DoctorateOpen Access

Derin öğrenme tekniklerinin hibrit yöntemini kullanarak farklı saldırıları tespit etmek için SDN ortamına yönelik siber güvenlik sistemi

2025
0 views
0 downloads
Advisor: Prof. Dr. Osman Nuri Uçan

Abstract (EN)

As contemporary networks come under attack with sophisticated and mass-scale cyber-threats, traditional intrusion detection systems (IDS) are unable to cope with changing threats. Such limitations are the focus of this research, and two new deep learning-based frameworks are introduced, which are best suited for fast and effective intrusion detection in Software-Defined Network (SDN) environments: (1) the Adversarial Learning-based Multi-Branched Hybrid Architecture and (2) the Multi-Branched Hybrid Perceptron Network (MBHPN). Together, these models offer an intelligent and scalable IDS platform that can detect advanced threats, in particular Distributed Denial of Service (DDoS) attacks, through adaptive learning, real-time integration, and context analysis. The first architecture, as explained in Chapter 3, combines Convolutional Neural Networks (CNN), Capsule Networks, and Long Short-Term Memory (LSTM) layers in a multi-branch architecture. CNNs encode spatial dependencies, Capsule Networks preserve hierarchical relations among features, and LSTMs describe sequential behaviors of traffic flows. The framework also incorporates Dynamic Adversarial Learning, where adversarial samples are produced to mimic attacks, thus enhancing model robustness. Each branch produces a unique feature representation, which is combined using attention-weighted methods to create an integrated, discriminative feature space tailored for intrusion detection. In Chapter 4, this architecture is enriched by the addition of MBHPN, which is directly optimized for DDoS attack detection. This network combines three deep learning branches: MLP, DenseNet-like, and ResNet-like units. It adds Dynamic Feature Adaptation (DFA) to down-regulate noisy features and up-regulate pertinent traffic signatures. Multi-instance Learning (MIL) to process aggregated traffic flows instead of standalone instances, and thus greatly enhances contextual perception. These improvements make MBHPN robust against class imbalance, evasion attacks, and changing attack patterns prevalent in actual networks. The models are trained and tested on three intrusion detection benchmark datasets: UNSW-NB15, CICIDS2017, and CSE-CIC-IDS2018, which contain varied traffic patterns and attack conditions. Proven through extensive experimentation, the models outperform the current state of affairs. On the UNSW-NB15 dataset, MBHPN reports 99.31% accuracy, 98.02% precision, 98.87% recall, and an F1-score of 98.44% with a false positive ratio (FPR) decreased to 0.61% from the original 1.12% FPR of the base model. The time taken for inference reduced from 7.8 ms to 5.3 ms, which reflects a 32% boost in speed from SDNetc integration.

Author

Dr. Alı Tarıq Kalıl Al Khayyat

How to Cite

Alı Tarıq Kalıl Al Khayyat (Doctorate thesis). Derin öğrenme tekniklerinin hibrit yöntemini kullanarak farklı saldırıları tespit etmek için SDN ortamına yönelik siber güvenlik sistemi, 2025, Altınbaş University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Altınbaş University