Deep Learning-Based Anomaly Detection in Enterprise Networks
Loading...
Date
Journal Title
Journal ISSN
Volume Title
Publisher
University of Tlemcen
Abstract
The increasing frequency and sophistication of cyberattacks have made network security a
major concern for modern information systems. Intrusion Detection Systems (IDS) play a
crucial role in identifying malicious activities and protecting network infrastructures from
potential threats. However, traditional IDS solutions often struggle to detect complex attack
patterns and to adapt to the growing volume and diversity of network traffic. To address these
challenges, this thesis proposes a hybrid deep learning model that combines Convolutional
Neural Networks (CNNs) and Long Short-Term Memory (LSTM) networks for network in
trusion detection.
The proposed model was developed and evaluated using the NSL-KDD dataset. A com
prehensive preprocessing pipeline was applied, including data cleaning, categorical feature
encoding, feature scaling, and feature selection. The CNN component was used to auto
matically extract relevant traffic features, while the LSTM component captured sequential
dependencies and temporal patterns. The original feature space was reduced from 41 fea
tures to 20 informative features in order to improve computational efficiency and facilitate
embedded deployment.
Experimental evaluation on the KDDTest+ dataset produced an accuracy of 80.5%, a pre
cision of 96.8%, a recall of 68.0%, and an F1-score of 79.9%. These results demonstrate
the model’s ability to generate highly reliable intrusion alerts while maintaining a reason
able attack detection capability. In addition, the trained model was successfully deployed
on a Raspberry Pi within a controlled network environment. The deployment experiments
confirmed the feasibility of performing real-time intrusion detection on low-cost embedded
hardware.
The findings highlight the effectiveness of hybrid CNN–LSTM architectures for network
intrusion detection and demonstrate their potential for practical cybersecurity applications
requiring both accurate detection and real-time operation.