDoS attack detection framework for B5G networks. Computer Networks, 188, (2021) 107871. https://doi.org/10.1016/j.comnet.2021.107871
  22. M. Kuzlu, C. Fair, O. Guler, Role of Artificial Intelligence in the Internet of Things (IoT) cybersecurity. Discover Internet of Things, 1(1), (2021). https://doi.org/10.1007/s43926-020-00001-4
  23. H. Chaudhary, A. Detroja, P. Prajapati, P. Shah, (2020). A review of various challenges in cybersecurity using Artificial Intelligence. International Conference on Intelligent Sustainable Systems (ICISS), IEEE, India. https://doi.org/10.1109/ICISS49785.2020.9316003
  24. G. Kocher, G. Kumar, Machine learning and deep learning methods for intrusion detection systems: recent developments and challenges. Soft Computing, 25(15), (2021) 9731–9763. https://doi.org/10.1007/s00500-021-05893-0
  25. J. Lansky, S. Ali, M. Mohammadi, M.K. Majeed, S.H.T. Karim, S. Rashidi, M. Hosseinzadeh, A.M. Rahmani, Deep Learning-Based Intrusion Detection Systems: A Systematic Review. IEEE Access, 9, (2021) 101574–101599. https://doi.org/10.1109/ACCESS.2021.3097247
  26. S.W. Lee, H. Mohammed sidqi, M. Mohammadi, S. Rashidi, A. M. Rahmani, M. Masdari, M. Hosseinzadeh, Towards secure intrusion detection systems using deep learning techniques: Comprehensive analysis and review. Journal of Network and Computer Applications, 187, (2021) 103111. https://doi.org/10.1016/j.jnca.2021.103111
  27. A. Thakkar, R. Lohiya, A Review on Machine Learning and Deep Learning Perspectives of IDS for IoT: Recent Updates, Security Issues, and Challenges. Archives of Computational Methods in Engineering, 28, (2021) 3211–3243. https://doi.org/10.1007/s11831-020-09496-0
  28. Y. Imrana, Y. Xiang, L. Ali, Z. Abdul-Rauf, A bidirectional LSTM deep learning approach for intrusion detection. Expert Systems with Applications, 185, (2021) 115524. https://doi.org/10.1016/j.eswa.2021.115524
  29. S. Gamage, J. Samarabandu. Deep learning methods in network intrusion detection: A survey and an objective comparison. Journal of Network and Computer Applications, 169, (2020) 102767. https://doi.org/10.1016/j.jnca.2020.102767
  30. T. Saranya, S. Sridevi, C. Deisy, T.D. Chung, M.K.A.A. Khan, (Performance Analysis of Machine Learning Algorithms in Intrusion Detection Systems: A Review. Procedia Computer Science, 171, 2020) 1251–1260. https://doi.org/10.1016/j.procs.2020.04.133
  31. M.M. Yamin, M. Ullah, H. Ullah, B. Katt, Weaponized AI for cyber-attacks. Journal of Information Security and Applications, 57, (2021).102722. https://doi.org/10.1016/j.jisa.2020.102722
  32. K. Dhanushkodi, S. Thejas, Ai enabled threat detection: Leveraging artificial intelligence for advanced security and cyber threat mitigation. IEEE access, 12, (2024) 173127-173136. https://doi.org/10.1109/ACCESS.2024.3493957
  33. T. Sowmya, E.A. Mary Anita, A comprehensive review of an AI-based intrusion detection system. Elsevier, 28, (2023) 1-13. https://doi.org/10.1016/j.measen.2023.100827
  34. S. Alem, D. Espes, L. Nana, E. Martin, F. De Lamotte, A novel bi-anomaly-based intrusion detection system approach for industry 4.0. Future Generation Computer Systems, 145, (2023) 267-283. https://doi.org/10.1016/j.future.2023.03.024
  35. H. Zeng, M. Yunis, A. Khalil, N. Mirza, Towards a conceptual framework for AI-driven anomaly detection in smart city IoT networks for enhanced cybersecurity. Journal of Innovation & Knowledge, 9(4), (2024) 100601. https://doi.org/10.1016/j.jik.2024.100601
  36. M. Baker, A.Y. Fard, H. Althuwaini, M.B. Shadmand, Real-time AI-based anomaly detection and classification in power electronics dominated grids. IEEE Journal of Emerging and Selected Topics in Industrial Electronics, 4(2), (2022) 549-559. https://doi.org/10.1109/JESTIE.2022.3227005
  37. M. Vishwakarma, N. Kesswani, DIDS: A Deep Neural Network based real-time Intrusion detection system for IoT. Decision Analytics Journal, 5, (2022) 100142. https://doi.org/10.1016/j.dajour.2022.100142
  38. M. Asaduzzaman, M.M. Rahman, (2022) An adversarial approach for intrusion detection using hybrid deep learning model. In 2022 International Conference on Information Technology Research and Innovation (ICITRI), IEEE, Indonesia. https://doi.org/10.1109/ICITRI56423.2022.9970221
  39. Z. Zhang, H. Al Hamadi, E. Damiani, C.Y. Yeun, F. Taher, Explainable artificial intelligence applications in cyber security: State-of-the-art in research. IEEe Access, 10, (2022) 93104-93139. https://doi.org/10.1109/ACCESS.2022.3204051
  40. A. Attkan, V. Ranga, Cyber-physical security for IoT networks: a comprehensive review on traditional, blockchain and artificial intelligence based key-security. Complex & Intelligent Systems, 8(4), (2022) 3559-3591. https://doi.org/10.1007/s40747-022-00667-z
  41. Y. Luo, Y. Xiao, L. Cheng, G. Peng, D.D. Yao, Deep learning-based anomaly detection in cyber-physical systems: Progress and opportunities. ACM Computing Surveys, 54(5), (2021) Article 106. https://doi.org/10.1145/3453155
  42. I. Sharafaldin, A.H. Lashkari, A.A. Ghorbani, Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018), (2018) 108-116. https://doi.org/10.5220/0006639801080116