A Unified Behavioral Attack DNA Framework for Global Cyber Threat Detection Using Multi-Dataset Learning

Authors

Deepta Chakravarty

Department of Networking and Communications SRM Institute of Science and Technology Kattankulathur, Chennai, Tamil Nadu (India)

Mayukh Mondal

Department of Networking and Communications SRM Institute of Science and Technology Kattankulathur, Chennai, Tamil Nadu (India)

Disha Chaudhury

Department of Networking and Communications SRM Institute of Science and Technology Kattankulathur, Chennai, Tamil Nadu (India)

Dr. Lakshmi Dhevi B

Department of Networking and Communications SRM Institute of Science and Technology Kattankulathur, Chennai, Tamil Nadu (India)

Article Information

DOI: 10.51244/IJRSI.2026.1305000195

Subject Category: Engineering & Technology

Volume/Issue: 13/5 | Page No: 2140-2154

Publication Timeline

Submitted: 2026-05-26

Accepted: 2026-06-01

Published: 2026-06-09

Abstract

Cyber threats are becoming increasingly complex, and laws around data sovereignty are leading to increasingly complex regulations; this has rendered global collaboration in cybersecurity not only necessary but challenging. Traditional intrusion detection systems (IDSs) are often based on centralized architectures or signatures, which are inadequate against these attacks, which can change and evolve over the course of an attack. This paper introduces a single system of detecting the global cyber threats in the shape of the behavioral representation known as — Attack DNA. The features are combined in a systematical fashion to generate a common feature space for heterogeneous datasets of intrusion detection (CIC-IDS2017, NSL-KDD, UNSW-NB15 and TON_IoT); packet count, byte count, flow rate, etc. are used to produce a standardized description of network behavior in a variety of environments. It compares the sequence and feature-based models with the Long Short-Term Memory (LSTM) networks and Random Forest classifiers; the feature-based models are shown to be better in the case of non-temporal aggregated data. Also, a geographical analysis is conducted to assess differences in the pattern of attacks by different geographical sources, illustrating the usability of the framework in cybersecurity situations on a global scale. Results highlight the significance of standardized behavior for scalable, interpretable and cross-dataset intrusions.

Keywords

Cyber Threat Detection, Attack DNA, Behavioral Analysis, Intrusion Detection Systems, Multi-Dataset Learning, Random Forest, LSTM, Feature Engineering, Network Security.

Downloads

References

1. M. A. Alohali, M. Aljebreen, N. Ahmad, S. Alahmari, S. S. Albouq, A. Alqazzaz, H. Alkhiri, and Y. Said, “Privacy Preserving Blockchain Integrated Explainable Artificial Intelligence with Two Tier Optimization for Cyber Threat Detection,” 2025. [Google Scholar] [Crossref]

2. W. Ali, A. Sajid, T. A. Ghodke, R. Malik, N. Malik, and K. Kaushik, “Honeypot Comparison of Attack Detection and Mitigation of SSH Attack,” 2024. [Google Scholar] [Crossref]

3. J. Bi, Z. Guan, H. Yuan, and J. Zhang, “Improved Network Intrusion Classification with Attention-Assisted Bidirectional LSTM and Optimized Sparse Contractive Autoencoders,” 2024. [Google Scholar] [Crossref]

4. P. Cheimonidis and K. Rantos, “A Proactive and Time-Sensitive Cyber Risk Assessment Model Integrating Markov Chains and Bayesian Networks,” 2025. [Google Scholar] [Crossref]

5. M. Fan, Z. Si, X. Xie, Y. Liu, and T. Liu, “Text Backdoor Detection Using an Interpretable RNN Abstract Model,” 2021. [Google Scholar] [Crossref]

6. J. Franco, A. Arış, B. Canberk, and S. Uluagac, “A Survey of Honeypots and Honeynets for IoT, IIoT, and CPS,” 2021. [Google Scholar] [Crossref]

7. Y. Imrana, Y. Xiang, L. Ali, and Z. Abdul-Rauf, “A Bidirectional LSTM Deep Learning Approach for Intrusion Detection,” 2021. [Google Scholar] [Crossref]

8. J. Kang, H. Yang, Y. Zhang, Y. Dai, M. Zhan, and W. Wang, “ActDetector: A Sequence-Based Framework for Network Attack Activity Detection,” 2022. [Google Scholar] [Crossref]

9. Q. Liu, Y. Zhan, and B. Wang, “Secure and Efficient Cloud-Based Multi-Party Private Set Intersection with Union Protocol,” 2025. [Google Scholar] [Crossref]

10. N. Naik, C. Shang, P. Jenkins, and Q. Shen, “D-FRI-Honeypot: A Secure Sting Operation Using Dynamic Fuzzy Rule Interpolation,” 2021. [Google Scholar] [Crossref]

11. M. Raza, M. J. Saeed, M. B. Riaz, and M. A. Sattar, “Federated Learning for Privacy-Preserving Intrusion Detection in Software-Defined Networks,” 2024. [Google Scholar] [Crossref]

12. P. Revathi and S. Kingslin, “A Review of Privacy-Preserving Intrusion Detection for Healthcare Edge-IoT,” 2026. [Google Scholar] [Crossref]

13. M. A. O. Rabah, H. Drid, Y. Medjadba, and M. Rahouti, “Detection and Mitigation of DDoS Attacks Using Ensemble Learning and Honeypots in SDN-UAV Architecture,” 2024. [Google Scholar] [Crossref]

14. R. Ben Said, Z. Sabir, and I. Askerzade, “CNN-BiLSTM: A Hybrid Deep Learning Approach for Network Intrusion Detection,” 2023. [Google Scholar] [Crossref]

15. X. Wang, J. Liu, and C. Zhang, “Network Intrusion Detection Based on Multi-Domain Data and Ensemble Bidirectional LSTM,” 2023. [Google Scholar] [Crossref]

16. C. D. Xuan, “Detecting APT Attacks Based on Network Traffic Using Machine Learning,” 2021. [Google Scholar] [Crossref]

17. Y. Yang, S. Tu, R. H. Ali, H. Alasmary, M. Waqas, and M. N. Amjad, “Intrusion Detection Based on Bidirectional Long Short-Term Memory with Attention Mechanism,” 2023. [Google Scholar] [Crossref]

18. J. Zhang, L. Pan, Q.-L. Han, C. Chen, and S. Wen, “Deep Learning Based Attack Detection for Cyber-Physical System Cybersecurity: A Survey,” 2022. [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles