AI-Driven Incident Response Systems for Cybersecurity: A Hybrid Approach
摘要
The increasing complexity and sophistication of cybersecurity threats necessitate the development of strong and flexible incident response systems. This study presents a hybrid methodology that utilizes various machine learning models such as Random Forest (RF), Decision Trees (DT), Isolation Forest, Convolutional Neural Network (CNN), and a unique Hybrid Gated Recurrent Unit—CNN (GRU-CNN) design. The proposed model seeks to improve the precision and effectiveness of incident detection and response in real-time. The study shows that combining various models is effective in creating a robust defense mechanism against cyber threats. Random Forest and Decision Trees improve model interpretability, while Isolation Forest boosts anomaly detection abilities. The Convolutional Neural Network integration aids in extracting spatial features from input data, while the Hybrid GRU-CNN enhances the model’s capacity to capture temporal dependencies in cybersecurity incidents. The hybrid approach demonstrated superior performance, achieving an impressive accuracy of 98.86% in incident detection and response, as shown by experimental results. The proposed model shows significant progress in managing spatial and temporal aspects of cybersecurity data, surpassing individual models and conventional methods. Combining machine learning methods creates a strong base for developing flexible and durable AI-powered incident response systems in the changing field of Cybersecurity.