Jul 2026· 2026 7th International Conference on Smart Systems and Inventive Technology (ICSSIT)· pp. 223-228· 0 citations· 19 references
Abstract
Traditional signature-based intrusion detection systems (IDS) and rule-based security mechanisms frequently fail to detect these kinds of advanced and adaptive attacks because they rely on the patterns of attacks in the past. In addition, modern cyberattacks are very dynamic and polymorphic; traditional detection methods are not adequate for real-time cybersecurity protection. In this paper, an Adaptive Deep Learning Framework for Zero-Day Attack Detection Using Anomaly and Behavior Analysis is proposed to overcome the above limitations. The proposed scheme incorporates deep learning, anomaly detection, and behaviour analysis methods to detect novel cyber threats and malicious activities in real-time, intelligently. The framework constantly observes the traffic in the network, the pattern of user activity, system logs, and communication anomalies, and builds adaptive behavioral models that can differentiate between normal and malicious behavior. Advanced deep neural networks, Long Short-Term Memory (LSTM) architectures, and adaptive anomaly detection mechanisms are employed to analyze the temporal attack behavior and detect abnormal network activities with high accuracy. The findings support the adaptability, resilience, and efficiency of the proposed framework for intelligent zero-day attack detection and cybersecurity applications with deep learning.
The rapid growth of digital communication, cloud computing, Internet of Things (IoT), software-defined networking, and edge computing has significantly increased the complexity and volume of network traffic, creating new opportunities for sophisticated cyberattacks. Traditional signature-based intrusion detection systems are highly effective against previously identified threats but often fail to recognize emerging zero-day attacks whose behavioral characteristics have not been previously observed. Consequently, anomaly-based deep learning approaches have gained considerable attention because of their capability to automatically learn complex traffic patterns and identify deviations from legitimate network behavior. This study proposes an anomaly-based deep learning model for detecting both known and zero-day attacks in heterogeneous network environments. The proposed framework integrates advanced traffic preprocessing, automated feature extraction, deep neural representation learning, adaptive anomaly scoring, and intelligent attack classification to enhance detection accuracy while minimizing false alarms. The model is designed to capture nonlinear relationships among network traffic attributes, enabling effective identification of sophisticated intrusion attempts that evade conventional security mechanisms. Furthermore, the proposed architecture emphasizes scalability, robustness, and real-time applicability for modern enterprise networks. The anticipated outcomes demonstrate improved detection performance, reduced false positive rates, enhanced generalization capability for unseen attacks, and strengthened network resilience, thereby providing an effective intelligent cybersecurity solution for next-generation network intrusion detection systems.
Aswathy N. Rajan· Journal of Intelligent Decis...· 0 citations
This review presents a comprehensive analysis of machine learning-based intrusion detection systems, covering a wide range of techniques including supervised learning, unsupervised learning, ensemble learning, and deep learning models, and discusses critical challenges affecting the deployment of ML-based IDS.
Ranobir Hasan, H. Jamal, Kamal Kamal et al.· The Eastasouth Journal of In...· 0 citations
The findings confirm that the proposed IDSaaS framework provides an efficient, scalable, and adaptive solution for real-time cloud intrusion detection and significantly enhances the reliability and resilience of modern cloud and industrial cybersecurity infrastructures.
Unik B. Lokhande, Kavita Sonawane· Journal of Cloud Computing· 0 citations
The rapid evolution of cyber threats has increased the demand for intelligent and efficient approaches to network security. Deep learning has gained considerable attention in this context because of its ability to learn complex patterns and automatically extract relevant features from large and diverse cybersecurity data. The present paper examines the application of deep learning for network security threat identification and mitigation, with emphasis on the capabilities of different deep learning architectures and their suitability for cybersecurity tasks. CNN, DBN, RBM, Autoencoder, Stacked Autoencoder, RNN, LSTM, and GAN-based approaches are examined in relation to malware detection, intrusion detection, phishing and spam detection, botnet detection, and ransomware detection. The paper further considers recent developments in hybrid deep learning models, GAN-based approaches, federated learning, attention-based techniques, and Transformer-based methods for improving threat detection. Along with these developments, important challenges involving parameter optimization, evaluation metrics, datasets, model architecture, inference, and interpretability are considered. The analysis highlights the growing role of deep learning in developing automated and adaptive security mechanisms and emphasizes the need for reliable datasets, suitable model selection, improved generalization, and explainable approaches for effective cybersecurity applications.
Unknown authors· International journal of com...· 0 citations
This article presents an advanced IDS that uses deep learning, specifically stacked Long Short-Term Memory (LSTM) and the CatBoost algorithm, to detect anomalies in network traffic to monitor and detect the cyber threats in real-time.
Muhammad Moosa, B. Naseem, Sana Alam et al.· 0 citations
Experimental results demonstrate that the proposed model achieves high detection accuracy, strong discriminative capability, and low false alarm rates across both datasets, confirming its effectiveness and scalability for next-generation cybersecurity applications.