Sequence-Based Threat Identification in Modern Networks Via Recurrent Memory Architectures and Game-Theoretic Feature Verification
Main Article Content
Abstract
Contemporary network infrastructure faces sophisticated, multi-phase attack campaigns such as stealthy reconnaissance and Advanced Persistent Threats (APTs) that unfold deliberately across elongated time frames. Traditional point-in-time machine learning approaches parse network transactions as discrete, isolated entities, neglecting the vital directional dependencies embedded within traffic sequences. This investigation introduces a robust sequence-aware intrusion detection framework leveraging recurrent Long Short-Term Memory (LSTM) neural networks. When evaluated against the benchmark UNSW-NB15 dataset, the architecture dynamically captures deep historical dependencies hidden across contiguous communication sequences. Empirical execution demonstrates optimal performance, yielding a 97.5% classification accuracy and an F1-score of 97.0%. To guarantee model transparency and alignment with security operations, a post-hoc diagnostic layer utilizing game-theoretic attributions translates the complex parameter gates of the network into explicit, human-interpretable feature importance metrics at the connection layer