A new hybrid approach combining GCN and LSTM for real-time anomaly detection from network data
| dc.contributor.author | Kaya, Muhammed Onur | |
| dc.contributor.author | Ozdem, Mehmet | |
| dc.contributor.author | Das, Resul | |
| dc.date.accessioned | 2026-08-12T17:42:08Z | |
| dc.date.issued | 2025 | |
| dc.department | Fırat Üniversitesi | |
| dc.description.abstract | The rapidly changing nature of cyber threats is becoming difficult to deal with, and this requires developing innovative solutions. This study presents an innovative AI-based approach for anomaly detection in real-time network traffic. Wireshark, a widely used tool in network traffic analysis, was used in the data collection phase of the proposed model and as a testbed for live anomaly detection. A high-performance hybrid model was developed by combining Long Short-Term Memory (LSTM) and Graph Convolutional Networks (GCN), which perform well on time series data. A comprehensive dataset consisting of packets containing many attacks and harmless network packets was created and made available for open access. The proposed hybrid model achieved 97% accuracy on a large and comprehensive dataset. In addition, it was proven that live anomaly detection in network traffic could be achieved by using the developed test code and the Wireshark tool in an integrated manner. It is anticipated that in the future, artificial intelligence and deep learning-based methods will find more place in critical tasks such as anomaly detection and threat analysis in the field of cybersecurity and that these technologies will provide more effective and dynamic solutions against constantly evolving threats. | |
| dc.identifier.doi | 10.1016/j.comnet.2025.111372 | |
| dc.identifier.issn | 1389-1286 | |
| dc.identifier.issn | 1872-7069 | |
| dc.identifier.orcid | 0000-0002-6113-4649 | |
| dc.identifier.orcid | 0009-0004-6313-2278 | |
| dc.identifier.orcid | 0000-0002-2901-2342 | |
| dc.identifier.scopus | 2-s2.0-105006882640 | |
| dc.identifier.scopusquality | Q1 | |
| dc.identifier.uri | https://doi.org/10.1016/j.comnet.2025.111372 | |
| dc.identifier.uri | https://hdl.handle.net/11508/59622 | |
| dc.identifier.volume | 268 | |
| dc.identifier.wos | WOS:001504019000001 | |
| dc.identifier.wosquality | Q1 | |
| dc.indekslendigikaynak | Web of Science | |
| dc.indekslendigikaynak | Scopus | |
| dc.language.iso | en | |
| dc.publisher | Elsevier | |
| dc.relation.ispartof | Computer Networks | |
| dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı | |
| dc.rights | info:eu-repo/semantics/closedAccess | |
| dc.snmz | KA_WoS_20260511 | |
| dc.subject | Information security | |
| dc.subject | Graph Convolutional Networks | |
| dc.subject | Long Short-Term Memory | |
| dc.subject | Cyber attack | |
| dc.subject | Anomaly detection | |
| dc.subject | Real-time network traffic | |
| dc.title | A new hybrid approach combining GCN and LSTM for real-time anomaly detection from network data | |
| dc.type | Article |







