Anomaly Based Hybrid Cyber Threat Detection System

There are teo types of detection systems SIGNATURE BASED and ANOMALY BASED but to detect a zero day or unknown attack signature detection system failes then comes anomaly based detection systems Our project is an anomaly based cyber threat detection system using deep learning.To improve the d

2025-06-28 16:25:07 - Adil Khan

Project Title

Anomaly Based Hybrid Cyber Threat Detection System

Project Area of Specialization Cyber SecurityProject Summary

There are teo types of detection systems SIGNATURE BASED and ANOMALY BASED but to detect a zero day or unknown attack signature detection system failes then comes anomaly based detection systems

Our project is an anomaly based cyber threat detection system using deep learning.To improve the detection we generate different patterns of threats from known threat so if any known threat comes in a disguised form our system is abe to detect it.

Project Objectives Project Implementation Method

Our detection system is composed of two levels of classification. On first level there is a
multi-classifier and on second level there are three binary classifiers for each attack kind.
(DOS, PROBE, R2L) The network traffic first goes to the first level multi-classifier which
detects if there is a threat in network traffic and detects the threat kind. If any threat kind is
detected, the network traffic goes to respective classifier for verification to attain highly
efficient model. But if network traffic is normal or not anomalous then second level
verification does not take place .For example DOS attack is detected by the multi-classifier
at the first level then DOS attack is verified by the DOS binary classifier at the second level.

To develop a highly efficient classification model, we preprocess data (NSL-KDD Dataset)
using three steps of feature engineering.
1. Categorical Data Encoding.
2. Feature Selection.
3. Dimensionality Reduction.
After preprocessing we filter dataset according to attack kind. To accomplish target of
detecting zero day attack we generate the synthetic instances of each kind using GANs so
that attack is detected even if it is in disguised form. All the classifiers are trained on dataset,
preprocessed on each combination. Then finally the combination that gives the best results
is selected for each classifier.

Benefits of the Project

Although many detection systems are available but generating different patterns of threats using GANs is not implemented yet and it surely increases the detection rate and highly efficient detection systems is need of the time.

Technical Details of Final Deliverable

Our final system having embeddes highly efficient classifiers which is classifying  the live netwrok traffic among three kinds of attcks (DOS,Probe,R2L) and all these detection are shown in a dashboard.

Final Deliverable of the Project Software SystemCore Industry SecurityOther Industries Legal , Media , Health , Telecommunication Core Technology Artificial Intelligence(AI)Other Technologies OthersSustainable Development Goals Industry, Innovation and Infrastructure, Reduced InequalityRequired Resources
Item Name Type No. of Units Per Unit Cost (in Rs) Total (in Rs)
Total in (Rs) 76100
Router Equipment12000020000
Switch Equipment019500
Ethernet Cables Equipment10115011500
Hard disk Equipment4700028000
Modem Equipment233006600
Overhead Miscellaneous 11000010000

More Posts