Deep Learning-Based Anomaly Detection in Enterprise Networks

dc.contributor.authorRezma,Omar
dc.contributor.authorKernabi,Mohammed Ziyad Miloud
dc.date.accessioned2026-10-08T12:02:37Z
dc.date.available2026-10-08T12:02:37Z
dc.date.issued2026-06-22
dc.description.abstractThe increasing frequency and sophistication of cyberattacks have made network security a major concern for modern information systems. Intrusion Detection Systems (IDS) play a crucial role in identifying malicious activities and protecting network infrastructures from potential threats. However, traditional IDS solutions often struggle to detect complex attack patterns and to adapt to the growing volume and diversity of network traffic. To address these challenges, this thesis proposes a hybrid deep learning model that combines Convolutional Neural Networks (CNNs) and Long Short-Term Memory (LSTM) networks for network in trusion detection. The proposed model was developed and evaluated using the NSL-KDD dataset. A com prehensive preprocessing pipeline was applied, including data cleaning, categorical feature encoding, feature scaling, and feature selection. The CNN component was used to auto matically extract relevant traffic features, while the LSTM component captured sequential dependencies and temporal patterns. The original feature space was reduced from 41 fea tures to 20 informative features in order to improve computational efficiency and facilitate embedded deployment. Experimental evaluation on the KDDTest+ dataset produced an accuracy of 80.5%, a pre cision of 96.8%, a recall of 68.0%, and an F1-score of 79.9%. These results demonstrate the model’s ability to generate highly reliable intrusion alerts while maintaining a reason able attack detection capability. In addition, the trained model was successfully deployed on a Raspberry Pi within a controlled network environment. The deployment experiments confirmed the feasibility of performing real-time intrusion detection on low-cost embedded hardware. The findings highlight the effectiveness of hybrid CNN–LSTM architectures for network intrusion detection and demonstrate their potential for practical cybersecurity applications requiring both accurate detection and real-time operation.
dc.identifier.urihttps://dspace.univ-tlemcen.dz/handle/112/26985
dc.language.isoen
dc.publisherUniversity of Tlemcen
dc.relation.ispartofseriesN°inventaire 10
dc.subjectIntrusion Detection System
dc.subjectIDS
dc.subjectDeep Learning
dc.subjectCNN–LSTM
dc.subjectNSL-KDD
dc.subjectCy bersecurity
dc.subjectNetwork Security
dc.subjectRaspberry Pi
dc.subjectReal-Time Detection.
dc.titleDeep Learning-Based Anomaly Detection in Enterprise Networks
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Deep_Learning-Based_Anomaly_Detection_in_Enterprise_Networks.pdf
Size:
7.4 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: