Detection of anomalies in local traffic using secure gating networks

User Rating:  / 0
PoorBest 

Authors:


O. V. Lebid, orcid.org/0000-0003-4253-8696, Vinnytsia National Agrarian University, Vinnytsia, Ukraine; e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.

I. A. Chikov*, orcid.org/0000-0002-2128-5506, Vinnytsia National Agrarian University, Vinnytsia, Ukraine; e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.

S. V. Khrushchak, orcid.org/0009-0007-9452-4372, Vinnytsia National Agrarian University, Vinnytsia, Ukraine; e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.

S. V. Strikha, orcid.org/0000-0002-5937-7748, State Research Institute for Testing and Certification of Weapons and Military Equipment, Cherkasy, Ukraine, e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.

O. B. Piven, orcid.org/0000-0001-5601-8304, Cherkasy State Technological University, Cherkasy, Ukraine, e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.

M. S. Kovalenko, orcid.org/0009-0008-0577-3148, SCIRE Foundation, Warsaw, Poland;  Interregional Academy of Personnel Management, Kyiv, Ukraine, e-mail This email address is being protected from spambots. You need JavaScript enabled to view it.

* Corresponding author e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.


повний текст / full article



Naukovyi Visnyk Natsionalnoho Hirnychoho Universytetu. 2026, (4): 156 - 163

https://doi.org/10.33271/nvngu/2026-4/156



Abstract:



Purpose.
To develop and evaluate a method for detecting anomalies in local network traffic based on the FCRNN-GRU architecture in order to improve classification accuracy and reduce the rate of false positive alerts.


Methodology.
In the study, network interactions are represented as normalized time series, which makes it possible to capture the dynamics of traffic changes. The baseline model is a fully connected recurrent neural network capable of identifying complex nonlinear and long-term dependencies due to its densely connected recurrent structure. To improve training efficiency and avoid the vanishing gradient problem, mini-batch stochastic gradient descent is used. The additional integration of GRU (Gated Recurrent Unit) enables optimization of the trade-off between model accuracy and computational complexity. Experimental evaluation was conducted on a dataset of 52,000 network flows, including 32,000 normal traffic instances and 20,000 anomalous ones covering various types of cyber threats. The network environment was simulated on a Linux platform using Mininet and Wireshark, while algorithm implementation was carried out in Python.


Findings.
The FCRNN-GRU model demonstrates high performance: detection rate – 98.59 %, false alarm rate – 5.29 %, and classification accuracy – 99.21 %. Compared to traditional and clustering-based methods, the proposed approach provides a significant improvement and confirms its effectiveness.


Originality.
The scientific novelty of the study lies in the adaptation of a fully connected recurrent neural network with the integration of gated recurrent units for network traffic analysis tasks. The combination of dense recurrent connections with GRU mechanisms enables more accurate modeling of temporal patterns in traffic behavior, while simultaneously reducing computational costs and improving model efficiency when processing large volumes of data.


Practical value.
The proposed approach has practical significance and can be integrated into modern monitoring and cybersecurity systems. Its application contributes to the timely detection of anomalous events in the network, enhances the level of information infrastructure security, and reduces risks associated with cyber threats.



Keywords:
network anomalies, traffic flow, cybersecurity analytics, neural networks, information security

References.


1. Haidur, H. I., Gakhov, S. O., & Bryhynets, A. A. (2023). Detection of network anomalies using neural network algorithms. Telecommunication and Information Technologies, 1, 016173. https://doi.org/10.31673/2412-4338.2023.016173

2. Ilyenko, A., Ilyenko, S., Kravchuk, I., & Herasymenko, M. (2022). Prospective directions for traffic analysis and intrusion detection based on neural networks. Cybersecurity: Education, Science, Technique, 1(17), 46-56. https://doi.org/10.28925/2663-4023.2022.17.4656

3. Marchenko, R., Kovalenko, A., & Znaidiuk, V. (2024). Analysis of methods for detecting anomalous traffic in Internet of Things (IoT) networks. Systems of Control, Navigation and Communication, 1(1), 133-147. https://doi.org/10.26906/SUNZ.2024.1.133

4. Al‑Ghuwairi, A. R., Sharrab, Y., Al‑Fraihat, D., Al‑Ghazi, M., & Khatatneh, M. (2023). Intrusion detection in cloud computing based on time series anomalies utilizing machine learning. Journal of Cloud Computing, 12, 127. https://doi.org/10.1186/s13677-023-00491-x

5. Almuhanna, R., & Dardouri, S. (2025). A deep learning/machine learning approach for anomaly based network intrusion detection. Frontiers in Artificial Intelligence, 8, 1625891. https://doi.org/10.3389/frai.2025.1625891

6. Alsyaibani, O. M. A., Utami, E., Raharjo, S., & Hartanto, A. D. (2022). Stacked LSTM-GRU model for traffic anomalies detection. Telematika, 15(2), 81-91. https://doi.org/10.35671/telematika.v15i2.1855

