MARATTO

review

Effectiveness of Machine Learning Algorithms in Threat Detection and Mitigation in Cyberspace: A Systematic Review

Abstract

The rapid digitalization and proliferation of internet-connected devices have not only revolutionized our daily lives but also exponentially expanded the attack surface for cybercriminals, creating an increasingly complex and treacherous cybersecurity landscape. This review critically examines the effectiveness of machine learning (ML) algorithms in cyber threat detection and mitigation, addressing the need for advanced cybersecurity measures in our interconnected digital landscape. Following Kitchenham's guidelines and utilizing the PRISMA model, the study analyzed 907 initial records from Science Direct, Google Scholar, IEEE Xplore, Springer, and ACM Digital Library, ultimately including only 15 studies that met stringent criteria. The thematic analysis revealed varying effectiveness of supervised learning (SVM and Random Forests) with accuracy rates of 85-90%, but with moderate false positive rates (15-20%). Unsupervised learning techniques (like K-means and DBSCAN) demonstrated lower accuracy (70-75%) yet excelled in detecting novel threats, albeit with higher false positive rates (25-30%). Reinforcement learning showcased adaptive defense capabilities but suffered from lower accuracy (65-70%) due to adversarial manipulation. Deep learning methods achieved high accuracy (up to 99%) in specific tasks, yet faced challenges related to resource demands and limited interpretability. The study highlights data quality difficulties, high false positive and negative rates, and complex model interpretability issues. ML can automate incident response and security orchestration, but the evaluation stresses the need for a balanced approach with human experience. Increasing model interpretability and defending against adversarial attacks are research gaps. The paper emphasises the need of hybrid approaches and explainable AI techniques for cyber threat identification and mitigation using ML. This thorough study lays the groundwork for ML-based cybersecurity in a complex threat landscape, despite limitations owing to the continuous evolution of cyber threats and ML technology.

Research topics

  • Network Security and Intrusion Detection

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/nigercon62786.2024.10927069

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.