Intelligent Agents in Cybersecurity: Deep Learning to Analyze User Behavior Applying
- 1 Ecole Nationale Supérieure Polytechnique, Université Marien Ngouabi, Brazzaville, Republic of Congo
- 2 Ecole Nationale Supérieure Polytechnique, Université Marien Ngouabi, Brazzaville, Republic of Congo
- 3 Ecole Nationale Supérieure Polytechnique, Université Marien Ngouabi, Brazzaville, Republic of Congo
Abstract
The research aim is to develop an intelligent agent for cybersecurity systems capable of detecting abnormal user behavior using deep learning methods and ensuring interpretability of decisions. A four-module architecture is proposed: log collection and aggregation, behavioral feature generation, analysis using the Long Short-Term Memory (LSTM) + Attention model, and an interpretation module. A hybrid approach is used that combines log processing, temporal neural networks and an attention mechanism to identify significant actions in the behavioral chain. Testing was conducted on the Computer Emergency Response Team (CERT) and the Australian Defence Force Academy Linux Dataset (ADFA-LD) datasets. The developed system demonstrated high accuracy rates (ROC-AUC > 0.95), as well as superiority over classical and modern models (Logistic Regression, Random Forest, and Autoencoder). The attention mechanism ensured interpretability: it became possible to visually determine which user actions caused the alarm. A method for preparing logs and forming training samples is proposed. The intelligent agent can be integrated into corporate Security Information and Event Management (SIEM)/User and Entity Behavior Analytics (UEBA) systems, used in monitoring centers and applied in educational practice. Scientific novelty is manifested in the architecture, the use of attention in logs and interpretable behavior analysis in real time.
- IBM Security (2023) Cost of a Data Breach Report (2023). IBM Corporation. https://www.ibm.com/reports/data-breach
- Nasir, R., Afzal, M., Latif, R. and Iqbal, W. (2021) Behavioral Based Insider Threat Detection Using Deep Learning. IEEE Access , 9, 143266-143274. https://doi.org/10.1109/access.2021.3118297
- Dommari, S. (2022) AI and Behavioral Analytics in Enhancing Insider Threat Detection and Mitigation. International Journal of Research and Analytical Reviews , 9, 399.
- Rabbani, M., Wang, Y., Khoshkangini, R., Jelodar, H., Zhao, R., Bagheri Baba Ahmadi, S., et al. (2021) A Review on Machine Learning Approaches for Network Malicious Behavior Detection in Emerging Technologies. Entropy , 23, Article 529. https://doi.org/10.3390/e23050529
- Zhang, J. and Yan, L. (2025) Gru-Enhanced Attention Mechanism for LSTM in Hybrid CNN-LSTM Models for Stock Prediction. Journal of Global Trends in Social Science , 2, 10-17. https://doi.org/10.70731/rzvs8j53
- Singh, H. (2025) Leveraging Intelligent Agents for Advanced Cybersecurity Orchestration. International Journal of Information Technology and Management Information Systems , 16, 1081-1093. https://doi.org/10.34218/ijitmis_16_01_077
- Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A.N., Kaiser, Ł. and Polosukhin, I. (2017) Attention Is All You Need. Advances in Neural Inform ation Processing Systems , 30, 5998-6008.
- Cho, K., van Merrienboer, B., Gulcehre, C., Bahdanau, D., Bougares, F., Schwenk, H., et al. (2014) Learning Phrase Representations Using RNN Encoder-Decoder for Statistical Machine Translation. Proceedings of the 2014 Conference on Empirical Methods in Natural Language Processing ( EMNLP ), Doha, October 2014, 1724-1734. https://doi.org/10.3115/v1/d14-1179
- Sutskever, I., Vinyals, O. and Le, Q.V. (2014) Sequence to Sequence Learning with Neural Networks. Advances in Neural Information Processing Systems , 27, 3104-3112.
- Singh, S. and Joshi, G. (2024) Application of Machine Learning and Deep Learning Techniques for Cyber Security. ShodhKosh : Journal of Visual and Performing Arts , 5, 1129-1142. https://doi.org/10.29121/shodhkosh.v5.i1.2024.3997
- Ferrag, M.A., Maglaras, L., Moschoyiannis, S. and Janicke, H. (2020) Deep Learning for Cyber Security Intrusion Detection: Approaches, Datasets, and Comparative Study. Journal of Information Security and Applications , 50, Article ID: 102419. https://doi.org/10.1016/j.jisa.2019.102419