Author
Listed:
- Elayaraja Subbaiah
- Manykandaprebou Vaitinadin
Abstract
The rapid escalation of malware, phishing, botnet, and advanced persistent threat (APT) activity has rendered traditional signature- and rule-based security systems increasingly ineffective against novel, zero-day, and obfuscated attacks. Cyber Threat Intelligence (CTI) addresses this security gap by systematically ingesting, processing, and analyzing high-velocity threat telemetry to enable proactive cyber defense. However, the immense volume, velocity, and structural heterogeneity of modern security telemetry—spanning network packet flows, operating system audit logs, and application event streams— exceed what manual security operation center (SOC) analysis or classical machine learning algorithms can reliably process. This paper presents an enhanced, multi-source deep learning framework for Cyber Threat Intelligence that fuses spatial feature extraction via a 1D Convolutional Neural Network (CNN), temporal sequence dependency modeling via Long Short-Term Memory (LSTM) units, and a dynamic Softmax Attention Mechanism. The framework extends prior single-source intrusion detection work by: (i) explicitly fusing multi-source telemetry combining network flow indicators and system event logs within a unified pipeline; (ii) computing per-sample calibrated Softmax confidence scores accompanied by a quantitative reliability threshold analysis for automated alert triage; and (iii) conducting rigorous empirical evaluation on two benchmark datasets, NSL-KDD and CICIDS2017, enabling direct baseline comparison. Extensive comparative benchmarking against individual CNN, LSTM, Autoencoder, and Transformer models as well as rule-based security baselines demonstrates that the proposed CNN-LSTM-Attention model achieves 96.8% accuracy, 96.2% precision, 96.5% recall, 96.3% F1-score, and an Area Under the Curve (AUC) of 0.982. An accompanying ablation study verifies that the attention mechanism contributes a 1.9% accuracy gain and isolates stealthy, low-frequency attack phases such as data exfiltration. These findings validate the operational deployment of multi-source, attention-enhanced deep learning for continuous CTI monitoring while establishing clear research pathways for explainable AI (XAI) and privacy-preserving federated threat sharing.
Suggested Citation
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:daw:ijsrmt:v:3:y:2024:i:3:p:36-42:id:1580. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Rahul Goyal (email available below). General contact details of provider: https://ijsrmt.com/index.php/ijsrmt/ .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.