A review of machine learning techniques in cybersecurity and research opportunities
Sangeeta Mittal · 2022
The past few years have seen a dramatic surge in Internet usage of all individuals. Moreover, this usage has evolved from casual surfing to serious online businesses. Pandemic has further greased the wheels of cyber presence as many organizations plan to go completely online, thereby increasing the importance of cybersecurity than never before. Cyber monitoring systems generate humongous amount of data that is difficult to be analyzed manually and thus machine learning (ML) techniques have been leveraged to make sense out of this data in real time to prevent cyberattacks. A systematic summary of ML applications in cyber defense have been provided by mapping threat categories to ML-based solutions. On examining these implementations, it has been concluded that issues like availability of real-world attack data, concept drift in normal behavior, and processing power issues are still not resolved. It has been discussed that due to these prevailing issues, the performance of ML-based security systems may decrease dramatically in actual implementations. New research directions in this domain have also been highlighted in the chapter.