Review on Cyber Defence with Machine Learning: A System for Detecting and Monitoring Attacks
DOI:
https://doi.org/10.70112/ajcst-2026.15.2.4469Keywords:
Cybersecurity, Malware Detection, Machine Learning, Cyber Threat Intelligence, Cyber-attackAbstract
Cybersecurity experts concentrate on identifying risk profiles and thinking up ways of handling them properly as the main focus of their work. One of the main objectives in this area is to set up strong and powerful ways to reinforce security measures. The use of machine learning has transformed the whole landscape of cyber defense systems in modern times to a great extent. It is the breakthroughs in data storage, processing power, and communication that have not only hastened the use of cloud services but also of advanced networks and programming languages that are gradually being replaced by more sophisticated ones. The ongoing digital transformation worldwide is building up the need for complex privacy and security issues to be handled, which in turn, puts pressure on the existing safeguards to further strengthen themselves against new and more efficient threats. The ever-growing computer system weaknesses are being looked upon as one of the root causes of the increase in the incidence of worldwide cyber terrorism. But on the other hand, the same technique is utilized to solve different global security issues through machine learning, which includes the detection of malicious software, the identification of ransomware, the detection of fraud, and the verification of spoofing attempts. This article looks into the dual role of online behavior modeling in attack and defense, revealing cyber risks through the application of machine learning tools and software. It also discusses the most common cyber threats and points out how machine learning helps in detection and prevention of attacks, vulnerability assessment, and open-source risk evaluation in the digital commerce sector.
References
[1] N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in Proc. Military Communications and Information Systems Conf. (MilCIS), Canberra, Australia, 2015, pp. 1–6.
[2] S. García, A. Zunino, and M. Campo, “The CTU-13 dataset: A benchmark for botnet detection,” Stratosphere IPS Project, Czech Technical University, Prague, Czech Republic, 2011.
[3] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” in Proc. Int. Conf. Inf. Syst. Security Privacy (ICISSP), Funchal, Portugal, 2018, pp. 108–116.
[4] M. Sarhan, A. Layeghy, N. Moustafa, and M. Portmann, “NetFlow datasets for machine learning-based network intrusion detection systems,” in Big Data Technologies and Applications, Springer, 2020, pp. 117–135.
[5] S. Sriram, R. Vinayakumar, M. Alazab, and K. P. Soman, “Network-flow based IoT botnet attack detection using deep learning,” in Proc. IEEE INFOCOM Workshops, Paris, France, 2019, pp. 189–194.
[6] H. Haddadi and R. Mortier, “NetFlow-based botnet detection using deep learning,” Security and Communication Networks, vol. 2023, Art. no. 2856912, 2023.
[7] M. Shinan, A. Abusitta, and M. Guizani, “Machine learning-based botnet detection: A survey,” Symmetry, vol. 13, no. 4, pp. 1–29, 2021.
[8] A. Najafimehr, “DDoS attacks and machine-learning-based detection: A taxonomy and survey,” Engineering Reports, vol. 5, no. 3, pp. 1–23, 2023.
[9] D. Choi, J. Kim, and H. Kim, “Attack-specific feature analysis for NetFlow IoT intrusion detection,” Journal of Information Security and Applications, vol. 79, pp. 103–118, 2025.
[10] M. Hossain, “Deep Q-learning intrusion detection system (DQ-IDS),” in Proc. Int. Conf. Information and Communication Technology (ICT), Dhaka, Bangladesh, 2025, pp. 1–7.
[11] R. Chinnasamy, “Deep learning-driven methods for network-based intrusion detection systems: A systematic review,” ICT Express, vol. 11, no. 2, pp. 1–12, 2025.
[12] V. Z. Mohale, S. B. Jagtap, and A. R. Patil, “Evaluating machine learning-based intrusion detection systems,” Frontiers in Computer Science, vol. 7, Art. no. 1520741, 2025.
[13] M. Luay, A. Alshamrani, and M. Alenezi, “Temporal analysis of NetFlow datasets for network intrusion detection systems,” arXiv preprint arXiv:2503.04404, 2025.
[14] J. Li, Y. Zhang, and X. Wang, “NFIoT-GATE-DTL: GA-tuned ensemble deep transfer learning for IoT intrusion detection,” Expert Systems with Applications, vol. 242, Art. no. 122987, 2025.
[15] G. G. Granadillo, R. Pries, and M. Bagnulo, “AI-based anomaly detection and classification of traffic using NetFlow,” in Proc. Int. Conf. Security and Cryptography (SECRYPT), Rome, Italy, 2025, pp. 321–331.
[16] D. Wagner and R. Soto, "Mimicry Attacks on Host-Based Intrusion Detection Systems," in Proc. 9th ACM Conf. Computer and Communications Security (CCS’02), pp. 255–264, 2002.
[17] C. Kruegel, D. Mutz, W. Robertson, and F. Valeur, "Bayesian Event Classification for Intrusion Detection," in Proc. 19th Annual Computer Security Applications Conf. (ACSAC), pp. 14–23, 2003.
[18] S. Benferhat and K. Tabia, "A Bayesian Approach for Intrusion Detection in Large-Scale Networks," in Proc. 5th Int. Conf. Intelligent Data Engineering and Automated Learning (IDEAL 2004), pp. 41–49, 2004.
[19] L. Koc, T. A. Mazzuchi, and S. Sarkani, "A Network Intrusion Detection System Based on a Hidden Naive Bayes Multiclass Classifier," Expert Syst. Appl., vol. 39, no. 18, pp. 13492–13500, 2012.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Centre for Research and Innovation

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
