Aug 2026· Journal of Computer Science Application and Engineering (JOSAPEN)· 0 citations· 17 references
TL;DR
The potential of XGBoost as an accurate and explainable approach for cybersecurity threat detection in IT infrastructure is demonstrated and the model outperformed Logistic Regression, Decision Tree, Random Forest, and SVM.
Abstract
The increasing complexity of IT infrastructure has created significant challenges in detecting cybersecurity threats, particularly malicious network activities that can evade conventional security mechanisms. This study proposes an XGBoost-based machine learning model for detecting cybersecurity threats in network traffic. A controlled cybersecurity simulation environment was used to generate 50,000 network-flow observations representing benign activities, including web browsing, DNS requests, file transfer, and client-server communication, as well as malicious activities involving DoS, DDoS, port scanning, and brute-force attacks. After preprocessing, 48,000 observations were retained and divided into 80% training and 20% testing datasets using stratified sampling. XGBoost feature importance and randomized hyperparameter optimization with five-fold cross-validation were applied to improve model performance. The optimized XGBoost model achieved 98.30% accuracy, 98.10% precision, 97.90% recall, 98.00% F1-score, and 99.20% ROC-AUC, with a reported false-positive rate of 1.20%. XGBoost also outperformed Logistic Regression, Decision Tree, Random Forest, and SVM. SHAP analysis identified Flow Packets/s, Flow Bytes/s, Flow Duration, and packet-related characteristics as influential features. These findings demonstrate the potential of XGBoost as an accurate and explainable approach for cybersecurity threat detection in IT infrastructure.
While integrating the Industrial Internet of Things (IIoT) into smart factories massively boosts efficiency, it also opens the door to severe cyberattacks, such as malware and denial-of-service, that can actually disable physical machinery. To protect these vulnerable systems, researchers developed an edge computing-ba...
Firoz Ahmed Mansuri, Anita Seth· International Conference Com...· 0 citations
The rapid growth of network-connected systems has made cyber threat detection a critical priority for modern infrastructures. Traditional signature-based intrusion detection systems (IDSs) struggle to detect novel and evolving attacks, creating the need for intelligent learning-based approaches. This paper presents Sec...
Buddha Dev Sarker, Md Fahim Ahammed, Md Rasheduzzaman Labu et al.· International Conference Com...· 0 citations
In the field of cybersecurity, malicious website classification plays a crucial role in protecting industrial systems. For this reason, research has been undertaken to analyze cybersecurity threats, with the long-term objective of developing methods for the effective detection and classification of malicious websites....
J. Wilk-Jakubowski, Aleksandra Sikora, J. Zapała· Processes· 0 citations
They originate from the rapid rise of cyber threats such as malware, phishing, ransomware,
denial of service, and unauthorised network intrusion, which have proven to be so difficult to
tackle that traditional security measures can hardly deal with the issue. Signature-based
intrusion detection system techniques in par...
Praveen Kumar Reddy Gouni· International Journal of Soc...· 0 citations
Smart Cities increasingly rely on interconnected digital infrastructures and Internet of Things (IoT) systems, which expand the attack surface and create new cybersecurity challenges. Traditional intrusion detection systems (IDS) based on signatures and rules are limited in scalability and adaptability against zero-day...
Tonatiuh Guadalupe, Nava-Razon, Francisco Salcedo-Arancibia et al.· Journal of Intelligent Decis...· 0 citations
A multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time is introduced.
Ameen Pasha.A· International Scientific Jou...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.