A Hybrid Technique for Detecting Cyber Threats Through Network Traffic Analysis
R.V. Umaselvi, T.R. Nisha Dayana · 2025
The increasing complexity of cyber risks such as advanced persistent threats (APTs), data breaches, and botnets, requires the use of effective and flexible detection techniques. This study provides a novel approach to detect such threats using network traffic analysis. Machine learning (ML), statistical analysis, and behavior profiling are used to detect abnormal patterns that differ from regular network activity. Using DL techniques, the system can analyze massive volumes of real-time and historical traffic data to detect subtle indicators of compromise (IoCs), such as atypical communication patterns, data exfiltration efforts, or command-and-control (C2) activity. The proposed framework combines signature-based detection for known threats with anomaly-based techniques for discovering previously unknown threats. It utilizes unsupervised learning to detect anomalies in traffic flow patterns and trained models to characterize hostile activity. The system also uses threat intelligence feeds to improve detection accuracy and reduce false positives. Evaluations on large-scale datasets show that the technique can detect sophisticated threats with excellent precision and recall, even in encrypted or obscured network traffic. The proposed method outperforms others since it employs a hybrid technique that includes signature-based identification, autoencoders for outlier detection, random forests for labelled data, and Recurrent Neural Networks (RNNs) for temporal analysis. This technique offers a preventive and flexible solution for minimizing cyber risks, giving businesses a deeper understanding into their network activity and greater resilience to evolving attack vectors.