Skip to content
#software testing Conference Open access

REAL-TIME NETWORK TRAFFIC CAPTURE AND ANALYSIS USING A DEEP NEURAL NETWORK

Sep 2026 · Proceedings of the International Conference on Secure Systems Design and Technology Development · Vol 3, pp. 45-52 · 0 citations · 9 references

TL;DR

Several deep neural networks are compared, namely One-dimensional convolution neural network/1D CNN, Long Short-Term Memory/LSTM and Autoencoder, to reveal the ability of deep neural networks to correctly model the behavior of network traffic and ultimately increase the recognition of compromised data.

Abstract

Nowadays, computer networks generate large and complex data sets, which leads to problems related to the detection of new, modified threats. Classic Intrusion Detection Systems – IDS, based on static rules and signatures, have difficulty identifying masked - as legitimate or previously unseen malicious activities. The challenge they face is reverse shell attacks, in which the attacker establishes a seemingly reliable connection with the victim. This study presents an approach aimed at solving a problem related to the cybersecurity of computer systems and networks. This is done by building, training, and testing the effectiveness of deep neural architectures for recognizing illegitimate reverse shell packets passing through a computer network in a controlled and real-world environment. The simulation of the attacks is carried out in a protected environment – ​​Oracle Virtual Box. The interception of network packets in real time is carried out using a software tool written in the Python programming language. Packet sniffing itself is performed both in the virtual environment and in the real environment. The sniffer script extracts significant sets of characteristics from network packets, such as packet size, protocols used, ports, TCP flags, IP addresses - of the source (attacker) and the recipient (victim), and others. The current report compares several deep neural networks, namely One-dimensional convolution neural network/1D CNN, Long Short-Term Memory/LSTM and Autoencoder. As 1D CNN, it extracts local dependencies between network packet features for traffic classification. LSTM models capture temporal dependencies and sequences from network data, and autoencoders reconstruct normal network behavior patterns. The results of the experiments reveal the ability of deep neural networks to correctly model the behavior of network traffic and ultimately increase the recognition of compromised data. The proposed approach offers the opportunity to further automate the processes of detection and monitoring of computer systems, which in turn would lead to the protection of network infrastructure in modern dynamic environments.

Read PDF

Similar papers

Real-time detection of cryptographic key misuse in software-defined networks using incremental learning

An incremental learning based framework to detect anomalous traffic patterns which may indicate any key misuse in Software-Defined Networks in dynamic and real-time environments in modern SDN environments is proposed.

Gineeth Rajeshkhanna, Tamilarasi Kathirvel Murugan, Logeswari Govindaraj et al. · 0 citations
Open access Aug 2026

Enhancing SQL Injection Detection: A Machine Learning Approach Using Network Flow Data

A flow-based detection method, making use of lightweight protocols like NetFlow and sFlow to identify SQLI attacks, which minimizes the need for computationally expensive packet inspection, which is going to render the process of detection more trustworthy and economical, particularly within high-traffic conditions.

P. Vinoth, K. Sudar, S. Muthukumar · 0 citations
Open access Aug 2026

Enhancing Network Security with a Hybrid Intrusion Detection System Using SVM

A thorough analysis of a modest version of a suggested system that use Support Vector Machines (SVM) to address networking anomaly and misuse detection in the face of insurmountable obstacles, foreseeing an all-encompassing solution to modern network security issues.

Gaurav Kishor Saxena, Shambhu Dayal Sahu · 0 citations
Review Open access Sep 2026

Deep Learning Approaches for Real-Time DDoS Detection in Network-Based Systems: A Comprehensive and Analytical Review

Distributed Denial of Service (DDoS) attacks are one of the most important cybersecurity problems today since they are one of the biggest threats against network service continuity and accessibility. Increasing network traffic volume combined with heterogeneous data structures and variations in attack types creates gre...

Ahmet Kara, Pınar Sarısaray Bölük · 0 citations

Related blog posts

MIT News · Artificial Intelligence Oct 2, 2026

Documenting the tech worker movement

Writing as a participant and researcher, PhD student JS Tan SM ’22 has co-authored a new book about the rise of tech worker protests and the employer backlash that followed.

GPT-Lab Sep 23, 2026

Requirements Don’t Live in Isolation: What We’re Exploring with Req-Space

Requirements in large systems rarely exist in isolation. Their meaning depends on the wider project context - other requirements, policies, decisions, tests, and implementation details. That becomes especially important when AI is used for review, because spotting a possible conflict or gap is only the beginning. ReqSpace explores how AI, visualisation, and connected project context can help reviewers understand those findings, trace the relationships behind them, and focus on the questions that…

GPT-Lab Sep 17, 2026

Beyond Prompt Engineering: The Role of Tacit Knowledge in Software Engineering

AI is making software generation faster, but speed does not remove the need for expertise. As more work is delegated to AI, tacit knowledge may become one of the most important human advantages in software engineering. The post Beyond Prompt Engineering: The Role of Tacit Knowledge in Software Engineering appeared first on GPT-Lab.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.