The increasing complexity and sophistication of cybersecurity threats necessitate the development of strong and flexible incident response systems. This study presents a hybrid methodology that utilizes various machine learning models such as Random Forest (RF), Decision Trees (DT), Isolation Forest, Convolutional Neural Network (CNN), and a unique Hybrid Gated Recurrent Unit—CNN (GRU-CNN) design. The proposed model seeks to improve the precision and effectiveness of incident detection and response in real-time. The study shows that combining various models is effective in creating a robust defense mechanism against cyber threats. Random Forest and Decision Trees improve model interpretability, while Isolation Forest boosts anomaly detection abilities. The Convolutional Neural Network integration aids in extracting spatial features from input data, while the Hybrid GRU-CNN enhances the model’s capacity to capture temporal dependencies in cybersecurity incidents. The hybrid approach demonstrated superior performance, achieving an impressive accuracy of 98.86% in incident detection and response, as shown by experimental results. The proposed model shows significant progress in managing spatial and temporal aspects of cybersecurity data, surpassing individual models and conventional methods. Combining machine learning methods creates a strong base for developing flexible and durable AI-powered incident response systems in the changing field of Cybersecurity.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

AI-Driven Incident Response Systems for Cybersecurity: A Hybrid Approach

  • Monika Soni,
  • Avinash M. Pawar,
  • Aditee Godbole,
  • Ashutosh Sharma,
  • S. A. Tiwaskar,
  • Chandrakant Deelip Kokane

摘要

The increasing complexity and sophistication of cybersecurity threats necessitate the development of strong and flexible incident response systems. This study presents a hybrid methodology that utilizes various machine learning models such as Random Forest (RF), Decision Trees (DT), Isolation Forest, Convolutional Neural Network (CNN), and a unique Hybrid Gated Recurrent Unit—CNN (GRU-CNN) design. The proposed model seeks to improve the precision and effectiveness of incident detection and response in real-time. The study shows that combining various models is effective in creating a robust defense mechanism against cyber threats. Random Forest and Decision Trees improve model interpretability, while Isolation Forest boosts anomaly detection abilities. The Convolutional Neural Network integration aids in extracting spatial features from input data, while the Hybrid GRU-CNN enhances the model’s capacity to capture temporal dependencies in cybersecurity incidents. The hybrid approach demonstrated superior performance, achieving an impressive accuracy of 98.86% in incident detection and response, as shown by experimental results. The proposed model shows significant progress in managing spatial and temporal aspects of cybersecurity data, surpassing individual models and conventional methods. Combining machine learning methods creates a strong base for developing flexible and durable AI-powered incident response systems in the changing field of Cybersecurity.