Augmenting Cybersecurity System with Hybrid Deep Learning Architectures: A Study of LSTM-CNN and LSTM-DNN Models for Advanced Threat Detection

Authors

  • Abdul Waheed Ahmad Riphah International University, Lahore, Pkaistan image/svg+xml
  • Sadia Akbar Riphah International University, Lahore, Pakistan image/svg+xml
  • Muhammad Adnan Riphah International University, Lahore, Pakistan image/svg+xml
  • Jamal ud Din Riphah International University, Lahore, Pakistan image/svg+xml

DOI:

https://doi.org/10.32350/icr.61.03

Keywords:

Hybrid Deep Learning, Malware Classification, Intrusion Detection, Anomaly Detection, Real-Time Threat Detection, Optimization Techniques

Abstract

The modern cyber threat environment is increasingly becoming dynamic, thus compromising the effectiveness of the more traditional intrusion detection, malware classification, and anomaly detection systems. The traditional methodologies often simply do not suffice to represent complex temporal dynamics and patterns of discriminative features, and thus give worse detection performance in respect to more advanced threat situations. To address these limitations, the current study performed a comparative evaluation of the two hybrid deep-learning (DL) models: Long Short-Term Memory Convolutional Neural Network (LSTM-CNN) and the Long Short-Term Memory Deep Neural Network (LSTM-DNN). These models have been developed to complement cybersecurity threat detection. Both networks utilize LSTM layers as the method of sequential learning, and then add either convolutional layers to learn spatial features or fully connected layers to learn hierarchical representations. This is accompanied by a single and consistent experimental design, where common pre-processing steps, input encoding using sequences, as well as pre-set training-validation-testing partitions and same optimization parameters are used. The models are tested using benchmark datasets, such as NSL -KDD, MalwareBytes, and CICIDS2017/2018. To determine robustness and stability, each experiment is repeated several times and the performance is given in terms of mean values and standard deviations. The experimental outcomes showed that LSTM- CNN is always more accurate in all the tasks compared to LSTM- DNN. In particular, the LSTM -CNN achieved 97.5 ± 0.12%, 97.1 ± 0.10%, and 98.7 ± 0.08% accuracy, respectively with intrusion, malware, and anomaly detection, and also higher precision, recall, and F1-score with less variability between runs. Convergence analysis of training also showed that the training process was stable and that there was good generalization. These results proved that the combination of convolutional features extraction with the use of temporal sequences modeling creates concrete performance gains in the complex cybersecurity detection problems. In general, the study presented empirical data to confirm the application of hybrid DL architectures as effective and scalable to modern cybersecurity systems.

Downloads

Download data is not yet available.
0

References

[1] X. Li, H. Huang, G. Yuan, Z. Wang, and R. Du, “An intrusion detection method based on fusion neural network,” Front. Comput. Intell. Syst., vol. 4, no. 2, pp. 124–130, Jun. 2023, https:// doi.org/10.54097/fcis.v4i2.10369.

[2] J. Bi, X. Zhang, H. Yuan, J. Zhang, and M. C. Zhou, “A hybrid prediction method for realistic network traffic with temporal convolutional network and LSTM,” IEEE Trans. Autom. Sci. Eng., vol. 19, no. 3, pp. 1869–1879, Jul. 2022, https://doi.org/ 10.1109/TASE.2021.3077537.

[3] J. Suganthi, B. Nagarajan, and S. Muhtumari, “Network anomaly detection using hybrid deep learning technique,” in Algorithms, Tools and Paradigms, D. J. Hemanth et al., Eds., vol. 39, Advances in Parallel Computing. Amsterdam, The Netherlands: IOS Press, 2022, pp. 103–109, https://doi.org/10.3233/ APC220014.

[4] X. Wan, H. Liu, H. Xu, and X. Zhang, “Network traffic prediction based on LSTM and transfer learning,” IEEE Access, vol. 10, pp. 86181–86190, 2022, https://doi.org/10.1109/ ACCESS.2022.3199372.

[5] A. Djenna, A. Bouridane, S. Rubab, and I. M. Marou, “Artificial intelligence-based malware detection, analysis, and mitigation,” Symmetry, vol. 15, no. 3, art. no. 677, Mar. 2023, https://doi.org/10.3390/sym15030677.

[6] S. Morgan, “Cybercrime to cost the world $10.5 trillion annually by 2025,” Cybercrime Magazine, Nov. 13, 2020. [Online]. Available: https://cybersecurityventures.com/hackerpocalypse-cybercrime-report-2016/. [Accessed: Feb. 25, 2025].

