Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Can deep-learning models transform intrusion detection?: An empirical study using LSTM on network traffic
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

The internet’s original design emphasized communication over security, leaving protocols like TCP/IP and DNS inherently vulnerable to modern threats. As global networks scale, signaturebased Intrusion Detection System (IDS) increasingly fail to detect sophisticated attacks such as zero-day exploits, botnets, and APTs. The rise of encrypted traffic further impairs visibility, underscoring the need for adaptive, learning-based detection. This study investigates the use of Deep Learning (DL), specifically Long Short-Term Memory (LSTM) networks, to improve real-time anomaly detection in network traffic. The proposed model leverages temporal dependencies in flow-level features (notably, flow bytes per second) from the CIC-UNSW NB15 dataset to identify sequence-level anomalies often missed by rule-based systems or shallow classifiers. An experimental evaluation compares the Long Short-Term Memory-Variational Autoencoder (LSTM-VAE) model against traditional IDS solutions, assessing its performance in terms of accuracy, false positives, scalability, and generalization. Baseline comparisons reference prior work (Hesford et al., 2024), where traditional models such as Slip and Kitsune achieved F1 scores of 0.13 and 0.56 respectively, versus 0.85 from a DNN-based IDS. This research builds on those results by integrating temporal modeling and explainability, aiming to reduce false positives and improve detection of evolving threats. Ultimately, the study examines whether Deep Learning-driven IDS represent a fundamental shift in cybersecurity or merely an enhancement to existing frameworks. Results suggest that while not a complete replacement, Deep Learningbased anomaly detection offers significant advantages in coverage, adaptability, and early-stage detection, particularly when combined with hybrid architectures. 

Place, publisher, year, edition, pages
2025. , p. 53
Keywords [en]
Machine learning, deep-learning, neural networks, IDS, LSTM, anomaly detection
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-25313OAI: oai:DiVA.org:his-25313DiVA, id: diva2:1973551
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2025-06-19 Created: 2025-06-19 Last updated: 2025-09-29Bibliographically approved

Open Access in DiVA

fulltext(982 kB)371 downloads
File information
File name FULLTEXT01.pdfFile size 982 kBChecksum SHA-512
68edea0c4bbf8cac9ec6a5ec90fbf84232aa0019874236fdc57b57db14bc0bc14b68c53604a6652714062c0f9b5f2ddcd740042144ad6162356ce8daea3f9827
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems, Social aspects

Search outside of DiVA

GoogleGoogle Scholar
Total: 374 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 473 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf