International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1706635

1706635 Vol 8 · Issue 6 Download Paper

Automated Threat Correlation Using Machine Learning: A Framework for Enhanced Cybersecurity

Feyisayo Ogunmade

Subject area: Science,Engineering and Technology  ·  Area of research: Cybersecurity

Abstract

As cyber threats grow increasingly sophisticated, the demand for agile, accurate, and automated methods to detect and respond to attacks has become imperative. This paper proposes a novel machine learning-driven framework for automated threat correlation, aimed at enhancing real-time threat detection and minimizing the manual oversight often required in traditional cybersecurity measures. By leveraging advanced algorithms, such as k-means clustering for event grouping, neural networks for pattern recognition, and the Apriori algorithm for association rule mining, the framework is designed to correlate threats from diverse data sources, including network traffic logs and threat intelligence feeds. This integration of machine learning models enhances detection accuracy, reduces false positives, and accelerates response times, significantly improving resource allocation for cybersecurity teams. The proposed framework also addresses key challenges in data preprocessing, model selection, and privacy compliance, demonstrating its potential for scalability and adaptability to various threats. Comparative analysis with prior approaches highlights the framework?s efficiency in reducing detection latency and improving resilience against multi-stage cyberattacks. This work concludes with recommendations for future enhancements, such as incorporating deep learning models and expanding data sources, to further refine the framework's capabilities. The proposed machine learning-based approach for automated threat correlation represents a critical advancement in cybersecurity, providing organizations with an adaptive, resilient, and scalable solution.

Keywords

Cybersecurity, Machine Learning, Threat Correlation, Automated Detection, Clustering, Neural Networks, Real-Time Threat Detection, Data Preprocessing, False Positives, Cyber Threat Intelligence

References

[1] Ahsan, Mostofa, Kendall E. Nygard, Rahul Gomes, Md Minhaz Chowdhury, Nafiz Rifat, and Jayden F Connolly. 2022. "Cybersecurity Threats and Their Mitigation Approaches Using Machine Learning—A Review" Journal of Cybersecurity and Privacy 2, no. 3: 527-555. https://doi.org/10.3390/jcp2030027

[2] Aminu, Muritala & Akinsanya, Ayokunle & Oyedokun, Oyewale & Dickson, Apaleokhai & Dako,. (2024). Enhancing Cyber Threat Detection through Real-time Threat Intelligence and Adaptive Defense Mechanisms. International Journal of Computer Applications Technology and Research. 13. 11-27. 10.7753/IJCATR1308.1002

[3] Aslan, Ömer & Aktug, Semih & Ozkan Okay, Merve & Yılmaz, Abdullah & Akin, Erdal. (2023). A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions. Electronics. 12. 1-42. 10.3390/electronics12061333.

[4] Azeem M, Javaid S, Khalil RA, Fahim H, Althobaiti T, Alsharif N, Saeed N. (2023). Neural Networks for the Detection of COVID-19 and Other Diseases: Prospects and Challenges. Bioengineering (Basel). 2023 Jul 18;10(7):850. doi: 10.3390/bioengineering10070850. PMID: 37508877; PMCID: PMC10416184.

[5] Cai, Li & Zhu, Yangyong. (2015). The Challenges of Data Quality and Data Quality Assessment in the Big Data Era. Data Science Journal. 14. 10.5334/dsj-2015-002.

[6] Chao Liu; Zhaojun Gu; Jialiang Wang. (2021). A Hybrid Intrusion Detection System Based on Scalable K-Means+ Random Forest and Deep Learning. https://ieeexplore.ieee.org/abstract/document/9437227

[7] Cybersainik. (2021). Threat Correlation: A Comprehensive Guide. https://cybersainik.com/threat-correlation-a-comprehensive-guide/#:~:text=Threat%20correlation%20is%20using%20correlation,events%20to%20identify%20potential%20threats.

[8] Dalal, S., Manoharan, P., Lilhore, U.K. et al. (2023). Extremely boosted neural network for more accurate multi-stage Cyber attack prediction in a cloud computing environment. J Cloud Comp 12, 14 (2023). https://doi.org/10.1186/s13677-022-00356-9

[9] Dhongade, Gauri & Chandrakar, Dr & Khande, Rajeshree. (2024). Enhancing Cyber Security: A Study of Data Preprocessing Techniques for Cyber Security Datasets. International Journal of Scientific Research in Science and Technology. 11. 71-75. 10.32628/IJSRST2411427.

[10] Dol Aher, Sunita & J., Lobo. (2012). Combination of Clustering, Classification & Association Rule-based Approach for Course Recommender System in E-learning. International Journal of Computer Applications. 39. 8-15. 10.5120/4830-7087.

[11] Franklim Arévalo, Paolo Barucca, Isela-Elizabeth Téllez-León, William Rodríguez, Gerardo Gage, Raúl Morales. (2022). Identifying clusters of anomalous payments in the Salvadorian payment system. Latin American Journal of Central Banking. https://doi.org/10.1016/j.latcb.2022.100050.