[7] M. Saied, S. Guirguis, and M. Madbouly, “Review of filtering-based feature selection for botnet detection in the Internet of Things,” Artif. Intell. Rev., vol. 58, no. 4, art. no. 119, Apr. 2025, https://doi.org/10.1007/s10462-025-11113-0.

[8] M. Ozkan-Okay et al., “A comprehensive survey: Evaluating the efficiency of artificial intelligence and machine learning techniques on cyber security solutions,” IEEE Access, vol. 12, pp. 12229–12256, 2024, https://doi.org/10.1109/ACCESS.2024.3355547.

[9] J. W. Goodell and S. Corbet, “Commodity market interactions with energy-firm distress: Evidence from the Colonial Pipeline ransomware attack,” SSRN Electron. J., Jun. 2022, https://doi.org/10.2139/ssrn.4130544.

[10] D. E. Whitehead, K. Owens, D. Gammel, and J. Smith, “Ukraine cyber-induced power outage: Analysis and practical mitigation strategies,” in Proc. 70th Annu. Conf. Protective Relay Eng. (CPRE), College Station, TX, USA, 2017, pp. 1–8, https:// doi.org/10.1109/CPRE.2017.8090056.

[11] A. Greenberg, “The untold story of NotPetya, the most devastating cyberattack in history,” Wired, Aug. 22, 2018. [Online]. Available: https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/. [Accessed: Feb. 25, 2025].

[12] M. S. Akhtar and T. Feng, “Detection of malware by deep learning as CNN-LSTM machine learning techniques in real time,” Symmetry, vol. 14, no. 11, art. no. 2308, Nov. 2022, https://doi.org/10.3390/sym14112308.

[13] S. Ali et al., “A novel approach of botnet detection using hybrid deep learning for enhancing security in IoT networks,” Alexandria Eng. J., vol. 103, pp. 88–97, Sep. 2024, https:// doi.org/10.1016/j.aej.2024.05.113.

[14] M. Z. Alom et al., “A state-of-the-art survey on deep learning theory and architectures,” Electronics, vol. 8, no. 3, art. no. 292, Mar. 2019, https:// doi.org/10.3390/electronics8030292.

[15] M. Alauthman, N. Aslam, M. Alkasassbeh, S. Khan, A. Al-Qerem, and K.-K. R. Choo, “An efficient reinforcement learning-based botnet detection approach,” J. Netw. Comput. Appl., vol. 150, art. no. 102479, Jan. 2020, https://doi.org/10.1016/j.jnca. 2019.102479.

[16] J. Saxe and K. Berlin, “Deep neural network-based malware detection using two-dimensional binary program features,” in Proc. 10th Int. Conf. Malicious Unwanted Softw. (MALWARE), Fajardo, PR, USA, 2015, pp. 11–20, https://doi.org/ 10.1109/MALWARE.2015.7413680.

[17] V. T. Patil and S. S. Deore, “DDoS attack detection: Strategies, techniques, and future directions,” J. Electr. Syst., vol. 20, no. 9s, pp. 2030–2046, Jul. 2024, https://doi.org/10. 52783/jes.4808.

[18] I. A. Abdulmajeed and I. M. Husien, “MLIDS22—IDS design by applying hybrid CNN-LSTM model on mixed datasets,” Informatica, vol. 46, no. 8, pp. 121–134, Nov. 2022, https://doi. org/10.31449/inf.v46i8.4348.

[19] Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” Nature, vol. 521, no. 7553, pp. 436–444, May 2015, https://doi.org/10.1038/nature14539.

[20] S. Han, H. Yun, and Y. Park, “Deep learning for cybersecurity classification: Utilizing depth-wise CNN and attention mechanism on VM-obfuscated data,” Electronics, vol. 13, no. 17, art. no. 3393, Sep. 2024, https://doi.org/10.3390/ electronics13173393.

[21] L. Nataraj, S. Karthikeyan, G. Jacob, and B. S. Manjunath, “Malware images: Visualization and automatic classification,” in Proc. 8th Int. Symp. Visualization Cyber Security (VizSec ’11), Pittsburgh, PA, USA, 2011, art. no. 4, pp. 1–7, https://doi. org/10.1145/2016904.2016908.

[22] D. Kilichev, D. Turimov, and W. Kim, “Next-generation intrusion detection for IoT EVCS: Integrating CNN, LSTM, and GRU models,” Mathematics, vol. 12, no. 4, art. no. 571, Feb. 2024, https://doi.org/ 10.3390/math12040571

[23] H. Kim and M. Kim, “Malware detection and classification system based on CNN-BiLSTM,” Electronics, vol. 13, no. 13, art. no. 2539, Jul. 2024, https://doi.org/10.3390/electronics13132539.

