Content area
This framework presents an innovative methodology that combines LSTM, Transformer, and GNN models to effectively capture both temporal and spatial patterns within log data, thus improving cybersecurity anomaly detection and forensic analysis. By utilizing LSTM networks, the system is able to model sequential log patterns over time, which aids in identifying hidden attack behaviors. Transformer architectures are employed to examine contextual relationships within logs, allowing for accurate, context-sensitive classification. Moreover, Graph Neural Networks (GNNs) depict logs as interconnected graphs, which facilitates the identification of coordinated multi-stage attacks from various sources. The integration of these models enables a thorough analysis of log data, simultaneously capturing dynamic temporal sequences and intricate relationships. The system autonomously correlates logs from system, network, and application sources to reconstruct attack timelines and identify emerging threats in real time. Empirical assessments on datasets such as HDFS, CICIDS, and UNSW-NB15 indicate that this integrated approach outperforms traditional methods, achieving detection accuracies of up to 98.2%, minimizing false positives, and expediting forensic investigations—thereby significantly enhancing the capabilities of automated cybersecurity monitoring and response.
Details
1 Department Computer Science and Engineering, Indore, India
2 Galgotias University, School of Computing Science and Engineering, Department of Computer Science and Engineering, Greater Noida, India (GRID:grid.448824.6) (ISNI:0000 0004 1786 549X)
3 Galgotias University, School of Computer Applications & Technology, Greater Noida, India (GRID:grid.448824.6) (ISNI:0000 0004 1786 549X)
4 Taif University, P. O. Box 11099, 21944, Department of Computer Science, College of Computers and Information Technology, Taif, Saudi Arabia (GRID:grid.412895.3) (ISNI:0000 0004 0419 5255)
5 Taif University, P. O. Box 11099, 21974, Department of Information Technology, College of Computers and Information Technology, Taif, Saudi Arabia (GRID:grid.412895.3) (ISNI:0000 0004 0419 5255)
6 Arba Minch University, Arba Minch, Ethiopia (GRID:grid.442844.a) (ISNI:0000 0000 9126 7261)