Home / Current Issue / Paper 1718901
Deep Learning Based Attribution of Threat Activity in Network Forensic Analytics
Subject area: Science,Engineering and Technology · Area of research: Cyber Security
DOI: 10.64388/IREV9I12-1718901
Abstract
Attributing malicious network activity to specific threat actors remains a critical challenge in digital forensics due to encrypted traffic and high volume of network data. Conventional rule-based and signature-based methods lack generalization and cannot capture the spatial and temporal dependencies that characterize advanced persistent threats. This paper presents a deep learning framework that combines Convolutional Neural Networks and Recurrent Neural Networks for automated attribution of threat activity within network forensics analytics. The framework employs CNN to extract Spatial features from packet-level and flow-level traffic representations, identifying structural patterns, protocol anomalies, and payload signatures indicative of malicious behavior. Temporal dynamics and attack progression are modeled using RNNs with gated Recurrent Units, enabling the system to learn sequential patterns in tactics, techniques, and procedures across network sessions. Evaluation was performed on the CICIoT2023 dataset, which was adopted because of its scale, diversity, and relevance to modern IoT security environments. The hybrid CNN-RNN model called Intelligent Network Forensic Investigative Model (INFIM) achieved 98.3% accuracy, 98.4% F1-Score, 98.7% precision, and 98.5% recall for multiclass attribution. Ablation analysis confirms that both spatial and temporal components are essential, particularly under imbalanced and low-signal conditions. The system also demonstrates robustness against common evasion ways, such as traffic padding and minor protocol obfuscation. This work shows that integrating CNN and RNN architectures improves the scalability and accuracy of network forensic attribution, reducing analyst burden and supporting timely incident response.
Keywords
Convolutional Neural Network, Deep Learning, Network Forensic Analytics, Recurrent Neural Network.
References
[1] Akinyokun, O. (2024). Hybridized digital forensic investigative models for cybercrime analysis. International Journal of Cybersecurity Research, 15(2), 112–128.
[2] Alansari, M. (2023). Network forensics and intelligent intrusion analysis. Journal of Information Security, 18(4), 201– 219.
[3] Carrier, B. (2005). File system forensic analysis. Addison-Wesley.
[4] Casey, E. (2011). Digital evidence and computer crime (3rd ed.). Academic Press.
[5] Chen, L., Wang, H., & Li, J. (2024). Deep neural intrusion detection in IoT networks. IEEE Access, 12, 22451–22469.
[6] Farooq, M. (2023). Deep learning techniques for cybersecurity analytics. Computers & Security, 128, 103102.
[7] Hnamte, L., & Hussain, A. (2023). Explainable AI in cybersecurity systems. Expert Systems with Applications, 219, 119580.
[8] Idrissi, A., Karim, M., & Hassan, R. (2023). CNN-LSTM network intrusion detection systems. Applied Soft Computing, 136, 110021.
[9] Kalakoti, R., Singh, P., & Rao, S. (2025). Federated explainable intrusion detection systems. IEEE Transactions on Dependable and Secure Computing, 22(1), 114–129.
[10] Koroniotis, N., & Moustafa, N. (2020). Explainable cyber threat intelligence using machine learning. Future Generation Computer Systems, 112, 360–372.
[11] Kumar, S., & Manash, P. (2019). Deep learning applications in cybersecurity. Cybersecurity Review, 6(1), 44–59.
[12] Moustafa, N., & Slay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems. Military Communications and Information Systems Conference, 1–6.
[13] Schultz, E., & Garfinkel, S. (2012). Computer forensics and digital investigation. Wiley.
[14] Zeadally, S., Patel, A., & Gupta, D. (2020). Deep learning techniques for cyberattacks detection. IEEE Communications Surveys & Tutorials, 22(3), 1982–2012.
How to cite this paper
@article{1718901,
author = {Olarinde O. O., Adewale O. S., Agbonifo O. C., Taiwo O.},
title = {Deep Learning Based Attribution of Threat Activity in Network Forensic Analytics},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {9},
number = {12},
pages = {1762-1767},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1718901.pdf},
abstract = {Attributing malicious network activity to specific threat actors remains a critical challenge in digital forensics due to encrypted traffic and high volume of network data. Conventional rule-based and signature-based methods lack generalization and cannot capture the spatial and temporal dependencies that characterize advanced persistent threats. This paper presents a deep learning framework that combines Convolutional Neural Networks and Recurrent Neural Networks for automated attribution of threat activity within network forensics analytics. The framework employs CNN to extract Spatial features from packet-level and flow-level traffic representations, identifying structural patterns, protocol anomalies, and payload signatures indicative of malicious behavior. Temporal dynamics and attack progression are modeled using RNNs with gated Recurrent Units, enabling the system to learn sequential patterns in tactics, techniques, and procedures across network sessions. Evaluation was performed on the CICIoT2023 dataset, which was adopted because of its scale, diversity, and relevance to modern IoT security environments. The hybrid CNN-RNN model called Intelligent Network Forensic Investigative Model (INFIM) achieved 98.3% accuracy, 98.4% F1-Score, 98.7% precision, and 98.5% recall for multiclass attribution. Ablation analysis confirms that both spatial and temporal components are essential, particularly under imbalanced and low-signal conditions. The system also demonstrates robustness against common evasion ways, such as traffic padding and minor protocol obfuscation. This work shows that integrating CNN and RNN architectures improves the scalability and accuracy of network forensic attribution, reducing analyst burden and supporting timely incident response.},
keywords = {Convolutional Neural Network, Deep Learning, Network Forensic Analytics, Recurrent Neural Network.},
month = {June},
doi = {https://doi.org/10.64388/IREV9I12-1718901}
}