A Hybrid Deep Learning Framework for Real-Time Botnet Attack Detection in IoT Networks | IJCSE Volume 10 β Issue 5 | IJCSE-V10I5P20
IJCSE
International Journal of Computer Science Engineering Techniques
ISSN 2455-135X Β· Peer-Reviewed Β· Open Access
π Volume 10, Issue 5
π
September 29, 2026
π Pages 168β173
π ID: IJCSE-V10I5P20
Table of Contents
ToggleA Hybrid Deep Learning Framework for Real-Time Botnet Attack Detection in IoT Networks
Author(s)
Vadde Sai Sharan, Vijay Krishna M, Yashaswini BS
Abstract
Internet of Things deployment has outrun the security practice applied to it, leaving a large population of under-monitored, resource-constrained endpoints available to botnet families such as Mirai and BASHLITE. Detection models built around a single network architecture tend to capture either the spatial structure of a traffic flow or its temporal structure, but rarely both at once. This paper describes BotSentry, a framework in which convolutional, recurrent, LSTM and dense layers are chained into one trainable network that consumes flow-level features and assigns each flow to one of three operational tiers: Normal, Suspicious or Botnet. The model is not confined to offline scoring. It is embedded in a Flask/Socket.IO application backed by MySQL that reads the active network interface, derives flow features from live traffic counters, and pushes statistics, per-device status and threat alerts to a browser dashboard without a page reload, while retaining a conventional upload-and-analyse path for pre-captured traffic. Training and inference share one preprocessing pipeline – cleaning, encoding, scaling and SMOTE-based balancing of the training partition – so the transformation applied to a live flow is by construction the transformation the model was fitted under. Section VI reports accuracy, precision, recall, F1-score, ROC-AUC and PR-AUC on a held-out test set. The contribution lies less in the individual components than in their arrangement: a hybrid spatial-sequential classifier delivered as a working capture-to-alert system rather than a notebook result.
Keywords
IoT Security; Botnet Detection; Hybrid Deep Learning; ANN; CNN; RNN; LSTM; Network Traffic Analysis; Cybersecurity; Intrusion Detection System (IDS); DDoS Detection.
Conclusion
This paper has described BotSentry, a botnet detection framework for IoT and Wi-Fi networks that joins a hybrid CNN-RNN-LSTM-ANN classifier to a live capture-to-alert pipeline, a MySQL detection history, and a dashboard requiring no manual interface configuration. Much of the surveyed literature stops at an offline score. BotSentry instead runs the trained model inside a system where training-time and inference-time preprocessing are the same persisted objects, which removes a class of deployment failure that is easy to introduce and hard to notice. Several extensions suggest themselves: optional raw packet capture for richer flow features, simultaneous monitoring across multiple interfaces, and email or SMS alert delivery. The more substantial piece of follow-up work is a controlled comparison – retraining ACLR [8] and the baselines from [1] and [3]-[7] on the dataset and split used here, so that Table III can be replaced with a like-for-like benchmark.
References
Y. Meidan, M. Bohadana, Y. Mathov, Y. Mirsky, A. Shabtai, D. Breitenbacher, and Y. Elovici, "N-BaIoTβNetwork-Based Detection of IoT Botnet Attacks Using Deep Autoencoders," IEEE Pervasive Computing, vol. 17, no. 3, pp. 12β22, 2018.
[2] N. Koroniotis, N. Moustafa, E. Sitnikova, and B. Turnbull, "Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset," Future Generation Computer Systems, vol. 100, pp. 779β796, 2019.
[3] M. S. Alshehri et al., "SkipGateNet: A Lightweight CNN-LSTM Hybrid Model with Learnable Skip Connections for Efficient Botnet Attack Detection in IoT," IEEE Access, 2024, doi: 10.1109/ACCESS.2024.3371992.
[4] A. R. Arun, A. R. de Souza, S. Sairam, V. Vani, and N. Karthik, "IoT Botnet Detection using a Hybrid of CNN-LSTM with Blockchain," in Proc. 2024 Int. Conf. Computing and Intelligent Reality Technologies (ICCIRT), IEEE, 2024, pp. 293β297.
[5] A. Nazir, J. He, N. Zhu, S. S. Qureshi, S. U. Qureshi, F. Ullah, A. Wajahat, and M. S. Pathan, "A deep learning-based novel hybrid CNN-LSTM architecture for efficient detection of threats in the IoT ecosystem," Ain Shams Engineering Journal, vol. 15, no. 7, 2024, doi: 10.1016/j.asej.2024.102777.
[6] "Efficient IoT Intrusion Detection with an Improved Attention-Based CNN-BiLSTM Architecture," arXiv:2503.19339, 2025.
[7] "A high performance hybrid LSTM CNN secure architecture for IoT environments using deep learning," Scientific Reports, 2025.
[8] M. Ali, M. Shahroz, M. F. Mushtaq, S. Alfarhood, M. Safran, and I. Ashraf, "Hybrid Machine Learning Model for Efficient Botnet Attack Detection in IoT Environment," IEEE Access, vol. 12, pp. 40682β40699, 2024, doi: 10.1109/ACCESS.2024.3376400.
[9] N. Moustafa and J. Slay, "UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set)," in Proc. Military Communications and Information Systems Conference (MilCIS), Nov. 2015, pp. 1β6.
[2] N. Koroniotis, N. Moustafa, E. Sitnikova, and B. Turnbull, "Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset," Future Generation Computer Systems, vol. 100, pp. 779β796, 2019.
[3] M. S. Alshehri et al., "SkipGateNet: A Lightweight CNN-LSTM Hybrid Model with Learnable Skip Connections for Efficient Botnet Attack Detection in IoT," IEEE Access, 2024, doi: 10.1109/ACCESS.2024.3371992.
[4] A. R. Arun, A. R. de Souza, S. Sairam, V. Vani, and N. Karthik, "IoT Botnet Detection using a Hybrid of CNN-LSTM with Blockchain," in Proc. 2024 Int. Conf. Computing and Intelligent Reality Technologies (ICCIRT), IEEE, 2024, pp. 293β297.
[5] A. Nazir, J. He, N. Zhu, S. S. Qureshi, S. U. Qureshi, F. Ullah, A. Wajahat, and M. S. Pathan, "A deep learning-based novel hybrid CNN-LSTM architecture for efficient detection of threats in the IoT ecosystem," Ain Shams Engineering Journal, vol. 15, no. 7, 2024, doi: 10.1016/j.asej.2024.102777.
[6] "Efficient IoT Intrusion Detection with an Improved Attention-Based CNN-BiLSTM Architecture," arXiv:2503.19339, 2025.
[7] "A high performance hybrid LSTM CNN secure architecture for IoT environments using deep learning," Scientific Reports, 2025.
[8] M. Ali, M. Shahroz, M. F. Mushtaq, S. Alfarhood, M. Safran, and I. Ashraf, "Hybrid Machine Learning Model for Efficient Botnet Attack Detection in IoT Environment," IEEE Access, vol. 12, pp. 40682β40699, 2024, doi: 10.1109/ACCESS.2024.3376400.
[9] N. Moustafa and J. Slay, "UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set)," in Proc. Military Communications and Information Systems Conference (MilCIS), Nov. 2015, pp. 1β6.
π How to Cite This Paper
Vadde Sai Sharan, Vijay Krishna M, Yashaswini BS (2026). A Hybrid Deep Learning Framework for Real-Time Botnet Attack Detection in IoT Networks. International Journal of Computer Science Engineering Techniques, 10(5), 168β173. ISSN: 2455-135X. DOI: https://doi.org/10.5281/zenodo.23030122

