Sunday, September 13, 2026
Detecting Zero-Day Cyberattacks with Deep Reinforcement Learning: An Open-Set Intrusion Detection Approach | Research Work
Hi everyone, I am posting something on this blog after a decade. Good to see that my 11-year-old posts are still getting some views and is still somehow relevant even in the age of AI....
Open-Set Intrusion Detection and Semantic Analysis of Zero-Day Network Attacks Using Deep Reinforcement Learning and Large Language Models
by Shreyash Tiwari
The increasing prevalence of zero-day cyberattacks presents a significant challenge for modern Intrusion Detection Systems (IDS), as previously unseen network traffic often falls outside the distribution of supervised training data. Traditional deep learning-based IDS solutions operate under a closed-set assumption, requiring all attack categories to be known during training.
Consequently, novel attacks may be misclassified as benign traffic or incorrectly assigned to known attack classes, reducing the effectiveness of network defense mechanisms. Although recent open-set recognition approaches improve the detection of unknown traffic, they typically provide limited insight into the behavioral characteristics of detected anomalies, requiring additional manual investigation by security analysts.
This thesis presents a unified framework for open-set intrusion detection and semantic analysis of unknown network traffic by combining deep learning, reinforcement learning, and large language models. The proposed framework employs a Convolutional Neural Network (CNN) to learn feature representations from known network traffic classes and a Deep Q-Network (DQN) that uses SoftMax-derived uncertainty metrics, including maximum probability, probability gap, and Shannon entropy, to dynamically distinguish known from unknown traffic without manually defined confidence thresholds. To improve interpretability, a selective Large Language Model (LLM) reasoning module is applied only to traffic identified as unknown by the CNN-DQN pipeline. Unlike existing approaches that focus solely on detection or apply computationally expensive LLM reasoning across all traffic, the proposed framework combines efficient open-set detection with targeted semantic interpretation of suspicious network behavior.
Experimental evaluation was conducted using the CICIDS-2017 and UNSW-NB15 intrusion detection datasets. The CNN-DQN framework achieved a binary F1-score of 97.83% for known-versus-unknown traffic separation while maintaining strong performance on known attack classes and effectively identifying previously unseen attacks. Cross-dataset experiments demonstrated the framework’s ability to generalize to traffic distributions not observed during training. The LLM-assisted reasoning stage generated behaviorally aligned explanations for 77.5% of DQN-flagged unknown traffic samples and provided meaningful behavioral insights for an additional 22.1% of samples, demonstrating its effectiveness in supporting contextual interpretation of suspicious network activity.
The proposed framework contributes to the development of adaptive, explainable, and deployable intrusion detection systems capable of addressing evolving cyber threats. By combining uncertainty-aware open-set detection with semantic reasoning, the system enables security analysts, network administrators, and cybersecurity researchers to not only identify previously unseen attacks but also understand their underlying behavioral characteristics. This capability can support faster incident response, improved threat intelligence generation, and enhanced protection of enterprise, cloud, Internet of Things (IoT), and critical infrastructure environments against emerging cyber threats.
DOI: https://doi.org/10.62791/20638
Research Gate: https://www.researchgate.net/profile/Shreyash-Tiwari-6
Sunday, September 13, 2026 by Shreyash Tiwari · 0
Friday, May 4, 2012
you can shut-down websites for specific timing usin g
this toolkit very effective for hackerzzz it is a toolkit
by anonymous !
here are things required:
- 1) insert url of website with (http://)
- 2)set power of attack
- 3)hit "IMMA CHARGIN MAH LAZER"
here is a screenshot:
LOIC 1.0.0.0 Toolkit Download: Here
LOIC 1.1.1.17 Save As (LOGIC.EXE) FULL Toolkit Download: Here
i hope you like this tutorial and this toolkit.
provide your FeeDBack....!! :D
Friday, May 4, 2012 by Shreyash Tiwari · 0
Sunday, April 29, 2012
A denial-of-service attack (DoS attack) or distributed denial-of-service attack (DdoS attack) is an attempt to make a computer or network resource unavailable to its intended users. Although the means to carry out, motives for, and targets of a DoS attack may vary, it generally consists of the efforts of one or more people to temporarily or indefinitely interrupt or suspend services of a host connected to the Internet.
work of this Ddos?
In a typical DdoS attack, a hacker begins by exploiting a vulnerability in one computer system and making it the DdoS master. It is from the master system that the intruder identifies and communicates with other systems that can be compromised. The intruder loads cracking tools available on the Internet on multiple sometimes thousands of compromised systems. With a single command, the intruder instructs the controlled machines to launch one of many flood attacks against a specified target. The inundation of packets to the target causes a denial of service.
this Ddos tool coded on visual basic 6 firstly you must send this ocx's to system32
msinet.ocx
mscomctl.ocx
mswinsck.ocx
this Tool will be detected supicious by Antiviruses because ddos tool works on port 80 & it is also a backdoor port soo it is a false positive detection dont worry this tool is clean.


problemzzz..!!
