A new hybrid approach combining GCN and LSTM for real-time anomaly detection from network data

dc.contributor.authorKaya, Muhammed Onur
dc.contributor.authorOzdem, Mehmet
dc.contributor.authorDas, Resul
dc.date.accessioned2026-08-12T17:42:08Z
dc.date.issued2025
dc.departmentFırat Üniversitesi
dc.description.abstractThe rapidly changing nature of cyber threats is becoming difficult to deal with, and this requires developing innovative solutions. This study presents an innovative AI-based approach for anomaly detection in real-time network traffic. Wireshark, a widely used tool in network traffic analysis, was used in the data collection phase of the proposed model and as a testbed for live anomaly detection. A high-performance hybrid model was developed by combining Long Short-Term Memory (LSTM) and Graph Convolutional Networks (GCN), which perform well on time series data. A comprehensive dataset consisting of packets containing many attacks and harmless network packets was created and made available for open access. The proposed hybrid model achieved 97% accuracy on a large and comprehensive dataset. In addition, it was proven that live anomaly detection in network traffic could be achieved by using the developed test code and the Wireshark tool in an integrated manner. It is anticipated that in the future, artificial intelligence and deep learning-based methods will find more place in critical tasks such as anomaly detection and threat analysis in the field of cybersecurity and that these technologies will provide more effective and dynamic solutions against constantly evolving threats.
dc.identifier.doi10.1016/j.comnet.2025.111372
dc.identifier.issn1389-1286
dc.identifier.issn1872-7069
dc.identifier.orcid0000-0002-6113-4649
dc.identifier.orcid0009-0004-6313-2278
dc.identifier.orcid0000-0002-2901-2342
dc.identifier.scopus2-s2.0-105006882640
dc.identifier.scopusqualityQ1
dc.identifier.urihttps://doi.org/10.1016/j.comnet.2025.111372
dc.identifier.urihttps://hdl.handle.net/11508/59622
dc.identifier.volume268
dc.identifier.wosWOS:001504019000001
dc.identifier.wosqualityQ1
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherElsevier
dc.relation.ispartofComputer Networks
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.snmzKA_WoS_20260511
dc.subjectInformation security
dc.subjectGraph Convolutional Networks
dc.subjectLong Short-Term Memory
dc.subjectCyber attack
dc.subjectAnomaly detection
dc.subjectReal-time network traffic
dc.titleA new hybrid approach combining GCN and LSTM for real-time anomaly detection from network data
dc.typeArticle

Dosyalar