Enhancing Anomaly-Based Intrusion Detection with Hybrid Feature Selection and CNN–BiLSTM Architecture
Main Article Content
Abstract
Anomaly-based intrusion detection systems play a central role in identifying previously unseen and continuously evolving cyberattacks that are able to bypass traditional signature-based defences. Although deep learning has recently led to clear gains on modern intrusion detection benchmarks, several practical issues remain: network traffic is high-dimensional, class distributions are often heavily imbalanced, and feature selection is rarely integrated in a principled way with deep architectures. In this study, a hybrid feature selection and deep learning framework is developed for network anomaly detection and examined on two widely used datasets, UNSW-NB15 and CIC-IDS2017. The approach couples a two-stage filter–wrapper feature selection pipeline with a convolutional–bidirectional LSTM (CNN–BiLSTM) classifier, so that only the most informative traffic features are passed to the deep model. Across both datasets, the proposed system consistently achieves higher accuracy and F1-score, and a lower false positive rate, than a Random Forest baseline and a deep neural network trained on the full feature set. These results indicate that combining hybrid feature selection with a temporal deep architecture not only improves detection quality but also reduces computational overhead, making the framework a realistic candidate for deployment in contemporary network security environments..


