FolioStart free

Computer Science · Literature

Research papers on Cybersecurity threat detection

Recent and highly-cited academic work on cybersecurity threat detection, gathered from Semantic Scholar, CrossRef and OpenAlex.

Search all 200M+ papers on this topic, free →
  1. Survey of intrusion detection systems: techniques, datasets and challenges

    Ansam Khraisat, Iqbal Gondal, Peter Vamplew, et al. · 2019 · Cybersecurity · 1,873 citations

    Cyber-attacks are becoming more sophisticated and thereby presenting increasing challenges in accurately detecting intrusions. Failure to prevent the intrusions could degrade the credibility of security services, e.g. data confidentiality, integrity, and availability. Numerous intrusion detection methods have been proposed in the literature to tackle computer security threats, which can be broadly classified into Signature-based Intrusion Detection Systems (SIDS) and Anomaly-based Intrusion Detection Systems (AIDS). This survey paper presents a taxonomy of contemporary IDS, a comprehensive review of notable recent works, and an overview of the datasets commonly used for evaluation purposes.

  2. Deep Learning Approach for Intelligent Intrusion Detection System

    R. Vinayakumar, Mamoun Alazab, K. P. Soman, et al. · 2019 · IEEE Access · 1,819 citations

    Machine learning techniques are being widely used to develop an intrusion detection system (IDS) for detecting and classifying cyberattacks at the network-level and the host-level in a timely and automatic manner. However, many challenges arise since malicious attacks are continually changing and are occurring in very large volumes requiring a scalable solution. There are different malware datasets available publicly for further research by cyber security community. However, no existing study has shown the detailed analysis of the performance of various machine learning algorithms on various publicly available datasets. Due to the dynamic nature of malware with continuously changing attackin

  3. Network intrusion detection system: A systematic study of machine learning and deep learning approaches

    Zeeshan Ahmad, Adnan Shahid Khan, Cheah Wai Shiang, et al. · 2020 · Transactions on Emerging Telecommunications Technologies · 1,220 citations

    Abstract The rapid advances in the internet and communication fields have resulted in a huge increase in the network size and the corresponding data. As a result, many novel attacks are being generated and have posed challenges for network security to accurately detect intrusions. Furthermore, the presence of the intruders with the aim to launch various attacks within the network cannot be ignored. An intrusion detection system (IDS) is one such tool that prevents the network from possible intrusions by inspecting the network traffic, to ensure its confidentiality, integrity, and availability. Despite enormous efforts by the researchers, IDS still faces challenges in improving detection accu

  4. Machine Learning and Deep Learning Methods for Intrusion Detection Systems: A Survey

    Hongyu Liu, Bo Lang · 2019 · Applied Sciences · 1,078 citations

    Networks play important roles in modern life, and cyber security has become a vital research area. An intrusion detection system (IDS) which is an important cyber security technique, monitors the state of software and hardware running in the network. Despite decades of development, existing IDSs still face challenges in improving the detection accuracy, reducing the false alarm rate and detecting unknown attacks. To solve the above problems, many researchers have focused on developing IDSs that capitalize on machine learning methods. Machine learning methods can automatically discover the essential differences between normal data and abnormal data with high accuracy. In addition, machine lea

  5. Cybersecurity data science: an overview from machine learning perspective

    Iqbal H. Sarker, A. S. M. Kayes, Shahriar Badsha, et al. · 2020 · Journal Of Big Data · 731 citations

    Abstract In a computing context, cybersecurity is undergoing massive shifts in technology and its operations in recent days, and data science is driving the change. Extracting security incident patterns or insights from cybersecurity data and building corresponding data-driven model , is the key to make a security system automated and intelligent. To understand and analyze the actual phenomena with data, various scientific methods, machine learning techniques, processes, and systems are used, which is commonly known as data science. In this paper, we focus and briefly discuss on cybersecurity data science , where the data is being gathered from relevant cybersecurity sources, and the analyti

  6. Benchmarking of Machine Learning for Anomaly Based Intrusion Detection Systems in the CICIDS2017 Dataset

    Ziadoon Kamil Maseer, Robiah Yusof, Nazrulazhar Bahaman, et al. · 2021 · IEEE Access · 443 citations

    An intrusion detection system (IDS) is an important protection instrument for detecting complex network attacks. Various machine learning (ML) or deep learning (DL) algorithms have been proposed for implementing anomaly-based IDS (AIDS). Our review of the AIDS literature identifies some issues in related work, including the randomness of the selected algorithms, parameters, and testing criteria, the application of old datasets, or shallow analyses and validation of the results. This paper comprehensively reviews previous studies on AIDS by using a set of criteria with different datasets and types of attacks to set benchmarking outcomes that can reveal the suitable AIDS algorithms, parameters

  7. A Survey on Security Threats and Defensive Techniques of Machine Learning: A Data Driven View

    Qiang Liu, Pan Li, Wentao Zhao, et al. · 2018 · IEEE Access · 426 citations

    Machine learning is one of the most prevailing techniques in computer science, and it has been widely applied in image processing, natural language processing, pattern recognition, cybersecurity, and other fields. Regardless of successful applications of machine learning algorithms in many scenarios, e.g., facial recognition, malware detection, automatic driving, and intrusion detection, these algorithms and corresponding training data are vulnerable to a variety of security threats, inducing a significant performance decrease. Hence, it is vital to call for further attention regarding security threats and corresponding defensive techniques of machine learning, which motivates a comprehensiv

  8. Chained Anomaly Detection Models for Federated Learning: An Intrusion Detection Case Study

    Davy Preuveneers, Vera Rimmer, Ilias Tsingenopoulos, et al. · 2018 · Applied Sciences · 318 citations

    The adoption of machine learning and deep learning is on the rise in the cybersecurity domain where these AI methods help strengthen traditional system monitoring and threat detection solutions. However, adversaries too are becoming more effective in concealing malicious behavior amongst large amounts of benign behavior data. To address the increasing time-to-detection of these stealthy attacks, interconnected and federated learning systems can improve the detection of malicious behavior by joining forces and pooling together monitoring data. The major challenge that we address in this work is that in a federated learning setup, an adversary has many more opportunities to poison one of the l

  9. Performance Comparison and Current Challenges of Using Machine Learning Techniques in Cybersecurity

    Kamran Shaukat, Suhuai Luo, Vijay Varadharajan, et al. · 2020 · Energies · 301 citations

    Cyberspace has become an indispensable factor for all areas of the modern world. The world is becoming more and more dependent on the internet for everyday living. The increasing dependency on the internet has also widened the risks of malicious threats. On account of growing cybersecurity risks, cybersecurity has become the most pivotal element in the cyber world to battle against all cyber threats, attacks, and frauds. The expanding cyberspace is highly exposed to the intensifying possibility of being attacked by interminable cyber threats. The objective of this survey is to bestow a brief review of different machine learning (ML) techniques to get to the bottom of all the developments mad

  10. Machine learning in cybersecurity: a comprehensive survey

    Dipankar Dasgupta, Zahid Akhtar, Sajib Sen · 2020 · The Journal of Defense Modeling and Simulation Applications Methodology Technology · 249 citations

    Today’s world is highly network interconnected owing to the pervasiveness of small personal devices (e.g., smartphones) as well as large computing devices or services (e.g., cloud computing or online banking), and thereby each passing minute millions of data bytes are being generated, processed, exchanged, shared, and utilized to yield outcomes in specific applications. Thus, securing the data, machines (devices), and user’s privacy in cyberspace has become an utmost concern for individuals, business organizations, and national governments. In recent years, machine learning (ML) has been widely employed in cybersecurity, for example, intrusion or malware detection and biometric-based user au

  11. Innovative Machine Learning Algorithms for Classification and Intrusion Detectionv By IJISRT

    Pankaj Malik, Parag Jhala, Vedanshi Sharma, et al. · 2024 · International Journal of Innovative Science and Research Technology (IJISRT) · 208 citations

    With the escalating sophistication of cyber threats, the need for robust intrusion detection systems has become paramount in safeguarding information systems. This research addresses the limitations of traditional methods by proposing and evaluating innovative machine learning algorithms for classification in intrusion detection. The study explores a diverse set of algorithms designed to enhance accuracy, efficiency, and adaptability in the dynamic landscape of cybersecurity. The introduction provides a context for the research, emphasizing the critical role of intrusion detection in contemporary cybersecurity. A comprehensive literature review underscores the shortcomings of existing method

  12. Machine learning in cybersecurity: A review

    Anand Handa, Ashu Sharma, Sandeep K. Shukla · 2019 · Wiley Interdisciplinary Reviews Data Mining and Knowledge Discovery · 194 citations

