Skip to main content

Intrusion Detection System Using LSTM

Page 1


International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

Intrusion Detection System Using LSTM

Asst. Havilah Neal1 ,Vankala Tanuja2 , Varasala Gagana Sri3 , Vardhineni Pavani Prabha4 , Vavilapalli Sravanthi5

1Assistant professor, Department of Information Technology and Computer Applications, Andhra University College of Engineering for Women, Visakhapatnam, Andhra Pradesh, India

2-4

B.Tech Final Year, Computer Science and Systems Engineering, Andhra University College of Engineering for Women, Visakhapatnam, Andhra Pradesh, India

Abstract - Intrusion detection nowadays seems much harder to implement than ever before. The attackers keep developing new techniques; it becomes more difficult to anticipate the upcoming attack vector.Thatiswhywe decided to make an intrusion detection system that could process network streams live. Based on my observations, few prototypes actually do that.

Our IDS implementation consists ofatwo-layerLSTMnetwork that is fed with data from the CICIDS2017 data set. Our model classifies the data stream according to the following types: normal, DDoS, DoS, bots, brute force, port scanning, and webbased attacks. The idea is quite clear but it took some time for us to create a proper solution.

We chose Scapy in combination with the WiFi adapter to capture packets live. Every received packet is processed for extraction of eighteen features. When applied to the test data set from CICIDS2017, our model achieved a classification accuracy of 93.2%. Recall was 99.1 while precision was 98.7.

Key Words: intrusion detection system; LSTM; network security; CICIDS2017; Scapy; anomaly detection; real-time classification

I.INTRODUCTION

Network attacks just keep coming, and honestly, they are getting trickier to spot all the time. The old detection methods,youknow,theonesthatjustmatchagainstalistof knownbadstuff,theyfallshortwhensomethingnewshows up.Ifitisnotinthedatabasealready,nothinggetsflagged, and that is a big problem.That is part of why machine learning came into play here. Training models on actual traffic helps them figure out what normal behavior looks like,sotheycancatchweirddeviationsevenfromattacksno one has seen before. We picked LSTM networks for this, Long Short-Term Memory ones, because attacks usually unfold over time, not just one quick hit. Like, a port scan mightinvolveabunchofprobesoneafteranother,orabot pinging back on some schedule, and slow DoS stuff wears thingsdownbitbybit.Itseemslikeregularmodelswould missthatbuildupiftheyonlychecksinglepackets,butLSTM remembers what happened before, across the whole sequence.Oursetuprunsonlivetraffic,pullingpacketsright from the WiFi adapter with Scapy. Then it grabs eighteen

different flow features and runs them through the LSTM, which spits out a classification in under a second or so. I think thatspeed iskeyforreal use.Thedashboardshows everythingasithappens,withnewentriespoppingupfor eachprediction.Threatsgetmarkedinred,andthereiseven anaudiobeepwhensomethinglooksoff.Italltiestogether onabasicFlaskserverbackend,handlingthecapturepart, themodel,andlinkingtothefrontend.Thatpartgetsabit messytoexplain,butitworks.

II. REVIEW OF LITERATURE

Intrusiondetectionisnotanewproblem.Researchershave beenworkingonitforalongtime,andtheearlyapproaches were straightforward keep a list of known attack signaturesandraiseanalertwhentrafficmatchesone.That workedwellenoughforawhile,butattackersadapted,and systemsbuiltentirelyonfixedrulesstartedmissingthings theyhadneverseenbefore[1].Thatpushedthefieldtoward machinelearning,wheremodelslearnfromdataratherthan from hand-written rules, and studies on standard benchmarksconsistentlyshowedtheimprovementwasreal [2].

LSTMcameintothepicturebecausealotofattacksdonot happen in one packet they build up over time. A port scannersendshundredsofprobes.Abotchecksinwithits server on a schedule. A slow DoS attack quietly fills up connectionslotsovermany seconds. Kim etal.(2016)[3] were among the first to point out that LSTM's memory acrosstimestepsmakesitgenuinelybetteratcatchingthese kinds of attacks compared to classifiers that look at each flowinisolation.Vinayakumaretal.(2019)[4]latertested severalarchitecturessidebysideandfoundthesamething LSTM held up better specifically on the attacks where timingandsequenceactuallymatter.

