Multi-class network intrusion detection: Machine and deep learning benchmark with live stream deployment

dc.authorid0000-0003-0261-4404
dc.contributor.authorDanışmaz, Betül
dc.contributor.authorBıyık, Mustafa Emre
dc.contributor.authorGözüaçık, Necip
dc.date.accessioned2026-08-21T10:19:43Z
dc.date.available2026-08-21T10:19:43Z
dc.date.issued2026
dc.departmentFakülteler, Mühendislik ve Doğa Bilimleri Fakültesi, Yazılım Mühendisliği Bölümü
dc.description.abstractThe rapid rise of advanced cyber threats is exposing the limitations of traditional, signature-based network intrusion detection systems. While machine learning and deep learning models offer proactive defense mechanisms, current research is often compromised due to temporal data leakage, impractical threat classifications, and significant discrepancies between offline evaluation and online deployment. This study presents a comparative evaluation of traditional machine learning and deep learning architectures integrated into a fully functional real-time inference pipeline. Additionally, we propose an operationally motivated three-class classification encompassing Benign, Volumetric, and Semantic traffic to contextualize incident response. When the trained XGBoost, Random Forest, Decision Tree, LSTM, and BiLSTM models were evaluated and compared under the same constraints, the BiLSTM model achieved the highest Macro F1 score at 97.72%. However, XGBoost closely followed with a Macro F1 of 95.87%, while achieving 15.5 times faster inference. To translate these findings into practice, a Kafka-based live system architecture was designed that integrates real-time stream inference, zero-downtime model switching, and automated threat response capabilities.
dc.description.abstractGelişmiş siber tehditlerin hızla artması, geleneksel, imza tabanlı ağ saldırı tespit sistemlerinin sınırlarını ortaya koymaktadır. Makine öğrenimi ve derin öğrenme modelleri proaktif savunma mekanizmaları sunarken, mevcut araştırmalar genellikle zamansal veri sızıntıları, pratik olmayan tehdit sınıflandırmaları ve çevrimdışı değerlendirme ile çevrimiçi dağıtım arasındaki önemli farklar nedeniyle tehlikeye girmektedir. Bu çalışma, tamamen işlevsel bir gerçek zamanlı çıkarım hattına entegre edilmiş geleneksel makine öğrenimi ve derin öğrenme mimarilerinin karşılaştırmalı değerlendirmesini sunmaktadır. Ayrıca, olaylara müdahaleyi anlamlandırmak için Zararsız, Hacimsel ve Semantik trafiğini kapsayan, operasyonel olarak motive edilmiş üç sınıflı bir sınıflandırma önerilmiştir. Eğitilen XGBoost, Rastgele Orman, Karar Ağacı, LSTM, BiLSTM modelleri aynı kısıtlamalar altında değerlendirilerek karşılaştırıldığında BiLSTM ağı, %97,72 ile en yüksek Makro F1 puanını elde etmiştir. Ancak, XGBoost algoritması %95,87 ile 15,5 kat daha hızlı çıkarım sergilemiştir. Bu bulguları pratiğe aktarmak için, gerçek zamanlı akış çıkarımı, sıfır kesintili model değişimi ve otomatik tehdit yanıtı özelliklerini bir arada barındıran Kafka tabanlı bir canlı sistem mimarisi tasarlanmıştır.
dc.identifier.citationDanışmaz, B., Bıyık, M. E., & Gözüaçık, N. (2026). Multi-class network intrusion detection: Machine and deep learning benchmark with live stream deployment. 34th Signal Processing and Communications Applications Conference (SIU), IEEE. https://doi.org/10.1109/SIU71813.2026.11636987
dc.identifier.doi10.1109/SIU71813.2026.11636987
dc.identifier.issn2165-0608
dc.identifier.urihttps://doi.org/10.1109/SIU71813.2026.11636987
dc.identifier.urihttps://hdl.handle.net/20.500.13055/1587
dc.indekslendigikaynakWeb of Science
dc.institutionauthorDanışmaz, Betül
dc.institutionauthorBıyık, Mustafa Emre
dc.institutionauthorGözüaçık, Necip
dc.institutionauthorid0000-0003-0261-4404
dc.language.isotr
dc.publisherIEEE
dc.relation.ispartof34th Signal Processing and Communications Applications Conference (SIU)
dc.relation.publicationcategoryKonferans Öğesi - Uluslararası - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/openAccess
dc.subjectNetwork Intrusion Detection
dc.subjectMachine Learning
dc.subjectDeep Learning
dc.subjectReal-Time Deployment
dc.subjectMulti-Class Attack
dc.subjectCICIDS2017
dc.subjectAğ Saldırı Tespiti
dc.subjectMakine Öğrenimi
dc.subjectDerin Öğrenme
dc.subjectGerçek Zamanlı Dağıtım
dc.subjectÇok Sınıflı Saldırı
dc.titleMulti-class network intrusion detection: Machine and deep learning benchmark with live stream deployment
dc.title.alternativeÇok sınıflı ağ saldırı tespiti: Canlı akış dağıtımı ile makine ve derin öğrenme karşılaştırması
dc.typeConference Object
dspace.entity.typePublication

Dosyalar

Orijinal paket
Listeleniyor 1 - 1 / 1
Yükleniyor...
Küçük Resim
İsim:
Tam Metin / Full Text.pdf
Boyut:
1010.15 KB
Biçim:
Adobe Portable Document Format
Lisans paketi
Listeleniyor 1 - 1 / 1
Kapalı Erişim
İsim:
license.txt
Boyut:
1.17 KB
Biçim:
Item-specific license agreed upon to submission
Açıklama: