Open Access

Cybersecurity Threat Intelligence Using Machine Learning Classification Techniques

4 Assistant Professor, Department of Computer Science and Applications, Mandsaur (M.P.), India

Abstract

New attacks are getting smarter and more sophisticated, so the old signature-based intrusion detection and prevention systems can't find them. This work proposes a machine learning approach to build a cybersecurity threat intelligence framework for effective multiclass intrusion detection, in which the Decision Tree classifier is used. The CICIDS2017 benchmark dataset, which contains both benign network traffic and several types of cyberattacks, is used to build and test the suggested model. The goal of the preparation process is to enhance classification performance by cleaning and separating data, utilizing Standard Scaler to scale features, and SMOTE to balance classes. Metrics like as recall, accuracy, precision, F1-score, confusion matrix, and ROC curve are used to test the Decision Tree model. An impressive 99.91% accuracy (ACC) rate, 97.79% precision (PRE), 97.08% recall (REC), 97.41% F1-score (F1), and 0.99 AUC were revealed by the experiment's outcomes. The suggested method beats state-of-the-art deep learning and ML approaches in terms of performance, execution time, and computational complexity. The results show that the suggested design is a reliable, efficient, and lightweight way to find cyber security threats and IDR apps with intelligence.

Keywords

References

N. Mohamed, “Current trends in AI and ML for cybersecurity: A state-of-the-art survey,” Cogent Eng., vol. 10, no. 2, pp. 1–30, Dec. 2023, doi: 10.1080/23311916.2023.2272358.
P. Kumar, “A Zero Trust-Based Approach to Modern Cybersecurity Challenges in Software Development,” Int. J. Emerg. Res. Eng. Technol., vol. 6, no. 9, pp. 113–122, September, 2025.
S. C. -, “Risk Management in Advanced Persistent Threats (APTs) for Critical Infrastructure in the Utility Industry,” Int. J. Multidiscip. Res., vol. 3, no. 4, pp. 1–10, July-August, Aug. 2021, doi: 10.36948/ijfmr.2021.v03i04.34396.
V. Koppireddy, D. G. Parasad, D. Patel, S. R. Somula, V. Kamaraj, and A. Meher, “AI Security Governance for Trustworthy Intelligent Systems: A Critical Analysis of Cyber Risks, Privacy Threats, and Responsible Deployment Frameworks,” Int. J. Res. Trends Innov., vol. 11, no. 07, pp. a407–a435, July, 2026, doi: 10.56975/ijrti.v11i7.214029.
M. M. Kowsar, “Adaptive Cybersecurity Threat Intelligence Using Explainable Artificial Intelligence for Resilient Protection of U.S. Critical Information Systems,” Am. ofAdvanced Technol. Eng. Solut., vol. 1, no. 2, pp. 216–261, 2025, doi: 10.2139/ssrn.5329985.
V. K. R. K. Koppireddy, “The Future of Cybersecurity: AI-Powered Innovations Redefining Digital Defense.”
S. P. Sivashanmugam, S. Kumara, A. Mohile, and D. R. Suram, “Improving Detection Accuracy of Phishing Attacks with Feature Selection and Machine learning Techniques in Cybersecurity,” in 2026 1st International Conference on Emerging Trends in Advancements and Applications of Computational Intelligence Techniques (ETAACT), Bhubaneswar, India: IEEE, 2026, pp. 1–6, April. doi: 10.1109/ETAACT69135.2026.11542138.
M. Beyene and K. R. Shekar, “Performance Analysis of Homomorphic Cryptosystem on Data Security in Cloud Computing,” in 2019 10th International Conference on Computing, Communication and Networking Technologies (ICCCNT), Kanpur, India: IEEE, 2019, pp. 1–7, July. doi: 10.1109/ICCCNT45670.2019.8944837.
M. T. Karatu, I. M. Mungadi, and A. Shehu, “Machine Learning Techniques for Cybersecurity Threat Detection : A Systematic Review,” Int. J. Innov. Sci. Res. Technol., vol. 11, no. 3, pp. 2992–2998, 2026.
A. T. Quanita and M. A. Y. Srizon, “Enhancing Cyber Threat Intelligence Using Transformer Models for Text Classification,” in 2026 IEEE 2nd International Conference on Quantum Photonics, Artificial Intelligence & Networking (QPAIN), 2026, pp. 1–5. doi: 10.1109/QPAIN69676.2026.11546420.
M. Kumar, M. Shojonov, B. Madaminov, A. K. Sahoo, T. Tiwari, and M. K. Sharma, “AI-Powered Cyber security: Neural Networks for Threat Detection and Prevention,” in 2025 World Skills Conference on Universal Data Analytics and Sciences (WorldSUAS), 2025, pp. 1–5. doi: 10.1109/WorldSUAS66815.2025.11199107.
