This study suggests a hybrid model of prediction and anomaly detection of dynamic network based on graph density time series. The main issue that is being tackled is that traditional linear models cannot explain non-linear structural shocks and volatility clustering that are facts in cyber network data. The methodology proposed implies turning network flows of the UNSW-NB15 dataset into dynamic graph snapshots, deriving graph density as a scalar measure, and stabilizing the series by converting it to log-returns. The existence of the “fat tails” and non-Gaussian shocks which cannot be detected using traditional statistical tools was verified by the use of advanced diagnostic tests, like Kurtosis and Jarque-Bera test. As a result, a hybrid model that was a combination of the autoregressive moving average (ARMA) and exponential generalized autoregressive conditional heteroscedasticity (EGARCH) was applied. This research used the selection of the ARMA ($p$, $q$)-EGARCH ($u$, $v$) model as the best specification in terms of the Akaike Information Criterion (AIC) and Bayesian Information Criterion (BIC). The result of the hybrid model had an accuracy with running time spent in predictive and anomaly detection. Compared with two different methods, the methodology of ARMA ($p$, $q$)-EGARCH ($u$, $v$) has demonstrated the highest level of anomaly detection with a decrease in time processing in prediction and detection processes. This paper shows that structural graph analysis with modeling can be used to increase the resilience and sensitivity of intrusion detection systems.