PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 6, 20260 citationsOpen Access

An Ensemble Machine Learning Framework for Automated Cybersecurity Incident Classification Using Structured Metadata

View Full Paper
SOSamuel Adeolu OgunbiyiOAOludele AdelekeUniversity of IbadanOOO. OsunadeUniversity of Ibadan

Key Points

  • This study aims to develop an automated framework for classifying cybersecurity incidents using machine learning.
  • Developed an ensemble machine learning framework using structured cybersecurity incident metadata.
  • Analyzed a dataset of 93,144 incidents categorized into six attack types.
  • Applied supervised learning algorithms: Decision Tree and Random Forest, among others.
  • Utilized SMOTE to address class imbalance; dataset split into training, validation, and testing.
  • Extra Trees classifier achieved highest accuracy at 95.4% and macro F1-score at 95.2%.
  • Random Forest followed with 94% accuracy, while Decision Tree and KNN showed 88% and 81%, respectively.
  • High performance across all attack categories despite misclassifications between closely related classes.
  • Feature importance analysis revealed user agent and IP variables significantly contribute to predictive performance.

Abstract

This study addresses the growing need for accurate and automated cyber incident classification systems to support timely decision-making in response to increasing cyber threats. It develops and evaluates an ensemble machine learning framework for multi-class classification using structured cybersecurity incident metadata. A dataset of 93,144 incidents, categorized into six attack types, was analyzed using four supervised learning algorithms: Decision Tree, K-Nearest Neighbors (KNN), Random Forest, and Extra Trees. To address class imbalance, the Synthetic Minority Oversampling Technique (SMOTE) was applied. The dataset was split into 80% training, 10% validation, and 10% testing, and model performance was evaluated using accuracy, precision, recall, and F1-score, alongside confusion matrix and feature importance analysis. Results show that ensemble models outperform non-ensemble approaches, with the Extra Trees classifier achieving the highest performance (95.4% accuracy and 95.2% macro F1-score), followed by Random Forest (94%), Decision Tree (88%), and KNN (81%). Performance remained consistently high across all attack categories, with most misclassifications occurring between closely related classes. Feature importance analysis revealed that over 80% of predictive performance was driven by variables such as user agent, source IP, destination IP, and temporal features. The study concludes that lightweight and interpretable ensemble models can achieve high classification accuracy comparable to more complex methods while remaining computationally efficient. The proposed framework offers a practical and scalable solution for real-world cybersecurity incident classification and supports improved incident response strategies.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Ogunbiyi et al. (2026) studied this question.

synapsesocial.com/papers/69fa980604f884e66b531d23https://doi.org/10.5281/zenodo.20025310
Ask AI
Helpful
Bookmark
Share
View Full Paper