Aug 2026· The Eastasouth Journal of Information System and Computer Science· 0 citations· 64 references
TL;DR
By minimizing false alarms, the proposed framework improves the efficiency of security operations, reduces alert fatigue among cybersecurity analysts, and enables security teams to prioritize genuine threats more effectively.
Abstract
The rapid digital transformation of critical infrastructure has significantly increased its exposure to complex and continuously evolving cyber threats, creating an urgent need for intelligent and adaptive cybersecurity solutions. Conventional security mechanisms, such as signature-based and rule-based intrusion detection systems, often struggle to identify novel attack patterns and provide timely responses to emerging threats. To address these limitations, this study proposes an artificial intelligence (AI)-driven framework for cyber threat detection and automated response that strengthens the security, resilience, and operational reliability of critical infrastructure environments. The experimental evaluation demonstrates that AI-based techniques substantially outperform traditional cybersecurity methods in terms of detection performance. Conventional rule-based systems achieve an average detection accuracy of approximately 68%, whereas machine learning and deep learning models improve the accuracy to nearly 80% and 88%, respectively. The proposed AI-driven framework delivers the highest performance, achieving an overall detection accuracy of approximately 94%. This superior performance highlights its capability to accurately identify both previously known attacks and sophisticated zero-day threats. Beyond detection accuracy, the study evaluates response time, which plays a crucial role in limiting the impact of cyber incidents. The findings reveal that the proposed AI-enabled response mechanism reduces the average response time to approximately 35 seconds, compared with around 150 seconds for manual response processes and 90 seconds for conventional rule-based automation. Such improvements enable faster threat containment, minimize operational disruption, and enhance the resilience of critical infrastructure systems. The framework also demonstrates notable improvements in reducing false positive alerts. The AI-driven approach achieves a false positive rate of approximately 5%, significantly lower than the 20% observed in signature-based systems and the 12% reported for anomaly-based detection methods. By minimizing false alarms, the proposed framework improves the efficiency of security operations, reduces alert fatigue among cybersecurity analysts, and enables security teams to prioritize genuine threats more effectively.
The increasing sophistication, frequency, and scale of cyberattacks have created significant challenges for conventional cybersecurity systems. Traditional security solutions such as firewalls, signature-based intrusion detection systems, and antivirus software are largely reactive and depend on predefined rules and known attack patterns. Consequently, these systems often struggle to detect and respond effectively to emerging threats such as Advanced Persistent Threats (APTs), zero-day attacks, ransomware, botnets, and insider attacks. Recent advancements in Artificial Intelligence (AI), particularly Reinforcement Learning (RL), have demonstrated the potential to create autonomous systems capable of learning and adapting to dynamic environments. Simultaneously, Cyber Threat Intelligence (CTI) provides valuable contextual information regarding threat actors, attack techniques, vulnerabilities, and indicators of compromise. This study proposes an Autonomous Cyber Defense Framework that integrates Reinforcement Learning and Threat Intelligence to enhance threat detection, decision-making, and automated response capabilities. The framework employs a Deep Q-Network (DQN) agent that continuously learns optimal defense actions through interaction with network environments while utilizing threat intelligence feeds to improve situational awareness. Experimental evaluation was conducted using benchmark cybersecurity datasets, including CICIDS2017 for Intrusion Detection, UNSW-NB15 for attack classification, CTU-13 for botnet detection and Custom Threat Feeds for threat intelligence. The results indicate that the proposed framework achieved a precision rate of 98.4%, a recall rate of 98.2%, an F1-score of 98.3%, and a threat mitigation rate of 96.8%. False positive rate of 1.9, False negative rate of 1.5 and Response rate of 41%, significantly outperforming traditional machine learning and signature-based security approaches. The findings demonstrate that integrating reinforcement learning with threat intelligence can provide a highly adaptive and proactive cyber defense mechanism suitable for modern network environments.
Abimbola B. Owolabi, F. Osang· Direct Research Journal of E...· 0 citations
Cybersecurity is an increasingly critical concern due to the growing complexity and frequency of cyberattacks, particularly against critical infrastructures. Conventional security techniques such as intrusion detection and anomaly detection are often insufficient in addressing sophisticated threats like advanced persistent threats. This paper introduces a novel hybrid approach that combines LogBERT Transform for feature extraction, support vector machine for classification, and the Archimedes optimization algorithm for parameter tuning. This unique integration overcomes the limitations of traditional methods, improving detection accuracy while reducing false alarms. The proposed methodology is shown to outperform conventional systems, achieving 98.36% classification accuracy, 97.77% precision, 96.45% recall, and 97.10% F1-score. The model's low false positive and false negative rates demonstrate its practical feasibility in cybersecurity applications. This approach also enhances model interpretability and scalability, making it well-suited for deployment in large-scale networks and IoT systems, with further improvements in scalability and interpretability being key future directions.
Mingyan Liu, Xu Chao· International Journal of Inf...· 0 citations
The findings indicate that AI-powered cyber defense significantly enhances threat detection, reduces response time, and improves overall cyber resilience compared to traditional security models, highlighting its critical role in next-generation cybersecurity infrastructures.
Chinedu Eze· International Journal of App...· 0 citations
This study examines the application of artificial intelligence-powered intrusion detection systems that leverage deep learning architectures and anomaly detection methodologies to identify malicious activities within dynamic network environments and concludes that the convergence of deep learning methodologies and anomaly detection techniques provides a robust foundation for next-generation intrusion detection systems.
M. A. Gandhi, Dinesh Baban Kute, U. Hemavathi· International journal of com...· 0 citations
This chapter explores innovative AI technologies, including Machine Learning, Deep Learning, Reinforcement Learning, Explainable AI, and Generative AI, for intelligent attack detection, prediction, and mitigation and discusses current challenges, implementation limitations, and future research directions.
S. Mohanarangan, G. Shoba, D. Karthika et al.· International Journal of Com...· 0 citations
This paper evaluated the proposed framework for AI integrated cyber security (AICSF) for real-time threat detection and mitigation in smart industry environments in an AI-Mode, leveraging a recurrently refined DL architecture for real-time anomaly detection and adversarial learning.
S. Kiran, G. Shankarlingam, N. S. Kumar· International journal of com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.