REAL-TIME NETWORK TRAFFIC CAPTURE AND ANALYSIS USING A DEEP NEURAL NETWORK

Authors

  • Angela Borisova Computer Systems and Technologies Department, “Vasil Levski” National Military University, Shumen, Bulgaria
  • Krasimir Slavyanov Computer Systems and Technologies Department, “Vasil Levski”National Military University, Shumen, Bulgaria

DOI:

https://doi.org/10.68302/std2026.vol3.112

Keywords:

LSTM, 1D CNN, Autoencoder, reverse shell attacks

Abstract

Nowadays, computer networks generate large and complex data sets, which leads to problems related to the detection of new, modified threats. Classic Intrusion Detection Systems – IDS, based on static rules and signatures, have difficulty identifying masked - as legitimate or previously unseen malicious activities. The challenge they face is reverse shell attacks, in which the attacker establishes a seemingly reliable connection with the victim. This study presents an approach aimed at solving a problem related to the cybersecurity of computer systems and networks. This is done by building, training, and testing the effectiveness of deep neural architectures for recognizing illegitimate reverse shell packets passing through a computer network in a controlled and real-world environment.

The simulation of the attacks is carried out in a protected environment – ​​Oracle Virtual Box. The interception of network packets in real time is carried out using a software tool written in the Python programming language. Packet sniffing itself is performed both in the virtual environment and in the real environment. The sniffer script extracts significant sets of characteristics from network packets, such as packet size, protocols used, ports, TCP flags, IP addresses - of the source (attacker) and the recipient (victim), and others. The current report compares several deep neural networks, namely One-dimensional convolution neural network/1D CNN, Long Short-Term Memory/LSTM and Autoencoder. As 1D CNN, it extracts local dependencies between network packet features for traffic classification. LSTM models capture temporal dependencies and sequences from network data, and autoencoders reconstruct normal network behavior patterns. The results of the experiments reveal the ability of deep neural networks to correctly model the behavior of network traffic and ultimately increase the recognition of compromised data. The proposed approach offers the opportunity to further automate the processes of detection and monitoring of computer systems, which in turn would lead to the protection of network infrastructure in modern dynamic environments.

Supporting Agencies

This paper is created in favor of Bulgarian National Scientific program “Security and Dеfense”, Ministry Council decision No 731/21.10.2021, Agreement No Д01-74/19.05.2022, Ministry Council decision No 386/07.05.2026.

Downloads

Download data is not yet available.

References

[1] A. M. Alashjaee, "Deep learning for network security: an Attention-CNN-LSTM model for accurate intrusion detection," Scientific Reports, vol. 15, Art. no. 21856, 2025, https://doi.org/10.1038/s41598-025-07706-y.

[2] S. Titouni et al., "Hybrid CNN-Autoencoder model for accurate and efficient fault diagnosis in grid-connected photovoltaic systems," International Journal of Electrical Power & Energy Systems, vol. 173, Art. no. 111454, Dec. 2025, https://doi.org/10.1016/j.ijepes.2025.111454.

[3] Y. Xue, C. Kang, and H. Yu, "HAE-HRL: A network intrusion detection system utilizing a novel autoencoder and a hybrid enhanced LSTM-CNN-based residual network," Computers & Security, Art. no. 104328, 2025, https://doi.org/10.1016/j.cose.2025.104328.

[4] M. Udurume, V. Shakhov, and I. Koo, "Comparative Analysis of Deep Convolutional Neural Network—Bidirectional Long Short-Term Memory and Machine Learning Methods in Intrusion Detection Systems," Applied Sciences, vol. 14, no. 16, Art. no. 6967, 2024, https://doi.org/10.3390/app14166967.

[5] M. S. Ataa, E. E. Sanad, and R. A. El-khoribi, "Intrusion detection in software defined network using deep learning approaches," Scientific Reports, vol. 14, Art. no. 29159, 2024, https://doi.org/10.1038/s41598-024-79001-1.

[6] E. Mushtaq, A. Zameer, M. Umer, and A. A. Abbasi, "A two-stage intrusion detection system with auto-encoder and LSTMs," Applied Soft Computing, vol. 128, Art. no. 108768, 2022, https://doi.org/10.1016/j.asoc.2022.108768.

[7] L. Mohammadpour, T. C. Ling, C. S. Liew, and A. Aryanfar, "A Survey of CNN-Based Network Intrusion Detection," Applied Sciences, vol. 12, Art. no. 8162, 2022, https://doi.org/10.3390/app12168162.

[8] N. Dash, S. Chakravarty, A. K. Rath et al., "An optimized LSTM-based deep learning model for anomaly network intrusion detection," Scientific Reports, vol. 15, Art. no. 1554, 2025, https://doi.org/10.1038/s41598-025-85248-z .

[9] L. G. Nikolov, "Email social engineering in action," in Proceedings of International Scientific Conference “Defense Technologies” (DefTech 2024), Faculty of Artillery, Air Defense and Communication and Information Systems, 2024, ISSN 2815-4282, pp. 395–402.

[10] L. G. Nikolov, "Social engineering cyberattacks," in Proceedings of International Scientific Conference “Defense Technologies” (DefTech 2024), Faculty of Artillery, Air Defense and Communication and Information Systems, 2024, ISSN 2815-4282, pp. 403–408.

Downloads

Published

17.09.2026

How to Cite

[1]
A. Borisova and K. Slavyanov, “REAL-TIME NETWORK TRAFFIC CAPTURE AND ANALYSIS USING A DEEP NEURAL NETWORK”, SysTechDev, vol. 3, pp. 45–52, Sep. 2026, doi: 10.68302/std2026.vol3.112.