A Hybrid Deep Learning Framework for Real-Time Botnet Attack Detection in IoT Networks | IJCSE Volume 10 – Issue 5 | IJCSE-V10I5P20

IJCSE
International Journal of Computer Science Engineering Techniques
ISSN 2455-135X Β· Peer-Reviewed Β· Open Access
πŸ“š Volume 10, Issue 5
πŸ“… September 29, 2026
πŸ“„ Pages 168–173
πŸ”– ID: IJCSE-V10I5P20

A Hybrid Deep Learning Framework for Real-Time Botnet Attack Detection in IoT Networks

Author(s)

Vadde Sai Sharan, Vijay Krishna M, Yashaswini BS

Abstract

Internet of Things deployment has outrun the security practice applied to it, leaving a large population of under-monitored, resource-constrained endpoints available to botnet families such as Mirai and BASHLITE. Detection models built around a single network architecture tend to capture either the spatial structure of a traffic flow or its temporal structure, but rarely both at once. This paper describes BotSentry, a framework in which convolutional, recurrent, LSTM and dense layers are chained into one trainable network that consumes flow-level features and assigns each flow to one of three operational tiers: Normal, Suspicious or Botnet. The model is not confined to offline scoring. It is embedded in a Flask/Socket.IO application backed by MySQL that reads the active network interface, derives flow features from live traffic counters, and pushes statistics, per-device status and threat alerts to a browser dashboard without a page reload, while retaining a conventional upload-and-analyse path for pre-captured traffic. Training and inference share one preprocessing pipeline – cleaning, encoding, scaling and SMOTE-based balancing of the training partition – so the transformation applied to a live flow is by construction the transformation the model was fitted under. Section VI reports accuracy, precision, recall, F1-score, ROC-AUC and PR-AUC on a held-out test set. The contribution lies less in the individual components than in their arrangement: a hybrid spatial-sequential classifier delivered as a working capture-to-alert system rather than a notebook result.

Keywords

IoT Security; Botnet Detection; Hybrid Deep Learning; ANN; CNN; RNN; LSTM; Network Traffic Analysis; Cybersecurity; Intrusion Detection System (IDS); DDoS Detection.

Conclusion

This paper has described BotSentry, a botnet detection framework for IoT and Wi-Fi networks that joins a hybrid CNN-RNN-LSTM-ANN classifier to a live capture-to-alert pipeline, a MySQL detection history, and a dashboard requiring no manual interface configuration. Much of the surveyed literature stops at an offline score. BotSentry instead runs the trained model inside a system where training-time and inference-time preprocessing are the same persisted objects, which removes a class of deployment failure that is easy to introduce and hard to notice. Several extensions suggest themselves: optional raw packet capture for richer flow features, simultaneous monitoring across multiple interfaces, and email or SMS alert delivery. The more substantial piece of follow-up work is a controlled comparison – retraining ACLR [8] and the baselines from [1] and [3]-[7] on the dataset and split used here, so that Table III can be replaced with a like-for-like benchmark.

References

Y. Meidan, M. Bohadana, Y. Mathov, Y. Mirsky, A. Shabtai, D. Breitenbacher, and Y. Elovici, "N-BaIoTβ€”Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders," IEEE Pervasive Computing, vol. 17, no. 3, pp. 12–22, 2018.
[2] N. Koroniotis, N. Moustafa, E. Sitnikova, and B. Turnbull, "Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset," Future Generation Computer Systems, vol. 100, pp. 779–796, 2019.
[3] M. S. Alshehri et al., "SkipGateNet: A Lightweight CNN-LSTM Hybrid Model with Learnable Skip Connections for Efficient Botnet Attack Detection in IoT," IEEE Access, 2024, doi: 10.1109/ACCESS.2024.3371992.
[4] A. R. Arun, A. R. de Souza, S. Sairam, V. Vani, and N. Karthik, "IoT Botnet Detection using a Hybrid of CNN-LSTM with Blockchain," in Proc. 2024 Int. Conf. Computing and Intelligent Reality Technologies (ICCIRT), IEEE, 2024, pp. 293–297.
[5] A. Nazir, J. He, N. Zhu, S. S. Qureshi, S. U. Qureshi, F. Ullah, A. Wajahat, and M. S. Pathan, "A deep learning-based novel hybrid CNN-LSTM architecture for efficient detection of threats in the IoT ecosystem," Ain Shams Engineering Journal, vol. 15, no. 7, 2024, doi: 10.1016/j.asej.2024.102777.
[6] "Efficient IoT Intrusion Detection with an Improved Attention-Based CNN-BiLSTM Architecture," arXiv:2503.19339, 2025.
[7] "A high performance hybrid LSTM CNN secure architecture for IoT environments using deep learning," Scientific Reports, 2025.
[8] M. Ali, M. Shahroz, M. F. Mushtaq, S. Alfarhood, M. Safran, and I. Ashraf, "Hybrid Machine Learning Model for Efficient Botnet Attack Detection in IoT Environment," IEEE Access, vol. 12, pp. 40682–40699, 2024, doi: 10.1109/ACCESS.2024.3376400.
[9] N. Moustafa and J. Slay, "UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set)," in Proc. Military Communications and Information Systems Conference (MilCIS), Nov. 2015, pp. 1–6.

πŸ“‹ How to Cite This Paper

Vadde Sai Sharan, Vijay Krishna M, Yashaswini BS (2026). A Hybrid Deep Learning Framework for Real-Time Botnet Attack Detection in IoT Networks. International Journal of Computer Science Engineering Techniques, 10(5), 168–173. ISSN: 2455-135X. DOI: https://doi.org/10.5281/zenodo.23030122
Β© 2026 International Journal of Computer Science Engineering Techniques (IJCSE). All rights reserved. Β· ijcsejournal.org

Related Post

Submit Your Paper