7. Oğuz, H. T., & Kalaycıoğlu, A. (2022). Anomaly detection in multi‑tiered cellular networks using LSTM and 1D CNN. Journal on Wireless Communications and Networking, 101. https://doi.org/10.1186/s13638-022-02183-7

8. Wang, Y.-C., Houng, Y.-C., Chen, H.-X., & Tseng, S.-M. (2023). Network anomaly intrusion detection based on deep learning approach. Sensors, 23(4), 2171. https://doi.org/10.3390/s23042171

9. Lebid, O. V., Kiporenko, S. S., & Vovk, V. Y. (2023). Cyberattack detection and information security enhancement based on neural network technology in the conditions of cyberwar. Science and Technology Today, 1(15), 238-256. https://doi.org/10.52058/2786-6025-2023-1(15)-238-256

10.      Lebid, O. V., & Kiporenko, S. S. (2024). Integration of fractal analysis and machine learning for anomaly and cyberattack detection. Science and Technology Today, 12(40), 1294-1313. https://doi.org/10.52058/2786-6025-2024-12(40)-1294-1313

11.      Sisoienko, S., Babenko, V., & Zazhoma, V. (2025). Local area network traffic monitoring system with anomaly detection functionality. Science and Technology Today, 6(47), 1608-1619. https://doi.org/10.52058/2786-6025-2025-6(47)-1608-1619

12.      Chikov, I., Khaietska, O., Okhota, Yu., Titov, D., Prygotsky, V., & Nitsenko, V. (2023). Modeling of the synthetic indicator of competitiveness of agricultural enterprises: a methodological approach to the use of neural network tools. Financial and Credit Activity: Problems of Theory and Practice, 5(52), 222-242. https://doi.org/10.55643/fcaptp.5.52.2023.4149

13.      Bieliatynskyi, A., Bakulich, O., Bokyi, A., Kis, I., & Piven, O. (2024). Conceptual Model of Digital Transformation of Enterprise Management Processes. In E. Faure, Yu. Tryus, T. Vartiainen, O. Danchenko, M. Bondarenko, C. Bazilo, & G. Zaspa (Eds.). Information Technology for Education, Science, and Technics. ITEST 2024. Lecture Notes on Data Engineering and Communications Technologies, 222. Springer, Cham. https://doi.org/10.1007/978-3-031-71804-5_4

14.      Jain, G., Sharma, M., & Agarwal, B. (2019). Optimizing semantic LSTM for spam detection. International Journal of Information Technology, 11(2), 239-250. https://doi.org/10.1007/s41870-018-0157-5

15.      Yu, Y., Si, X., Hu, C., & Zhang, J. (2019). A review of recurrent neural networks: LSTM cells and network architectures. Neural Computation, 31, 1235-1270. https://doi.org/10.1162/neco_a_01199

16.      Khoroshko, V. A., Tkach, Yu. N., & Shelest, M. E. (2021). Multialternative detection of cyberatacs in information networks. Ukrainian Scientific Journal of Information Security, 26(3), 136-141.
https://doi.org/10.18372/2225-5036.27.16001

17.      Mahbub, M. (2020). Progressive researches on IoT security: An exhaustive analysis from the perspective of protocols, vulnerabilities, and preemptive architectonics. Journal of Network and Computer Applications, 168. https://doi.org/10.1016/j.jnca.2020.102761

18.      Valackienė, A., & Odejayi, R. O. (2024). The impact of cyber security management on the digital economy: multiple case study analysis. Intellectual Economics, 18(2), 261-283. https://doi.org/10.13165/IE-24-18-2-02

19.      Ślesicka, A., & Ślesicki, B. (2025). The use of deep learning for military vehicle identification in SAR imagery. Scientific Journal of Silesian University of Technology. Series Transport, 128, 251-268. https://doi.org/10.20858/sjsutst.2025.128.14

20.      Ingram, K., Diachenko, O., Halytskyi, O., Nitsenko, V., Romaniuk, M., & Zhumbei, M. (2022). Formalization of the Optimal Choice of the Activities of Agricultural Enterprises for the Implementation of Information and Communication Technologies. Financial and Credit Activity: Problems of Theory and Practice, 3(44), 141-149. https://doi.org/10.55643/fcaptp.3.44.2022.3758

21.      Kobets, D., Kasmin, D., Khruschak, S., Ziyautdinov, J., & Vodolazhska, T. (2025). Using artificial intelligence to optimize human resource management processes. Periodicals of Engineering and Natural Sciences, 13(3), 541-550. https://doi.org/10.21533/pen.v13.i3.504

 

Guest Book

If you have questions, comments or suggestions, you can write them in our "Guest Book"

Registration data

ISSN (print) 2071-2227,
ISSN (online) 2223-2362.
Journal was registered by Ministry of Justice of Ukraine.
Registration number КВ No.17742-6592PR dated April 27, 2011.

Contacts

D.Yavornytskyi ave.,19, pavilion 3, room 24-а, Dnipro, 49005
Tel.: +38 (066) 379 72 44.
e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.
You are here: Home Home EngCat Archive 2026 Content №4 2026 Detection of anomalies in local traffic using secure gating networks