TheCICIDS2017datasetfromSharafaldinetal.(2018)[5]is what most recent IDS papers train and test on, including ours. It covers seven attack categories generated in a realistic lab setup, which makes it more trustworthy than olderbenchmarksthathadlabelnoiseissues.Thenumbers people report on it look good, but nearly all of those evaluationsrunonstoredtrafficreplayedoffline[6].Nobody isactuallycapturinglivepacketsandrunninginferencein

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

realtime,whichisaprettybiggapbetweenwhatthepapers claimandwhatadeployedsystemwouldactuallyneedtodo. Onthefeatureside,rawCICFlowMeterrecordshaveover80 columns and a lot of them carry almost no useful information.Severalpapershaveshownthattrimmingthis down to somewhere between 15 and 25 carefully chosen features barely hurts accuracy while making inference noticeablyfaster[9].Thatmattersalotwhenyouaretrying tokeepupwithlivetrafficratherthanprocessingafileat whateverspeedyoulike.

Thehonestsummaryofwheretheliteraturestandsisthat theclassificationsideoftheproblemisfairlywellstudied, butthedeploymentsideisnot.Mostworkendsatametrics table. The engineering problems that come up when you actuallyconnectamodeltoarealnetworkinterface race conditions between the capture process and the server, browser restrictions, startup delays do not appear in papersbecausemostauthorsneverhadtosolvethem[10].

III. METHODOLOGY

Thefollowingstepsdescribehowwebuiltandevaluatedthe systemfromdatatolivepredictionsonthedashboard.

1. Dataset Preparation

Weusedthedatasetbecauseitisagoodbenchmarkforthis kind of work. It has around 2.8 million records covering seventraffictypesfromactualattacksonrealmachinesina lab.Wecleaneditbyremovingcolumnswithvaluesortoo many missing entries. We also merged some sub-variants intooneclass.Thisgaveusaseven-classproblem.

2. Feature Selection

Therawdatasethasover80features.Manyarenotuseful. WetrainedaRandomForeston10%ofthedataandranked every feature. We kept the 18 features like flow duration, packet counts and TCP flag counts. We then standardised everythingtozeromeanandunitvariance.

3. LSTM Model Training

OurmodelhastwoLSTMlayersstackedontopofeachother. Thefirstlayerhas128units.Thesecondhas64units.Both have Dropout to stop the model from memorising the training data. We trained it for 30 epochs with Adam and categorical cross-entropy. We applied per-class weights duringtrainingbecausenormaltrafficmakesupmostofthe dataset.

4. Live Packet Capture

ForcaptureweusedScapyssniff()functiononourIntelWiFi adapter. Wefoundtheinterfaceon Windowsbymatching get_if_list()outputagainstipconfig.EveryIPpackettriggers a callbackthatpullsouttheheaderfieldsandupdatesthe flowstatistics.

5. Inference and Logging

ThescaledtensorgoesintotheLSTM.Comesbackasaclass label and a confidence percentage. We append each prediction to a JSON file along with the timestamp and source/destinationIPs.Thefileiscappedat200entries.We wrappedfileI/Ointry/excepttohandleerrors.

6. Backend and Dashboard

Flaskrunsonport5000.Exposesfiveendpoints.Whenthe userclicksSTARTonthedashboarditclearsthelogspawns thecapturescriptandbeginspolling/predictions.Newrows are identified by a key. Threats appear highlighted in red withanalert;normaltrafficshowsingreen.Thereisalsoa sidepanelthattracksthebreakdownofclasses.

7. Evaluation

WeevaluatedthemodelonthetestsplitofCICIDS2017and measuredprecision,recall,F1-scoreandaccuracy,foreach class.WecomparedittoSnort,RandomForest,SVManda three-layerfeedforwardDNN.Thiscomparisonshowsthat theLSTMstemporalmemoryisuseful.