    Machine learning technology has become mainstream in a large number of domains, and cybersecurity applications of machine learning techniques are plenty. Examples include malware analysis, especially for zero‐day malware detection, threat analysis, anomaly based intrusion detection of prevalent attacks on critical infrastructures, and many others. Due to the ineffectiveness of signature‐based methods in detecting zero day attacks or even slight variants of known attacks, machine learning‐based detection is being used by researchers in many cybersecurity products. In this review, we discuss several areas of cybersecurity where machine learning is used as a tool. We also provide a few glimpses

  13. Threat Detection Driven by Artificial Intelligence: Enhancing Cybersecurity with Machine Learning Algorithms

    Heyao Chen, Zepeng Shen, Yong Wang, et al. · 2024 · World Journal of Innovation and Modern Technology · 16 citations

    This paper aims to explore the applications of artificial intelligence (AI) and machine learning (ML) in the field of cybersecurity, particularly in the development of end-to-end solutions for threat detection. By analyzing the current challenges in cybersecurity and the limitations of traditional threat detection methods, this paper seeks to demonstrate how AI/ML technologies can enhance the efficiency, accuracy, and automation levels of threat detection. The paper begins by introducing the core concepts of cybersecurity threat detection, including traditional methods such as signature-based detection, behavior-based detection, and rule-based detection systems. It then elaborates on the app

  14. On the fog’s frontline: a federated machine learning approach for industrial network threat detection and intrusion prevention

    Basharat Ali · 2025 · Journal of Cybersecurity · 14 citations

    Abstract The rapidly increasing field of industrial network security has led to the rapid growth of interconnecting devices, significantly enlarging attack surfaces and exposing flaws that older intrusion detection systems (IDS) cannot even handle due to scalability and privacy constraints. This work addresses the shortcomings by presenting an advanced federated framework for machine learning tailored toward intrusion detection in industrial networks. Using the detailed UNSW-NB15 dataset, known to represent realistic network traffic, we have analysed numerous machine learning methods in great detail to build a robust, adaptive, and privacy-preserving model for network prote

  15. Advancing cybersecurity with artificial intelligence and machine learning: Architectures, algorithms, and future directions in threat detection and mitigation

    Souratn Jain · 2025 · World Journal of Advanced Engineering Technology and Sciences · 11 citations

    The ever-growing number of and development of more elaborate threats require different levels of protection than formal regulation. AI & ML technology provide a promising outlook that even exists in the security domain and has become universal to design better, more dynamic security measures with better preparedness. In particular, the current paper discusses the correlation between AI, ML, and cybersecurity regarding architectures, algorithms, and potential for further development. The chosen AI-based architectures are captured here, like deep learning models, federated learning frameworks, and graph-based techniques to detect malware, phishing, ransomware, and insider threats. The paper th

  16. MACHINE LEARNING FOR CYBERSECURITY: THREAT DETECTION AND PREVENTION

    Husna Sultana · 2024 · ShodhKosh: Journal of Visual and Performing Arts · 6 citations

    The increasing sophistication and frequency of cyber threats pose significant challenges for organizations worldwide, necessitating advanced solutions for threat detection and prevention. Traditional cybersecurity measures, such as signature-based detection and rule-based systems, often fall short in identifying novel and complex attacks. This paper explores the application of machine learning (ML) as a transformative approach to enhance cybersecurity, focusing on its effectiveness in threat detection and prevention. Machine learning algorithms enable systems to learn from historical data, recognize patterns, and adapt to new threats in real-time. By leveraging techniques such as supervised,

  17. Cybersecurity Threat Detection using Machine Learning and Network Analysis

    Amaresh Kumar · 2024 · Journal of Artificial Intelligence General science (JAIGS) ISSN:3006-4023 · 5 citations

    Cybercriminals continually develop innovative strategies to confound and frustrate their victims, necessitating constant vigilance to protect the availability, confidentiality, and integrity of digital systems. Machine learning (ML) has emerged as a powerful technique for intelligent cyber analysis, enabling proactive defenses by studying recurring patterns of successful attacks. However, two significant drawbacks hinder the widespread adoption of ML in security analysis: high computing overheads and the need for specialized frameworks. This study aims to quantify the extent to which a hub can enhance ecosystem safety. Typical cyberattacks were executed on an Internet of Things (IoT) network

  18. Machine Learning Models for Cybersecurity in the USA firms and develop models to enhance threat detection

    Md Shawon Islam · 2024 · Journal of Business Venturing, AI and Data Analytics · 3 citations

    In the context of global digitalization trends, the problem of the impact of cyberattacks on the company is significantly relevant. The rapid evolution and growth of the internet through the last decades led to more concern about cyber-attacks that are continuously increasing and changing. As a result, an effective intrusion detection system was required to protect data, and the discovery of machine learning is one of the most successful ways to address this problem. This article is devoted to the impact of cyberattacks on the US firms’ market value since it is an indicator of firm performance and how it can be solved by using machine learning technology. The paper’s central hypothesis is th