[12] Haas, Steffen & Wilkens, Florian & Fischer, Mathias. (2019). Efficient Attack Correlation and Identification of Attack Scenarios based on Network-Motifs. 10.48550/arXiv.1905.06685.

[13] IBM (2024). IBM Report: Escalating Data Breach Disruption Pushes Costs to New Highs https://newsroom.ibm.com/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs#:~:text=Hacking%20the%20clock%20with%20AI,those%20disclosed%20by%20an%20attacker.

[14] J. Pavithra, S. Selvakumara Samy. (2022) A Comparative Study on Detection of Malware and Benign on the Internet Using Machine Learning Classifiers. Mathematical Problem Engineering. https://doi.org/10.1155/2022/4893390

[15] Kiran Maharana, Surajit Mondal, Bhushan Kumar Nemade. (2022). A review: Data pre-processing and data augmentation techniques. Global Transitions Proceedings. https://doi.org/10.1016/j.gltp.2022.04.020

[16] Kumar, Mukesh. (2012). Evaluating the performance of apriori and predictive apriori algorithms to find new association rules based on the statistical measures of datasets. IJERT "International Journal of Engineering Research and Technology". 1. 1-5.

[17] Li, Jingwen, Jianyi Liu, and Ru Zhang. 2024. "Advanced Persistent Threat Group Correlation Analysis via Attack Behavior Patterns and Rough Sets" Electronics 13, no. 6: 1106. https://doi.org/10.3390/electronics13061106.

[18] Maosa, Herbert, Karim Ouazzane, and Mohamed Chahine Ghanem. 2024. "A Hierarchical Security Event Correlation Model for Real-Time Threat Detection and Response" Network 4, no. 1: 68-90. https://doi.org/10.3390/network4010004

[19] Massella M, Dri DA, Gramaglia D. (2022). Regulatory Considerations on the use of Machine Learning-based tools in Clinical Trials. Health Technol (Berl). 2022;12(6):1085-1096. doi: 10.1007/s12553-022-00708-0. Epub 2022 Nov 7. PMID: 36373014; PMCID: PMC9638313.

[20] Mayra Macas, Chunming Wu, Walter Fuertes. (2024). Adversarial examples: A survey of attacks and defenses in deep learning-enabled cybersecurity systems. Expert Systems with Applications. https://doi.org/10.1016/j.eswa.2023.122223.

[21] Michal Tonhausera & Jozef Ristveja. (2023). TRANSCOM 2023: 15th International Scientific Conference on Sustainable, Modern and Safe Transport Cybersecurity Automation in Countering Cyberattacks. Transportation Research Procedia

[22] Norsyafawati, Fatin & Sabri, Mohd & Md Norwawi, Norita & Seman, Kamaruzzaman. (2011) Identifying False Alarm Rates for Intrusion Detection System with Data Mining. https://www.researchgate.net/publication/264880778_Identifying_False_Alarm_Rates_for_Intrusion_Detection_System_with_Data_Mining

[23] Ovais Naseem. 2024. Ensuring Data Accuracy in Machine Learning Models. Data-Driven Investors. https://www.datadriveninvestor.com/2024/08/28/ensuring-data-accuracy-in-machine-learning-models/

[24] Potter, Kaledio & Doris, Lucas. (2024). AI-POWERED THREAT DETECTION AND INCIDENT RESPONSE SYSTEMS. Cybersecurity.

[25] Sarker, I.H., Kayes, A.S.M., Badsha, S. et al. (2020). Cybersecurity data science: an overview from a machine learning perspective. J Big Data 7, 41. https://doi.org/10.1186/s40537-020-00318-5

[26] Salem, A.H., Azzam, S.M., Emam, O.E. et al. (2024). Advancing cybersecurity: a comprehensive review of AI-driven detection techniques. J Big Data 11, 105 (2024). https://doi.org/10.1186/s40537-024-00957-y

[27] Sameera, Nerella & Jyothi, M.Siva & K.Lakshmaji, & Neeli, V S R Pavan Kumar. (2023). Clustering-based Intrusion Detection System for effective Detection of known and Zero-day Attacks. Journal of Advanced Zoology. 44. 969-975. 10.17762/jaz.v44i4.2423.

[28] Sharma, Vinod. (2022). A Study on Data Scaling Methods for Machine Learning. International Journal for Global Academic & Scientific Research. 1. 10.55938/ijgasr.v1i1.4.

[29] Shahid Tufail, Hugo Riggs, Mohd Tariq, and Arif I. Sarwat. (2023). Advancements and Challenges in Machine Learning: A Comprehensive Review of Models, Libraries, Applications, and Algorithms. https://doi.org/10.3390/electronics12081789

[30] Siraj, Fakiha. (2020). CYBERSECURITY SITUATION AWARENESS 1 Effectiveness of Security Incident Event Management (SIEM) system for Cyber Security Situation Awareness. Indian Journal of Forensic Medicine & Toxicology. 14. 10.37506/ijfmt.v14i4.11587.