[24] B. Mohammed and E. Gbashi, “Intrusion detection system for NSL-KDD dataset based on deep learning and recursive feature elimination,” Eng. Technol. J., vol. 39, no. 7, pp. 1069–1079, Jul. 2021, https://doi.org/ 10.30684/etj.v39i7.1695.

[25] S. Shende and S. Thorat, “Long short-term memory (LSTM) deep learning method for intrusion detection in network security,” Int. J. Eng. Res. Technol. (IJERT), vol. 9, no. 6, pp. 1–6, Jun. 2020, https://doi.org/10. 17577/IJERTV9IS061016.

[26] F. E. Laghrissi, S. Douzi, K. Douzi, and B. Hssina, “Intrusion detection systems using long short-term memory (LSTM),” J. Big Data, vol. 8, no. 1, art. no. 65, May 2021, https://doi.org/10. 1186/s40537-021-00448-4.

[27] D. S. Berman, A. L. Buczak, J. S. Chavis, and C. L. Corbett, “A survey of deep learning methods for cyber security,” Information, vol. 10, no. 4, art. no. 122, Apr. 2019, https://doi.org/10.3390/info10040122.

[28] R. Baimukashev, K. Artykbayev, K. Adam, and B. Mels, “Intrusion detection system for wireless networks,” in Proc. 16th Int. Conf. Electron. Comput. Computation (ICECCO), Kaskelen, Kazakhstan, 2021, pp. 1–5, https://doi.org/10. 1109/ICECCO53203.2021.9663787.

[29] Y. Li, S. Chai, Z. Ma, and G. Wang, “A hybrid deep learning framework for long-term traffic flow prediction,” IEEE Access, vol. 9, pp. 11264–11271, 2021, https://doi.org/10.1109/ ACCESS.2021.3050836.

[30] G. Huang, Z. Liu, L. van der Maaten, and K. Q. Weinberger, “Densely connected convolutional networks,” in Proc. IEEE Conf. Comput. Vis. Pattern Recognit. (CVPR), Honolulu, HI, USA, 2017, pp. 2261–2269, https://doi.org/10.1109/CVPR.2017.243.

[31] F. Aksan, Y. Li, V. Suresh, and P. Janik, “CNN-LSTM vs. LSTM-CNN to predict power flow direction: A case study of the high-voltage subnet of northeast Germany,” Sensors, vol. 23, no. 2, art. no. 901, Jan. 2023, https://doi.org/10.3390/s23020901.

[32] S. Tipper, H. F. Atlam, and H. S. Lallie, “An investigation into the utilisation of CNN with LSTM for video deepfake detection,” Appl. Sci., vol. 14, no. 21, art. no. 9754, Nov. 2024, https://doi.org/10.3390/app 14219754.

[33] Hassan06, “NSL-KDD,” Kaggle. [Online]. Available: https://www. kaggle.com/datasets/hassan06/nslkdd. [Accessed: Jul. 28, 2026].

[34] Ernie55ernie, “Improved CICIDS2017 and CSE-CICIDS2018,” Kaggle. [Online]. Available: https://www. kaggle.com/datasets/ernie55ernie/improved-cicids2017-and-csecicids2018. [Accessed: Jul. 28, 2026].

[35] Microsoft, “Microsoft Malware Classification Challenge (BIG 2015),” Kaggle. [Online]. Available: https:// www.kaggle.com/c/malware-classification. [Accessed: Jul. 28, 2026].

[36] K. V. Nguyen, H. T. Nguyen, T. Q. Le, and Q. N. M. Truong, “Abnormal network packets identification using header information collected from Honeywall architecture,” J. Inf. Telecommun., vol. 7, no. 4, pp. 437–461, 2023, https://doi.org/10. 1080/24751839.2023.2215135.

[37] Y. Zhu, S. Yao, and X. Sun, “Feature interaction dual self-attention network for sequential recommendation,” Front. Neurorobot., vol. 18, art. no. 1456192, Aug. 2024, https:// doi.org/10.3389/fnbot.2024.1456192.

Downloads

Published

2026-06-25

How to Cite

Ahmad, A. W., Akbar, S., Adnan, M., & Din, J. ud. (2026). Augmenting Cybersecurity System with Hybrid Deep Learning Architectures: A Study of LSTM-CNN and LSTM-DNN Models for Advanced Threat Detection . Innovative Computing Review, 6(1), 31–50. https://doi.org/10.32350/icr.61.03

Issue

Section

Articles

Similar Articles

<< < 1 2 3 4 > >> 

You may also start an advanced similarity search for this article.