UGC Approved Journal no 63975(19)
New UGC Peer-Reviewed Rules

ISSN: 2349-5162 | ESTD Year : 2014
Volume 13 | Issue 9 | September 2026

JETIREXPLORE- Search Thousands of research papers



WhatsApp Contact
Click Here

Published in:

Volume 13 Issue 9
September-2026
eISSN: 2349-5162

UGC and ISSN approved 7.95 impact factor UGC Approved Journal no 63975

7.95 impact factor calculated by Google scholar

Unique Identifier

Published Paper ID:
JETIR2609305


Registration ID:
586334

Page Number

d37-d45

Share This Article


Jetir RMS

Title

Threat Intelligence Processing and Behavioral Anomaly Detection for Automated Security Monitoring

Abstract

Cyber threats continuously evolve, making timely identification of malicious activities an important requirement for modern security monitoring. Threat Intelligence (TI) provides information about known malicious entities such as IP addresses, domains, and other Indicators of Compromise (IOCs), while anomaly detection helps identify suspicious behavior that may not be present in threat intelligence databases. This research presents a lightweight Threat Intelligence Feed Processor and Anomaly Detector designed for local security monitoring. The proposed system collects malicious IP indicators from an external threat intelligence source, processes and stores them in a SQLite database, and compares incoming network and log events against the stored indicators. Events that match known malicious indicators are identified as threats, while events without an IOC match are further examined using behavioral anomaly detection. The system generates alerts with low, medium, or high-risk levels and stores relevant evidence for analysis. A Flask-based dashboard provides centralized visibility into IOCs, alerts, network activity, system activity, evidence, and security scores. In the experimental implementation, 1,000 AbuseIPDB indicators were processed, resulting in a total IOC database containing 2,736 IP records. The system analyzed 16 unique IP addresses, generated seven security alerts, and detected five behavioral anomalies in a controlled environment. The results demonstrate that combining threat intelligence with behavioral analysis can provide a practical approach for local security monitoring.

Key Words

Cyber Threat Intelligence, Threat Intelligence Feed, Indicators of Compromise, Anomaly Detection, Malicious IP Detection, Security Monitoring, Risk Scoring, Automated Threat Detection.

Cite This Article

"Threat Intelligence Processing and Behavioral Anomaly Detection for Automated Security Monitoring", International Journal of Emerging Technologies and Innovative Research (www.jetir.org), ISSN:2349-5162, Vol.13, Issue 9, page no.d37-d45, September-2026, Available :http://www.jetir.org/papers/JETIR2609305.pdf

ISSN


2349-5162 | Impact Factor 7.95 Calculate by Google Scholar

An International Scholarly Open Access Journal, Peer-Reviewed, Refereed Journal Impact Factor 7.95 Calculate by Google Scholar and Semantic Scholar | AI-Powered Research Tool, Multidisciplinary, Monthly, Multilanguage Journal Indexing in All Major Database & Metadata, Citation Generator

Cite This Article

"Threat Intelligence Processing and Behavioral Anomaly Detection for Automated Security Monitoring", International Journal of Emerging Technologies and Innovative Research (www.jetir.org | UGC and issn Approved), ISSN:2349-5162, Vol.13, Issue 9, page no. ppd37-d45, September-2026, Available at : http://www.jetir.org/papers/JETIR2609305.pdf

Publication Details

Published Paper ID: JETIR2609305
Registration ID: 586334
Published In: Volume 13 | Issue 9 | Year September-2026
DOI (Digital Object Identifier):
Page No: d37-d45
Country: Mumbai, Maharashtra, India .
Area: Science & Technology
ISSN Number: 2349-5162
Publisher: IJ Publication


Preview This Article


Downlaod

Click here for Article Preview

Download PDF

Downloads

0006

Print This Page

Current Call For Paper

Jetir RMS