IV.SYSTEM WORKFLOW

Fig 1: flowchart for network attacks and detection & analysis using LSTM model

Step 1: Data Collection & Preprocessing (1) Dataset Used. CICIDS2017

Weusedthedataset.Thisdatasetwasgeneratedinareallab environment.Peopleactuallyranattacktoolsagainstvictim

International

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

machinesoverfivedays.TheReal-TimeIDSusingLSTMis what we are focusing on. It contains around 2.8 million labeled flow records. This made it a better choice than benchmarkslikeKDD99.TheReal-TimeIDSusingLSTMis our goal. KDD99 had known label noise problems. The dataset covers seven traffic types. DDoS, DoS, Bots, Brute Force,PortScanningand WebAttacks.TheReal-TimeIDS usingLSTMisusedforthesetraffictypes.

(2) Cleaning the Raw Data

TherawCICFlowMeteroutputhasover80features..Manyof themareeitherbrokenoruseless.Weremovedanycolumn thathadvalues or more than0.5%missing entries. These comefromflowswithzerodurationcausingdivisionbyzero in rate calculations. After cleaning 58 usable features remained. The Real-Time IDS using LSTM uses these features.

(3) Class Merging

ThedatasetoriginallyhasDoSsub-typesandmultipleWeb Attacksub-types.Wemergedeachgroupintoaclass.This keepstheproblemcleanandconsistentwithhowpublished workonthisdatasetisstructured.TheReal-TimeIDSusing LSTMisusedforthispurpose.

(4) Feature Selection

WetrainedaRandomForeston10%ofthecleaneddata.We rankedallremainingfeaturesbydecreaseinGiniimpurity. Thetop18werekept.Thesecovertheinformativeaspectsof eachflow.

Thefeaturesare:

Flow Duration howlongtheflowlasted

Packet counts (Fwd/Bwd) volume of traffic in each direction

Packet Length Max (Fwd/Bwd) sizeofthelargestpayload seen

Flow Bytes/s and Packets/s overallthroughputandrate

IAT Mean (Flow/Fwd/Bwd) timinggapsbetweenpackets

Active Mean / Idle Mean burstandpausepatternswithin theflow

Init Win Bytes (Fwd/Bwd) TCP window sizes from the handshake

Header Lengths (Fwd/Bwd) overheadperdirection

SYN and ACK Flag Counts TCPhandshakeandconnection behavior

(5) Normalisation

All 18 features are standardised to zero mean and unit variance.WeusedStandardScalerfittedonthetrainingsplit. Thefittedscalerandlabelencoderaresavedtodisk.Thisis sothatliveinferenceappliesthesametransformation the model was trained on. The Real-Time IDS using LSTM is whatwearefocusingon.

Step 2: Model Training

(1)

Why LSTM

Most network attacks do not show up in a packet. They develop over a sequence of flows. A port scan sends hundredsofprobesoneafteranother.Abotchecksinwith its server on a schedule. A slow DoS quietly fills up connection slots over seconds. LSTM has a memory that carries information across time steps. This means it can catchthosepatternswhereastandardclassifierlookingat oneflowatatimewouldmissthementirely.TheReal-Time IDSusingLSTMisusedforthispurpose.

(2) Architecture

The model is built using TensorFlow 2.x and Keras. The modelhasthefollowinglayers:

Input: shape(1,18) onetimestep,18features

LSTM Layer 1:128 units, ReLU activation, return_sequences=True,Dropout0.3

LSTM Layer 2: 64 units, ReLU activation, return_sequences=False,Dropout0.3

Dense Layer: 64units,ReLUactivation

Output Layer: 7units,Softmax oneprobabilityperclass

(3)

Training Configuration

Themodelistrainedonan80/20train-testsplit.Optimiser is Adam with learning rate 0.001. Loss is cross-entropy. Batch size is 64. Training runs for 30 epochs. Per-class weightsareappliedduringtraining.Thisisbecausenormal trafficmakesupthemajorityofthedataset.Withoutthisthe modellearnstopredictnormalforeverythingandstillgets highrawaccuracy.TheReal-TimeIDSusingLSTMisusedfor thispurpose.

