Home / Current Issue / Paper 1712148
Behavioural Analytics for Predicting Social Engineering Attacks: A Risk-Based Approach Using Decision Trees, Gradient Boosting, and Bayesian Networks
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity
DOI: https://doi.org/10.64388/IREV9I5-1712148
Abstract
Social engineering attacks exploit human behaviour and remain a leading cause of security breaches. This paper evaluates predictive models that use behavioural analytics to estimate the risk of social engineering attacks. We compare Decision Trees, Gradient Boosting (XGBoost style ensemble) and Bayesian Networks on a phishing websites / behavioural dataset. Feature engineering emphasized URL and interaction patterns, response times, and email interaction rates. Models were trained and evaluated using accuracy, precision, recall, F1, and ROC-AUC. Gradient Boosting attained the highest ROC-AUC and strong F1 scores, Decision Trees offered interpretability, and Bayesian Networks provided probabilistic insight. We propose a lightweight risk prediction framework suitable for integration with alerting systems and security awareness programs.
Keywords
Behavioural Analytics, Machine Learning, Phishing, Socialengineering, Risk Prediction
References
[1] Afripol African Cyberthreat Assessment Report (2023), highlighting phishing risks and cybersecurity challenges in African countries (INTERPOL)
[2] Ali, A., & Shah, A. (2021). Machine Learning in Cybersecurity: Phishing Detection. Journal of Cybersecurity Privacy..
[3] Das, S., & Rakesh, B. (2020). Predictive Analytics in Cybersecurity: Using Machine Learning Techniques. International Journal of Information Security.
[4] Fadli, A., & Nuranida, A. (2020). Phishing websites detection using machine learning. Journal of Cyber Security Technology.
[5] Fu, C., & Li, P. (2020). Cybersecurity and Artificial Intelligence: Innovations in Phishing Detection. Journal of Information Security.
[6] North, D., & Price, B. (2020). Phishing attacks and their impact on businesses: A Game Theory approach. Computers & Security.
[7] Sharma, A., & Saini, P. (2020). A Hybrid Model for Phishing Detection Using Machine Learning. Soft Computing.
[8] Soni, P., & Rani, R. (2020). Predictive Modeling for Phishing Websites. Journal of Ambient Intelligence and Humanized Computing.
How to cite this paper
@article{1712148,
author = {Aweda Azeez Adebayo, Wusu, Ashiribo Senapon, Adegoke Stephen Olaniyan, Oladayo Ibunkunoluwa, Oladimeji},
title = {Behavioural Analytics for Predicting Social Engineering Attacks: A Risk-Based Approach Using Decision Trees, Gradient Boosting, and Bayesian Networks},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {5},
pages = {1780-1787},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1712148.pdf},
abstract = {Social engineering attacks exploit human behaviour and remain a leading cause of security breaches. This paper evaluates predictive models that use behavioural analytics to estimate the risk of social engineering attacks. We compare Decision Trees, Gradient Boosting (XGBoost style ensemble) and Bayesian Networks on a phishing websites / behavioural dataset. Feature engineering emphasized URL and interaction patterns, response times, and email interaction rates. Models were trained and evaluated using accuracy, precision, recall, F1, and ROC-AUC. Gradient Boosting attained the highest ROC-AUC and strong F1 scores, Decision Trees offered interpretability, and Bayesian Networks provided probabilistic insight. We propose a lightweight risk prediction framework suitable for integration with alerting systems and security awareness programs.},
keywords = {Behavioural Analytics, Machine Learning, Phishing, Socialengineering, Risk Prediction},
month = {November},
doi = {https://doi.org/10.64388/IREV9I5-1712148}
}