A. T. Haile, S. L. Abebe, and H. M. Melaku, “Real-Time Automated Cyber Threat Classification and Emerging Threat Detection Framework,” IEEE Open J. Comput. Soc., vol. 6, pp. 921–930, 2025, doi: 10.1109/OJCS.2025.3580235.
A. Gueriani, H. Kheddar, and A. C. Mazari, “Enhancing IoT Security with CNN and LSTM-Based Intrusion Detection Systems,” in 2024 6th International Conference on Pattern Analysis and Intelligent Systems (PAIS), 2024, pp. 1–7. doi: 10.1109/PAIS62114.2024.10541178.
M. O. Adebiyi, M. O. Ajayi, F. B. Osang, and A. A. Adebiyi, “A comparative study of selected machine learning algorithms for cyber threat detection in open source data,” in 2023 International Conference on Science, Engineering and Business for Sustainable Development Goals (SEB-SDG), 2023, pp. 1–8. doi: 10.1109/SEB-SDG57117.2023.10124615.
A. O. Al-Ansari and T. M. Alsubait, “Predicting Cyber Threats Using Machine Learning for Improving Cyber Supply Chain Security,” in 2022 Fifth National Conference of Saudi Computers Colleges (NCCC), 2022, pp. 123–130. doi: 10.1109/NCCC57165.2022.10067692.
D. Paul, S. A. D. B. N. Poovaiah, A. Kishore, V. S. K. Tankani, Meylikulov, and Shakhboz, “SHO-Xception: An Optimized Deep Learning Framework for Intelligent Intrusion Detection in Network Environments,” in 2025 International Conference on Innovations in Intelligent Systems: Advancements in Computing, Communication, and Cybersecurity (ISAC3), Bhubaneswar, India: IEEE, 2025, pp. 1–6, July. doi: 10.1109/ISAC364032.2025.11156610.
C. H. N, “Network Intrusion dataset(CIC-IDS- 2017),” Kaggle.
A. A. Abdualrahman and M. K. Ibrahem, “Intrusion Detection System Using Data Stream Classification,” Iraqi J. Sci., vol. 62, no. 1, pp. 319–328, Jan. 2021, doi: 10.24996/ijs.2021.62.1.30.
H. R. Sayegh, W. Dong, and A. M. Al-madani, “Enhanced Intrusion Detection with LSTM-Based Model, Feature Selection, and SMOTE for Imbalanced Data,” Appl. Sci., vol. 14, no. 2, p. 479, Jan. 2024, doi: 10.3390/app14020479.
A. Al Farsi, A. Khan, M. M. Bait-Suwailam, and M. R. Mughal, “Comparative Performance Evaluation of Machine Learning Algorithms for Cyber Intrusion Detection,” Dec. 2024. doi: 10.20944/preprints202412.0497.v1.
Z. K. Maseer, R. Yusof, N. Bahaman, S. A. Mostafa, and C. F. M. Foozy, “Benchmarking of Machine Learning for Anomaly Based Intrusion Detection Systems in the CICIDS2017 Dataset,” IEEE Access, vol. 9, pp. 22351–22370, 2021, doi: 10.1109/ACCESS.2021.3056614.
R. A. Disha and S. Waheed, “Performance analysis of machine learning models for intrusion detection system using Gini Impurity-based Weighted Random Forest (GIWRF) feature selection technique,” Cybersecurity, vol. 5, no. 1, p. 1, 2022, doi: 10.1186/s42400-021-00103-8.
M. Rodríguez, Á. Alesanco, L. Mehavilla, and J. García, “Evaluation of Machine Learning Techniques for Traffic Flow-Based Intrusion Detection,” Sensors, vol. 22, no. 23, p. 9326, Nov. 2022, doi: 10.3390/s22239326.
Z. Xu and Y. Liu, “Robust Anomaly Detection in Network Traffic: Evaluating Machine Learning Models on CICIDS2017,” arXiv, 2025.
S. Abiramasundari and V. Ramaswamy, “Distributed denial-of-service (DDOS) attack detection using supervised machine learning algorithms,” Sci. Rep., vol. 15, no. 1, p. 13098, Apr. 2025, doi: 10.1038/s41598-024-84879-y.
S. M. Kasongo and Y. Sun, “Performance Analysis of Intrusion Detection Systems Using a Feature Selection Method on the UNSW-NB15 Dataset,” J. Big Data, vol. 7, no. 1, 2020, doi: 10.1186/s40537-020-00379-6.
M. Arcos-Argudo, R. Bojorque, and A. Torres, “A Deterministic Comparison of Classical Machine Learning and Hybrid Deep Representation Models for Intrusion Detection on NSL-KDD and CICIDS2017,” Algorithms, vol. 18, no. 12, p. 749, Nov. 2025, doi: 10.3390/a18120749.
N. Dash, S. Chakravarty, A. K. Rath, N. C. Giri, K. M. AboRas, and N. Gowtham, “An optimized LSTM-based deep learning model for anomaly network intrusion detection,” Sci. Rep., vol. 15, no. 1, pp. 1–21, 2025, doi: 10.1038/s41598-025-85248-z.

Similar Articles

1-10 of 40

You may also start an advanced similarity search for this article.