A Hybrid Deep Learning Framework for Real-Time Botnet Attack Detection in IoT Networks
Internet of Things deployment has outrun the security practice applied to it, leaving a large population of under-monitored, resource-constrained endpoints available to botnet families such as Mirai and BASHLITE. Detection models built around a single network architecture tend to capture either the spatial structure of a traffic flow or its temporal structure, but rarely both at once. This paper describes BotSentry, a framework in which convolutional, recurrent, LSTM and dense layers are chained into one trainable network that consumes flow-level features and assigns each flow to one of three operational tiers: Normal, Suspicious or Botnet. The model is not confined to offline scoring. It is embedded in a Flask/Socket.IO application backed by MySQL that reads the active network interface, derives flow features from live traffic counters, and pushes statistics, per-device status and threat alerts to a browser dashboard without a page reload, while retaining a conventional upload-and-analyse path for pre-captured traffic. Training and inference share one preprocessing pipeline - cleaning, encoding, scaling and SMOTE-based balancing of the training partition - so the transformation applied to a live flow is by construction the transformation the model was fitted under. Section VI reports accuracy, precision, recall, F1-score, ROC-AUC and PR-AUC on a held-out test set. The contribution lies less in the individual components than in their arrangement: a hybrid spatial-sequential classifier delivered as a working capture-to-alert system rather than a notebook result.
Authors
- Vijay Krishna M
- Yashaswini BS
- Vadde Sai Sharan
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-29
- DOI
- https://doi.org/10.5281/zenodo.23030121
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00