  19. Enhancing Cybersecurity Through AI: A Machine Learning-Based Framework for Real-Time Threat Detection and Mitigation

    Abdullah Faiz, Amjad Jumani, Abdul Hafiz, et al. · 2025 · Annual Methodological Archive Research Review · 2 citations

    With the continually increasing evolution of cyber threats in both their complexity and occurrence, the signature based intrusion detection systems have been found inadequate in providing proactive and responsive network protection. The paper proposes a machine learning framework, which maximizes cybersecurity by performing real-time threat detection and mitigation in a layer-based approach by utilizing both unsupervised and supervised models. This framework uses the K-Means clustering method to find anomalies and then uses the Random Forest and Deep Neural Network (DNN) classifier to precisely detect and label the threat. When tested on the CICIDS2017 dataset, the system showed high detecti

  20. Machine Learning in Cybersecurity: A Comprehensive Review of Threat Detection, Prevention, and Response Strategies

    Tanvi Desai, Rakesh Kumar Pal · 2025 · 2025 4th International Conference on Computational Modelling, Simulation and Optimization (ICCMSO) · 2 citations

    The increased complexity and rate of cyberattacks have necessitated a change in the paradigm of cybersecurity strategies. The conventional rule-based systems are increasingly insufficient to address the dynamic and adaptive behaviour of modern threats. Machine learning (ML), with its ability to learn from vast amounts of data and identify complex patterns, has emerged as a powerful ally in combating these threats. This paper offers a comprehensive review of the application of ML in cybersecurity, its applications across the entire threat lifecycle. We present a wide range of ML approaches, including supervised, unsupervised, and deep learning approaches, and their effectiveness in areas of h

  21. Cybersecurity With Machine Learning: Implementing AI Algorithms for Intrusion Prevention, Advanced Data Protection, and Real-Time Threat Analysis

    Krishna Bonagiri, P. Krishnamoorthy, V. Keerthiga, et al. · 2025 · 2025 International Conference on Computational, Communication and Information Technology (ICCCIT) · 2 citations

    In an era where cyber attacks are getting increasingly complex, the incorporation of machine learning (ML) algorithms into cybersecurity processes has emerged as a crucial technique for boosting protection against potential intrusions and data breaches. For the purpose of preventing intrusions, providing superior data protection, and conducting real-time threat analysis, this research investigates the application of machine learning approaches that are driven by artificial intelligence. Organizations are able to increase their preventative defenses against cyber attacks by utilizing algorithms that are capable of analyzing massive volumes of data and identifying patterns that are indicative

  22. Web Attack Intrusion Detection System Using Machine Learning Approaches for Cybersecurity

    Ali E. Takieldeen, Aya El-Sayed El-Metwaly, Rahma Rezk Elzahdany, et al. · 2025 · 2025 International Telecommunications Conference (ITC-Egypt) · 1 citations

    This paper presents a real-time intrusion detection system (IDS) for web attacks that leverages machine learning techniques applied to web server logs. The increasing sophistication of web attacks necessitates advanced detection methods that can adapt to evolving threat landscapes. Our system addresses this challenge by employing a multi-stage approach: (1) comprehensive feature engineering, including novel features extracted from web logs, (2) feature selection to identify the most relevant attributes, (3) classification using various machine learning algorithms (Support Vector Machine, Gradient Boosted Trees, Decision Tree, and Random Forest), and (4) a real-time detection engine that proc

  23. Advancing Cybersecurity Practice: Explainable Machine Learning for Network Intrusion Detection

    Adam Grabowski, Shengjie Xu · 2025 · Journal of Cybersecurity Education, Research and Practice · 1 citations

    This research investigates explainable artificial intelligence (XAI) integration within machine learning (ML)-based intrusion detection systems (IDS), focusing on distinguishing malicious from benign network activities. We employed Random Forest and XGBoost models evaluated on widely recognized datasets, including NSL-KDD and UNSW-NB15, using both binary and multi-class classification tasks. The objective was to enhance cybersecurity operations through improved model transparency and interpretability. By integrating SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-Agnostic Explanations), the study offers comprehensive global and local insights into model decision-maki

Write your paper with these sources

Folio is the integrity-first research workspace: search 200M+ papers, save sources, and write with citations that format themselves. Free for students and researchers.

Start writing free →