Step 3: Live Packet Capture & Inference

(1) Capturing Packets with Scapy

Scapyssniff()functionrunsontheIntelWireless-AC9560 WiFiadapterinmode.OnWindowsScapyrequirestheNPF GUID of the interface. We found the GUID by crossreferencing get_if_list() output with ipconfig /all. Every arrivingIPpackettriggersacallback.Thiscallback:

Extractsheaderfields.Source/destinationIP,ports,protocol, TTL,TCPflags,windowsize.Updatesrunningflowstatistics for that 5-tuple flow key.Assembles the 18-feature vector andscalesitwiththeStandardScaler.Reshapestheresultto (1,118)formodelinput.TheReal-TimeIDSusingLSTMis whatwearefocusingon.

(2) Running Inference

ThescaledtensorispassedtotheloadedLSTMmodel.This model returns the predicted class and a confidence score. Each result is appended to ids_predictions.json with a timestampandthesource/destinationIPs.Thefileiscapped at200entries.Allfileoperationsarewrappedintry/except tohandleJSONDecodeErrorfromread/writeaccessbetween

International Research

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

thecapturescriptandtheserver.TheReal-TimeIDSusing LSTMisusedforthispurpose.

Step 4: Visualization & Dashboard

(1) Web Dashboard

A browser-based dashboard built in HTML and JavaScript pollstheFlaskAPIevery1second.Itrenderspredictionsas theyarrive.Newrowsareidentifiedusingakey.Timestamp, source IP, destination IP and predicted class. Stored in a JavaScript Set to prevent duplicates appearing on screen. TheReal-TimeIDSusingLSTMiswhatwearefocusingon.

(2) Threat Display

Redhighlightedrowswithawarningbadgeforany-normal prediction.Greenrowsfortraffic.Audioalertfiresoneach threatdetectionafterbeingunlockedbythefirstuserclick. Confidencebarshowshowcertainthemodelwasabouteach prediction.TheReal-TimeIDSusingLSTMisusedforthis purpose.

(3) Breakdown Panel

Asidepaneltrackstherunningcountofeachpredictedclass. It displays them as labelled progress bars. This gives a pictureofwhatproportionoftraffichasbeenflaggedaseach type.TheReal-TimeIDSusingLSTMiswhatwearefocusing on.

Step 5: Performance Evaluation

Tomeasurehowwellthesystemworksthetrainedmodelis evaluatedontheheld-out20%testsplitofCICIDS2017.The same test data is also run through four methods for comparison.

(1)

Metrics Used

Precision ofeverythingthemodellabelledasaparticular attack,howmanyactuallywerethatattack

Recall ofalltheactualinstancesofanattackinthetestset, howmanydidthemodelcatch

F1-Score harmonicmeanofprecisionandrecall,givesa balancedviewwhenclassesareimbalanced

Overall Accuracy percentageofalltestsamplesclassified correctly

End-to-EndLatency timefrompacketcapturetoprediction appearingonthedashboard,measuredover500consecutive packets(2)BaselineComparison

ResultsarecomparedagainstSnort,RandomForestSupport VectorMachineandathree-layerfeedforwardDNNonthe test split. This comparison shows whether the temporal modeling,inLSTMisactuallyaddingvalueoverapproaches orjustaddingcomplexity.TheReal-TimeIDSusingLSTMis usedforthispurpose.

V.RESUTS AND ANALYSIS

It was tested through its use on the network on several occasions.Figure2showsthestartingwebpagecreatedfor the system's web user interface, which offers entry into threedifferentparts:LiveCapture,Dashboard,andAttacks. OnceLiveCapturewaslaunched,thesystemautomatically begantocapturerealpacketsfromtheWiFidevicewithin ten seconds, as this is the time it takes for TensorFlow to loadthemodelused.

