Authors

Sonali Kurian

Dept. of Information Science Engineering, AMC Engineering College, Karnataka, India

Srijal Singhai

Dept. of Information Science Engineering, AMC Engineering College, Karnataka, India

Amit Kulkarni

Dept. of Information Science Engineering, AMC Engineering College, Karnataka, India

Satyendra Shukla

Dept. of Information Science Engineering, AMC Engineering College, Karnataka, India

Abstract

This research systematically addresses the increasing operational burden experienced by Security Operations Center (SOC) analysts by introducing an intelligent automation framework for cyber threat detection. Modern SOC environments are overwhelmed by high-volume alert streams, heterogeneous data sources, and sophisticated attack vectors, often leading to alert fatigue, delayed incident response, and increased false-positive rates. To mitigate these challenges, we propose a dual-model machine learning architecture specifically engineered to automate the detection of two high-impact and widely prevalent cyber threats: Trojan malware intrusions and Distributed Denial of Service (DDoS) attacks. The proposed framework adopts a modular design in which each attack category is managed by a dedicated, independently optimized detection engine. This separation enhances model specialization, interpretability, and scalability while minimizing computational overhead. By offloading repetitive analytical tasks to intelligent models, the framework significantly reduces manual triage efforts and enables SOC analysts to focus on high-priority incidents and strategic threat analysis. The first detection engine targets Trojan-based intrusions using a hybrid deep learning methodology that combines unsupervised and supervised learning paradigms. A multi-layer stacked autoencoder is employed for hierarchical feature extraction and dimensionality reduction. From an initial set of 86 network traffic attributes—including flow duration, packet statistics, header metadata, and protocol behavior—the autoencoder compresses the input space into a compact 16-dimensional latent representation. This latent embedding effectively captures nonlinear correlations and subtle behavioral signatures associated with Trojan communication patterns, including command-and-control (C2) activities and covert data exfiltration. The reduced feature set is subsequently processed by a Random Forest classifier, which performs robust ensemble-based supervised classification. The integration of ensemble decision trees enhances generalization capability, improves resilience against overfitting, and significantly lowers false-positive rates compared to traditional signature-based or shallow learning approaches. The second detection engine focuses on identifying DDoS attacks through a multi-stage analytical pipeline designed to capture both volumetric anomalies and temporal attack evolution. Initially, an autoencoder-based anomaly detection module establishes a baseline model of legitimate traffic behavior and flags statistically significant deviations. These anomalous traffic instances are then evaluated using a Logistic Regression classifier, which provides probabilistic discrimination between benign bursts and malicious flooding activities.

Keywords

DDoS Detection Trojan detection Machine Learning Cyber Security Security Operation center

Citation of this Article

Sonali Kurian, Srijal Singhai, Amit Kulkarni, & Satyendra Shukla. (2026). AI-Driven Automation of SOC Workflows Using Hybrid Models for Trojan and DDoS Attack Identification. Current Journal of Engineering and Science Research. 3(2), 6-21. Article DOI: https://doi.org/10.47001/CJESR/2026.302002

Licence Copyright (c) 2026 Current Journal of Engineering and Science Research. This work is licensed under a Creative Commons Attribution Non Commercial 4.0 International Licence.

