Effectiveness of Machine Learning Algorithms in Threat Detection and Mitigation in Cyberspace: A Systematic Review

M. A. Adaji, Francis S. Bakpo, Modesta Ero Ezema, Emmanuel Etuh, Caleb Markus, Samuel Owoicho Olofu, Buhari Isa Sambo · 2024

The rapid digitalization and proliferation of internet-connected devices have not only revolutionized our daily lives but also exponentially expanded the attack surface for cybercriminals, creating an increasingly complex and treacherous cybersecurity landscape. This review critically examines the effectiveness of machine learning (ML) algorithms in cyber threat detection and mitigation, addressing the need for advanced cybersecurity measures in our interconnected digital landscape. Following Kitchenham's guidelines and utilizing the PRISMA model, the study analyzed 907 initial records from Science Direct, Google Scholar, IEEE Xplore, Springer, and ACM Digital Library, ultimately including only 15 studies that met stringent criteria. The thematic analysis revealed varying effectiveness of supervised learning (SVM and Random Forests) with accuracy rates of 85-90%, but with moderate false positive rates (15-20%). Unsupervised learning techniques (like K-means and DBSCAN) demonstrated lower accuracy (70-75%) yet excelled in detecting novel threats, albeit with higher false positive rates (25-30%). Reinforcement learning showcased adaptive defense capabilities but suffered from lower accuracy (65-70%) due to adversarial manipulation. Deep learning methods achieved high accuracy (up to 99%) in specific tasks, yet faced challenges related to resource demands and limited interpretability. The study highlights data quality difficulties, high false positive and negative rates, and complex model interpretability issues. ML can automate incident response and security orchestration, but the evaluation stresses the need for a balanced approach with human experience. Increasing model interpretability and defending against adversarial attacks are research gaps. The paper emphasises the need of hybrid approaches and explainable AI techniques for cyber threat identification and mitigation using ML. This thorough study lays the groundwork for ML-based cybersecurity in a complex threat landscape, despite limitations owing to the continuous evolution of cyber threats and ML technology.

Read the paper · More papers on PaperTik