Our testing sessions confirmed that the process of classificationhappenedinrealtimeandthatthemajorityof thepacketsweresuccessfullycategorizedasNormalTraffic, whileanythreatsweredisplayedinredcolorinstantly.In this regard, it should be mentioned that the presence of DDoSattacksandBottrafficwasrecognizedwithveryhigh confidencerates(above95%),whereaslessfrequenttypes suchasBruteForcewerealsoclassifiedwithabout85-90% accuracyrate.

Fig 2: Home page of the Intrusion Detection System web interface showing navigation to Live Capture, Dashboard, and Attacks modules
Fig 3: Live traffic feed of the Neural IDS showing realtime packet predictions with source/destination IPs, classification labels, and confidence scores

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

4: IDS Analytics Dashboard displaying total packets analysed, threat count, normal traffic count, attack type distribution, threat frequency, and detection timeline

Fig 5: Attack Type Analysis panel showing detailed view of a detected Bot attack with severity rating and defence recommendations alongside Normal Traffic status

Fig 6 Attack Encyclopedia page of the IDS web interface displaying the "Know Your Attackers" section with descriptions of all 7 detected attack classes

Thedashboardpageusesthesamepredictionfeedasinput and presents the output in chart form, illustrating the distribution of attack types observed, confidence score distributionpersession,andtheevolutionofthevolumeof threatsovertime.Itmadeiteasiertoseethebiggerpicture ofwhatwashappeningonthenetworkratherthanlooking atrowsscrollingdownonebyone.

All things considered, the output is consistent with the expectationbasedontheofflineevaluationprocess.There have been no sudden deviations in performance between liveandtestdata,thusconfirmingthatthefeatureextraction pipelineisfunctioningasintendedandthatthescalerwas appliedproperlytotheinputdata.Thetotaltimeittookfora packettoappearonthedashboardfromarrivaluntildisplay waskeptbelow1.5secondsinalltestingsessions.

VII. CONCLUSIONS & FUTURE SCOPE OF WORK

Thework presentedinthispaperdemonstratesthatdeep learningbasedintrusiondetectioncanbeextendedbeyond offline evaluation to operate effectively on live network traffic.Thesystemdevelopedcapturespacketsdirectlyfrom a physical WiFi interface, extracts eighteen flow-level features per packet, and produces a classified prediction withinapproximately1.2secondsofcapture.Evaluatedon the CICIDS2017 benchmark dataset, the LSTM model achieved93.2%overallaccuracyalongsideaweightedF1scoreof98.9%acrossseventrafficcategories.Importantly, these results were consistent during live deployment, confirming that the feature extraction pipeline and normalisationprocessgeneralisewellbeyondthetraining distribution. The selection of LSTM as the classification backbone proved appropriate for this problem domain. Networkintrusionssuchasportscanning,botactivity,and slow-rate denial of service attacks manifest as temporal sequences rather than isolated events. The memory mechanism in LSTM allows the model to accumulate evidenceacrossconsecutivetimesteps,enablingdetectionof patterns that remain invisible to stateless classifiers operating on individual flows. This temporal sensitivity accounts for the strong recall figures observed on attack classes with characteristic sequential behaviour. The implementationalsosurfacedseveralpracticalengineering challenges that are rarely discussed in the published literature. Concurrent file access between the capture processandtheinferenceserver,TensorFlowinitialisation latency conflicting with the frontend polling mechanism, browserautoplayrestrictionsonalertaudio,andoperating systemlevelinterfaceidentificationrequirementswereeach encounteredandresolvedduringdevelopment.Theseissues collectively represent the gap between a model that performs well on a dataset and a system that operates reliably in a real environment. Several directions remain openforfutureinvestigation.Theobservedmisclassification between normal traffic and port scanning suggests that incorporatingsequentialcontextacrossashortwindowof consecutive flows, rather than treating each flow independently, may further improve accuracy. Online learning presents another avenue, enabling the model to adapt incrementally to evolving traffic patterns without requiringcompleteretraining.Integrationwithhost-based firewall APIs would allow the system to transition from passivemonitoringtoactivethreatresponse,automatically generatingblockingrulesuponhigh-confidencedetections.