References

  1. U. Bayer, C. Kruegel, and E. Kirda, "TTAnalyze: A tool for analyzing malware," Proceedings of the 15th European Institute for Computer Antivirus Research Annual Conference, 2006.
  2. M. Egele, T. Scholte, E. Kirda, and C. Kruegel, "A survey on automated dynamic malware-analysis techniques and tools," ACM Computing Surveys, vol. 44, no. 2, pp. 1-42, 2012.
  3. A.Mohaisen, O. Alrawi, and M. Mohaisen, "AMAL: High-fidelity, behavior-based automated malware analysis and classification," Computers & Security, vol. 52, pp. 251-266, 2015.
  4. U. Bayer, C. Kruegel, and E. Kirda, "TTAnalyze: A tool for analyzing malware," Proceedings of the 15th European Institute for Computer Antivirus Research Annual Conference, 2006.
  5. J. Z. Kolter and M. A. Maloof, "Learning to detect and classify malicious executables in the wild," Journal of Machine Learning Research, vol. 7, pp. 2721-2744, 2006.
  6. M. Ahmadi, D. Ulyanov, S. Semenov, M. Trofimov, and G. Giacinto, "Novel feature extraction, selection and fusion for effective malware family classification," Proceedings of the Sixth ACM Conference on Data and Application Security and Privacy, pp. 183-194, 2016.
  7. R. Ronen, M. Radu, C. Feuerstein, E. Yom-Tov, and M. Ahmadi, "Microsoft malware classification challenge," arXiv preprint arXiv:1802.10135, 2018.
  8. J. Saxe and K. Berlin, "Deep neural network based malware detection using two dimensional binary program features," International Conference on Malicious and Unwanted Software, pp. 11-20, 2015.
  9. G. E. Dahl, J. W. Stokes, L. Deng, and D. Yu, "Large-scale malware classification using random projections and neural networks," IEEE International Conference on Acoustics, Speech and Signal Processing, pp. 3422-3426, 2013.
  10. E. Raff, J. Barker, J. Sylvester, R. Brandon, B. Catanzaro, and C. Nicholas, "Malware detection by eating a whole EXE," AAAI Workshop on Artificial Intelligence for Cyber Security, 2018.
  11. R. Pascanu, J. W. Stokes, H. Sanossian, M. Marinescu, and A. Thomas, "Malware classification with recurrent networks," IEEE International Conference on Acoustics, Speech and Signal Processing, pp. 1916-1920, 2015.
  12. R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, A. Al-Nemrat, and S. Venkatraman, "Deep learning approach for intelligent intrusion detection system," IEEE Access, vol. 7, pp. 41525-41550, 2019.
  13. W. Wang, M. Zhu, X. Zeng, X. Ye, and Y. Sheng, "Malware traffic classification using convolutional neural network for representation learning," Information Sciences, vol. 433, pp. 234-245, 2018.
  14. R. Agrawal, J. W. Stokes, M. Marinescu, and K. Selvaraj, "Neural sequential malware detection with parameters," IEEE International Conference on Acoustics, Speech and Signal Processing, pp. 2746-2750, 2019.
  15. B. Anderson, S. Paul, and D. McGrew, "Deciphering malware's use of TLS (without decryption)," Journal of Computer Virology and Hacking Techniques, vol. 14, no. 3, pp. 195-211, 2018.
  16. S. Garcia, M. Grill, J. Stiborek, and A. Zunino, "An empirical comparison of botnet detection methods," Computers & Security, vol. 45, pp. 100-123, 2014.
  17. G. Aceto, D. Ciuonzo, A. Montieri, and A. Pescapé, "Mobile encrypted traffic classification using deep learning: Experimental evaluation, lessons learned, and challenges," IEEE Transactions on Network and Service Management, vol. 16, no. 2, pp. 445-458, 2019.
  18. F. A. Narudin, A. Feizollah, N. B. Anuar, and A. Gani, "Evaluation of machine learning classifiers for mobile malware detection," Soft Computing, vol. 20, no. 1, pp. 343-357, 2016.
  19. E. Menahem, A. Shabtai, L. Rokach, and Y. Elovici, "Improving malware detection by applying multi-inducer ensemble," Computational Statistics & Data Analysis, vol. 53, no. 4, pp. 1483-1494, 2009.
  20. R. Sommer and V. Paxson, "Outside the closed world: On using machine learning for network intrusion detection," IEEE Symposium on Security and Privacy, pp. 305-316, 2010.
  21. S. Mahadik, P. M. Pawar, and R. Muthalagu, “Efficient Intelligent Intrusion Detection System for Heterogeneous Internet of Things (HetIoT),” Journal of Network and Systems Management, vol. 31, no. 1, Oct. 2022, doi: https://doi.org/10.1007/s10922-022-09697-x.
  22. M. Esmaeili, S. H. Goki, B. H. K. Masjidi, M. Sameh, H. Gharagozlou, and A. S. Mohammed, “ML-DDoSnet: IoT Intrusion Detection Based on Denial-of-Service Attacks Using Machine Learning Methods and NSL-KDD,” Wireless Communications and Mobile Computing, vol. 2022, pp. 1–16, Aug. 2022, doi: https://doi.org/10.1155/2022/8481452.
  23. Kamaldeep, M. Malik, and Dr. M. Dutta, “Feature Engineering and Machine Learning Framework for DDoS Attack Detection in the Standardized Internet of Things,” IEEE Internet of Things Journal, pp. 1–1, 2023, doi: https://doi.org/10.1109/jiot.2023.3245153.
  24. K. B. Adedeji, A. M. Abu-Mahfouz, and A. M. Kurien, “DDoS Attack and Detection Methods in InternetEnabled Networks: Concept, Research Perspectives, and Challenges,” Journal of Sensor and Actuator Networks, vol. 12, no. 4, p. 51, Aug. 2023.
  25. S. Shanmuga. Priya, M. Sivaram, D. Yuvaraj, and A. Jayanthiladevi, “Machine Learning based DDOS Detection,” 2020 International Conference on Emerging Smart Computing and Informatics (ESCI), Mar. 2020, doi: https://doi.org/10.1109/esci48226.2020.9167642.
  26. K. Kumari and M. Mrunalini, “Detecting Denial of Service attacks using machine learning algorithms,” Journal of Big Data, vol. 9, no. 1, Apr. 2022, doi: https://doi.org/10.1186/s40537-022-00616-0.
  27. Mirkovic, J., & Reiher, P. (2004). A taxonomy of DDoS attack and DDoS defense mechanisms. ACM SIGCOMM Computer Communication Review, 34(2), 39–53.