Can deep-learning models transform intrusion detection?: An empirical study using LSTM on network traffic
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE credits
Student thesis
Abstract [en]
The internet’s original design emphasized communication over security, leaving protocols like TCP/IP and DNS inherently vulnerable to modern threats. As global networks scale, signaturebased Intrusion Detection System (IDS) increasingly fail to detect sophisticated attacks such as zero-day exploits, botnets, and APTs. The rise of encrypted traffic further impairs visibility, underscoring the need for adaptive, learning-based detection. This study investigates the use of Deep Learning (DL), specifically Long Short-Term Memory (LSTM) networks, to improve real-time anomaly detection in network traffic. The proposed model leverages temporal dependencies in flow-level features (notably, flow bytes per second) from the CIC-UNSW NB15 dataset to identify sequence-level anomalies often missed by rule-based systems or shallow classifiers. An experimental evaluation compares the Long Short-Term Memory-Variational Autoencoder (LSTM-VAE) model against traditional IDS solutions, assessing its performance in terms of accuracy, false positives, scalability, and generalization. Baseline comparisons reference prior work (Hesford et al., 2024), where traditional models such as Slip and Kitsune achieved F1 scores of 0.13 and 0.56 respectively, versus 0.85 from a DNN-based IDS. This research builds on those results by integrating temporal modeling and explainability, aiming to reduce false positives and improve detection of evolving threats. Ultimately, the study examines whether Deep Learning-driven IDS represent a fundamental shift in cybersecurity or merely an enhancement to existing frameworks. Results suggest that while not a complete replacement, Deep Learningbased anomaly detection offers significant advantages in coverage, adaptability, and early-stage detection, particularly when combined with hybrid architectures.
Place, publisher, year, edition, pages
2025. , p. 53
Keywords [en]
Machine learning, deep-learning, neural networks, IDS, LSTM, anomaly detection
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-25313OAI: oai:DiVA.org:his-25313DiVA, id: diva2:1973551
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
2025-06-192025-06-192025-09-29Bibliographically approved