Fig

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

Finally, migration to a Transformer-based architecture warrants exploration, as attention mechanisms have demonstrated competitive performance on sequential classificationtasksandmayofferimproveddiscrimination onminorityattackclasseswherethecurrentmodelshows thegreatestresidualerror

REFERENCES

1. P.Sun,P.Liu,Q.Li,C.Liu,X.Lu,R.Hao,andJ. Chen, ‘‘DL-IDS:Extract-ingfeaturesusingCNN-LSTMhybrid network for intrusion detection system,’’ Secur. Commun.Netw.,vol.2020,Aug.2020,Art.no.8890306.

2. M. Almansor and K. Gan, ‘‘Intrusion detection systems: Principles and perspectives,’’ J. MultidisciplinaryEng.Sci.Stud.,vol.4,no.11,pp.2458–2925,2018.677

3. H.AlkahtaniandT.H.H.Aldhyani,‘‘Intrusiondetection system to advance Internet of Things infrastructurebaseddeeplearningalgorithms,’’Complexity,vol.2021, Jul.2021,Art.no.5579851.

4. D.I.Edeh,‘‘Networkintrusiondetectionsystemusing deep learning technique,’’ M.S. thesis, Dept. Comput., Univ.Turku,Turku,Finland,2021.

5. P.Wu,‘‘Deeplearningfornetworkintrusiondetection: Attack recognition with computational intelligence,’’ M.S.thesis,SchoolComput.Sci.Eng.,Univ.NewSouth Wales,SydneyNSW,Australia,2020.

6. 6.M.K.Putchala,‘‘Deeplearningapproachforintrusion detectionsystem(IDS)intheInternetofThings(IoT) networkusinggatedrecurrentneuralnetworks(GRU),’’ M.S.thesis,Dept.Comput.Sci.Eng.,WrightStateUniv., Dayton,OH,USA,2017.

7. H. Benmeziane, ‘‘Comparison of deep learning frameworksandcom-pilers,’’M.S.thesis,Dept.Comput. Sci.,ÉcoleNationaleSupérieured’Informatique,Oued Smar,Algeria,2020.

8. R.K.Vigneswaran,R.Vinayakumar,K.P.Soman,andP. Poornachandran, 695 ‘‘Evaluating shallow and deep neural networks for network intrusion detec- tion systems in cyber security,’’ in Proc. 9th Int. Conf. Comput.,Commun.Netw.Technol.(ICCCNT),Jul.2018, pp.1–6.

9. L. Alzubaidi, J. Zhang, A. J. Humaidi, A. Al-Dujaili, Y. Duan,O.Al-Shamma,J.Santamaría,M.A.Fadhel,M.AlAmidie, and L. Farhan, ‘‘Review of deep learning: Concepts,CNNarchitectures,challenges,appli-cations, futuredirections,’’J. BigData,vol.8,no.1,p.53,Dec. 2021,doi:10.1186/s40537-021-00444-8.

10. B. B. Rao and K. Swathi, ‘‘Fast kNN classifiers for network intrusion detection system,’’ Indian J. Sci. Technol.,vol.10,no.14,pp.1–10,2017

BIOGRAPHIES

VanakalaTanuja

StudentAndhraUniversityCollege of EngineeringForWomen

VarasalaGaganaSri StudentAndhraUniversityCollege ofEngineeringForWomen

VardhineniPavaniPrabha StudentAndhraUniversityCollege ofEngineeringForWomen

VavilapalliSravanthi

StudentAndhraUniversityCollege ofSEngineeringForWomen

Turn static files into dynamic content formats.

Create a flipbook
Intrusion Detection System Using LSTM by IRJET Journal - Issuu