[31] Statista. (2023). The annual amount of financial damage caused by reported cybercrime in the U.S. 2001-2023. https://www.statista.com/statistics/267132/total-damage-caused-by-by-cybercrime-in-the-us/#:~:text=Annual%20amount%20of%20financial%20damage,cybercrime%20in%20U.S.%202001%2D2023&text=In%202023%2C%20the%20monetary%20damage,of%2012.5%20billion%20U.S.%20dollars.

[32] Stellar Cyber (2021). Stellar Cyber’s Open XDR Debuts AI-Powered Incident Correlation to Reveal and Stop Cyberattacks Faster https://stellarcyber.ai/news/press-releases/stellar-cyber-debuts-ai-powered-incident-correlation-to-reveal-and-stop-cyberattacks-faster/

[33] Sumathi P., Srinivasan. K, Meenu Parames. P, Sathya Murthy. D, Hari Krishnan B. (2024). AI-Powered Defense Against Phishing Threats for Enterprises. https://doi.org/10.22214/ijraset.2024.60395

[34] Taye, Mohammad Mustafa. 2023. "Understanding of Machine Learning with Deep Learning: Architectures, Workflow, Applications, and Future Directions" Computers 12, no. 5: 91. https://doi.org/10.3390/computers12050091

[35] Thapliyal, Vikalp & Thapliyal, Pranita. (2024). Machine Learning for Cybersecurity: Threat Detection, Prevention, and Response. Darpan International Research Analysis. 12. 1-7. 10.36676/dira.v12.i1.01.

[36] Trayi Chaganti & Rohith Tadi. (2022). Comparison of Machine Learning Algorithms for Anomaly Detection in Train’s Real-Time Ethernet using an Intrusion Detection System. Faculty of Computing, Blekinge Institute of Technology. https://www.diva-portal.org/smash/get/diva2:1707593/FULLTEX f

[37] Wan, Wai & Tsimplis, Michael & Siau, Keng & Yue, Wei & Nah, Fiona & Yu, Gabriel. (2022). Legal and Regulatory Issues on Artificial Intelligence, Machine Learning, Data Science, and Big Data. 10.1007/978-3-031-21707-4_40.

[38] Wasyihun Sema Admass, Yirga Yayeh Munaye, Abebe Abeshu Diro. (2024). Cyber security: State of the art, challenges, and future directions. Cyber Security and Applications. https://doi.org/10.1016/j.csa.2023.100031.

How to cite this paper

Feyisayo Ogunmade "Automated Threat Correlation Using Machine Learning: A Framework for Enhanced Cybersecurity" Iconic Research And Engineering Journals Volume 8 Issue 6 2024 Page 83-91
Feyisayo Ogunmade "Automated Threat Correlation Using Machine Learning: A Framework for Enhanced Cybersecurity" Iconic Research And Engineering Journals, vol. 8, no. 6, Dec. 2024
Feyisayo Ogunmade (2024). Automated Threat Correlation Using Machine Learning: A Framework for Enhanced Cybersecurity. Iconic Research And Engineering Journals, 8(6).
Feyisayo Ogunmade "Automated Threat Correlation Using Machine Learning: A Framework for Enhanced Cybersecurity" Iconic Research And Engineering Journals, vol. 8, no. 6, Dec. 2024.
@article{1706635,
      author = {Feyisayo Ogunmade},
      title = {Automated Threat Correlation Using Machine Learning: A Framework for Enhanced Cybersecurity},
      journal = {Iconic Research And Engineering Journals},
      year = {2024},
      volume = {8},
      number = {6},
      pages = {83-91},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1706635.pdf},
      abstract = {As cyber threats grow increasingly sophisticated, the demand for agile, accurate, and automated methods to detect and respond to attacks has become imperative. This paper proposes a novel machine learning-driven framework for automated threat correlation, aimed at enhancing real-time threat detection and minimizing the manual oversight often required in traditional cybersecurity measures. By leveraging advanced algorithms, such as k-means clustering for event grouping, neural networks for pattern recognition, and the Apriori algorithm for association rule mining, the framework is designed to correlate threats from diverse data sources, including network traffic logs and threat intelligence feeds. This integration of machine learning models enhances detection accuracy, reduces false positives, and accelerates response times, significantly improving resource allocation for cybersecurity teams. The proposed framework also addresses key challenges in data preprocessing, model selection, and privacy compliance, demonstrating its potential for scalability and adaptability to various threats. Comparative analysis with prior approaches highlights the framework?s efficiency in reducing detection latency and improving resilience against multi-stage cyberattacks. This work concludes with recommendations for future enhancements, such as incorporating deep learning models and expanding data sources, to further refine the framework's capabilities. The proposed machine learning-based approach for automated threat correlation represents a critical advancement in cybersecurity, providing organizations with an adaptive, resilient, and scalable solution.},
      keywords = {Cybersecurity, Machine Learning, Threat Correlation, Automated Detection, Clustering, Neural Networks, Real-Time Threat Detection, Data Preprocessing, False Positives, Cyber Threat Intelligence},
      month = {December},
  }