Development of an Enhanced Ripple Down System for Detecting Cybercrimes in a University Environment
Abstract
University environments have become increasingly vulnerable to cybercrimes, including identity theft, hacking, financial fraud, and data breaches. Existing detection systems often exhibit high false positive rates, causing alert fatigue and missed detections, alongside prolonged recognition times that delay response to critical incidents. These limitations undermine the effectiveness of cybersecurity measures in academic institutions. This research aims to develop and evaluate an Enhanced Ripple Down Rule (ERDR) system for detecting cybercrimes in a university environment, addressing the limitations of standard rule-based approaches. A dataset comprising 3,800 cybercrime records, covering seven crime types (labelled Crime A through G) with four attributes each, was used. The dataset was partitioned into training (2,800 records) and testing (1,000 records) sets. The ERDR system, extending the standard Ripple Down Rule framework, employs a binary tree structure with enhanced rule processing capabilities. The system was implemented using MATLAB (R2023a) on a Windows 10 64-bit platform. Performance was evaluated using Sensitivity, Specificity, False Alarm Rate (FAR), Accuracy, and Computational Time (CT) across multiple threshold values. At the optimum threshold of 0.80, the ERDR system achieved: Sensitivity of 97.86%, Specificity of 98.92%, FAR of 1.08%, Accuracy of 99.86%, and CT of 140.9 seconds. In comparison, the standard RDR achieved: Sensitivity of 96.24%, Specificity of 95.74%, FAR of 4.26%, Accuracy of 97.85%, and CT of 131.11 seconds. The ERDR system demonstrated superior performance across all metrics, reducing false alarms by 74.6% while improving accuracy by 2.01%. The system provides a robust, accurate, and practical solution for cybercrime detection in university environments. Its superior performance, particularly in reducing false positives, makes it suitable for deployment across higher education institutions. This research contributes to the field of cybersecurity by extending the Ripple Down Rule methodology with enhancements that significantly improve detection accuracy and operational efficiency.