Deep Learning Approaches for Cyber Threat Intelligence: A Multi-Source, Explainable CNN-LSTM-Attention Framework Evaluated on NSL-KDD and CICIDS2017
DOI:
https://doi.org/10.38124/ijsrmt.v3i3.1580Keywords:
Cyber Threat Intelligence, Deep Learning, Intrusion Detection System (IDS), LSTM, CNN, Attention Mechanism, Anomaly Detection, Network Traffic Analysis, NSL-KDD, CICIDS2017, Softmax Confidence CalibrationAbstract
The rapid escalation of malware, phishing, botnet, and advanced persistent threat (APT) activity has rendered traditional signature- and rule-based security systems increasingly ineffective against novel, zero-day, and obfuscated attacks. Cyber Threat Intelligence (CTI) addresses this security gap by systematically ingesting, processing, and analyzing high-velocity threat telemetry to enable proactive cyber defense. However, the immense volume, velocity, and structural heterogeneity of modern security telemetry—spanning network packet flows, operating system audit logs, and application event streams— exceed what manual security operation center (SOC) analysis or classical machine learning algorithms can reliably process. This paper presents an enhanced, multi-source deep learning framework for Cyber Threat Intelligence that fuses spatial feature extraction via a 1D Convolutional Neural Network (CNN), temporal sequence dependency modeling via Long Short-Term Memory (LSTM) units, and a dynamic Softmax Attention Mechanism. The framework extends prior single-source intrusion detection work by: (i) explicitly fusing multi-source telemetry combining network flow indicators and system event logs within a unified pipeline; (ii) computing per-sample calibrated Softmax confidence scores accompanied by a quantitative reliability threshold analysis for automated alert triage; and (iii) conducting rigorous empirical evaluation on two benchmark datasets, NSL-KDD and CICIDS2017, enabling direct baseline comparison. Extensive comparative benchmarking against individual CNN, LSTM, Autoencoder, and Transformer models as well as rule-based security baselines demonstrates that the proposed CNN-LSTM-Attention model achieves 96.8% accuracy, 96.2% precision, 96.5% recall, 96.3% F1-score, and an Area Under the Curve (AUC) of 0.982. An accompanying ablation study verifies that the attention mechanism contributes a 1.9% accuracy gain and isolates stealthy, low-frequency attack phases such as data exfiltration. These findings validate the operational deployment of multi-source, attention-enhanced deep learning for continuous CTI monitoring while establishing clear research pathways for explainable AI (XAI) and privacy-preserving federated threat sharing.
Downloads
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2024 International Journal of Scientific Research and Modern Technology

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
PlumX Metrics takes 2–4 working days to display the details. As the paper receives citations, PlumX Metrics will update accordingly.