An Intelligent Framework for Automated Cyber Threat Data Synthesis and Network Log Anomaly Detection Using Deep Learning NLP Architectures

Modern enterprise environments generate vast volumes of unstructured log data daily across cloud and local network assets. Traditional Security Operations Centers (SOCs reliance heavily on rule-based signature detection systems, which consistently struggle with log volume scaling and fail against novel zero-day exploits, leading to catastrophic analyst alert fatigue. This paper presents an intelligent, automated framework that utilizes advanced Natural Language Processing (NLP) models to ingest unstructured network logs, extract critical security entities, and automatically map adversarial activities to the MITRE ATT&CK framework. By deploying a serverless ingestion pipeline combined with a fine-tuned Transformer-based classification engine, the proposed architecture filters ambient network noise and synthesizes complex threat payloads in real-time. Experimental evaluations demonstrate that the framework achieves a 94.2% precision rate in threat entity classification while dramatically reducing the manual threat parsing window from hours to fractions of a second, offering a scalable infrastructure defense mechanism for modern enterprise tech stacks.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-04
DOI
https://doi.org/10.5281/zenodo.23135442
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

An Intelligent Framework for Automated Cyber Threat Data Synthesis and Network Log Anomaly Detection Using Deep Learning NLP Architectures

Venkata Neeraj Meka
Zenodo (CERN European Organization for Nuclear Research)
Network Security and Intrusion Detection
article

An Intelligent Framework for Automated Cyber Threat Data Synthesis and Network Log Anomaly Detection Using Deep Learning NLP Architectures

Venkata Neeraj Meka
article en

Abstract

Modern enterprise environments generate vast volumes of unstructured log data daily across cloud and local network assets. Traditional Security Operations Centers (SOCs reliance heavily on rule-based signature detection systems, which consistently struggle with log volume scaling and fail against novel zero-day exploits, leading to catastrophic analyst alert fatigue. This paper presents an intelligent, automated framework that utilizes advanced Natural Language Processing (NLP) models to ingest unstructured network logs, extract critical security entities, and automatically map adversarial activities to the MITRE ATT&CK framework. By deploying a serverless ingestion pipeline combined with a fine-tuned Transformer-based classification engine, the proposed architecture filters ambient network noise and synthesizes complex threat payloads in real-time. Experimental evaluations demonstrate that the framework achieves a 94.2% precision rate in threat entity classification while dramatically reducing the manual threat parsing window from hours to fractions of a second, offering a scalable infrastructure defense mechanism for modern enterprise tech stacks.

Zenodo (CERN European Organization for Nuclear Research)
Openalex Percentile: Top 11%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.