Sunday, April 29, 2012 by Shreyash Tiwari · 0
ping 100.00.0.0 -t -l 65500
[Here ip adress is just an example]
5.after one hour visit the website you will see the website is crashed
hope u like this post :D:D
by Shreyash Tiwari · 0
Friday, April 13, 2012
Features:
Scan - This will scan the selected target for open ports and vulnerabilities, also allowing the user to select a specific scanning script for a more advanced/targeted scan.
Spy - This will 'sniff' images transferred to/from the selected device and display them on your phone in a nice gallery layout. If you choose a network subnet/range as target, then all images transferred on that network - for all connected devices - will be shown. Another feature of the Spy plugin is to sniff URLs (web sites) and non-secured (ie, not HTTPS) username/passwords logins, shown on the bottom drawer.
D.O.S - This will cause a Denial Of Service (D.O.S) for the selected target, ie. it will deny them any further access to the internet until you exit the attack.
Replace images - This will replace all images transferred to/from the target with an Anti logo, thus preventing from attacked used seeing any images on their browsers while the browse the Internet, except for a nice looking Anti logo...
M.I.T.M - The Man In The Middle attack (M.I.T.M) is an advanced attack used mainly in combination with other attack. It allows invoking specific filters to manipulate the network data. Users can also add their own mitm filters to create more mitm attacks.
Attack - This will initiate a vulnerability attack using our Cloud service against a specific target. Once executed successfully, it will allow the attack to control the device remotely from your phone.
Report - This will generate a vulnerability report with findings, recommendations and tips on how to fix found vulnerabilities or bad practices used.
Friday, April 13, 2012 by Shreyash Tiwari · 0
Wednesday, April 4, 2012
hey guys today i will provide you a backtrack Ddos tut to shut-down big websites yes you can shut down big websites with this tut you just need 5-6 computers so u can say this tut is so powerful i hav provided a picture tut hope u all like it
Ddos website manually..!
ADVICE: {use anonymous proxie} protect yourself from getting caught :P
MATERIAL REQUIRED:
>> slowloris.pl script
>> Backtrack 5r1 or r2
PICTURE TUTORIAL:
create a new folder name "slowloris.pl"
now paste slowloris.pl (perl) script in the folder
now move the folder to desktop
open the target folder
Wednesday, April 4, 2012 by Shreyash Tiwari · 1
FUNCTIONS :
ddos script
php dos
php ddos script
php dos script
ddos php script
ddos script php
phpDos
ddos scripts
script DDOS
php ddos
ddos php
denial of service script
dos php
ddos attack script
php ddoser
script php ddos
dos php script
php script ddos
ddos script download
php DDos attack script
script ddos php
PHP DoS Script by Exe
ddos
php dos by exe
ddos skript
mysql ddos
DENIAL OF SERVICE php script
php ddos attack
php ddos download
download script ddos
ddos online
denial of service scripts
PHP DoS/DDoS (Denial Of Service) Script
ddos php tool
php curl ddos
ddos php scripts
script ddos attack
dos script denial
php Dos scripts
php denial of service

Mirror 1:
Script download here: download script {11.1 MB}
Mirror 2:
full script download: download scripT {26.3 MB}
by Shreyash Tiwari · 1
Saturday, March 31, 2012
Saturday, March 31, 2012 by Shreyash Tiwari · 0
Wednesday, March 28, 2012
DoS Attack?
Short form of denial-of-service attack, a type of attack on a network that is designed to bring the network to its knees by flooding it with useless traffic. Many DoS attacks, such as the Ping of Death and Teardrop attacks, exploit limitations in the TCP/IP protocols. For all known DoS attacks, there are software fixes that system administrators can install to limit the damage caused by the attacks. But, like viruses, new DoS attacks are constantly being dreamed up by hackers.first check that your website vul apache server website or not for that go there - http://uptime.netcraft.com/
now search the url of your website check the result like shown in the screenshot:
so our website is vulnerable!! :D:D!!
now download this Dos toolkit:
Qslowloris download {4.27 MB}
virus scan of Qslowloris {safe}
now after downloading extend the Qslowloris in your desktop and do the same like i am doing
see screenshot:
click on Fire ! the website will be Shut down for specific time according to your Timeout limit :D:D!!
Wednesday, March 28, 2012 by Shreyash Tiwari · 0
Tuesday, March 27, 2012
this is a powerful Ddos toolkit by anonymous.
- enter values by clicking on THREADS
- then choose target in the right corner of tool. click on "+"option enter website url ok.
- then click on "FIRE TEH LAZER"
if the attack works the website will shut down
Tuesday, March 27, 2012 by Shreyash Tiwari · 0
Blog Warning:
THIS WEBSITE IS BUILD BY ME ONLY FOR EDUCATIONAL PURPOSE I JUST WANT TO PROVIDE CYBER TIPS SO IF U USE THESE INFORMATION TO HARM ANY SUBSTANCE,COMMUNITY OR PERSON AND GOT CAUGHT THEN I AM NOT RESPONSIBLE FOR IT SO MIND MY WORDS HACKING IS A CYBER CRIME DON'T CHEAT OTHERS WITH YOUR POWERS
KNOWLEDGE IS FOR SHARING ASK-SHARE
STSHREYASH50@GMAIL.COM












