Foundations of AI and ML in Security

Sunil Kumar Mohapatra, Ankita Biswal, Harapriya Senapati, Adyasha Swain, Swarupa Pattanaik · 2025

The Internet has been ingrained in people's daily lives worldwide; simultaneously, online criminal behavior has inspired advances in cybersecurity. Traditional cybersecurity approaches involve proactive efforts involving technologies, best practices, and policies to ensure information confidentiality, integrity, and availability. However, they have limitations, such as relying on static defense mechanisms, struggling with advanced threats, being dependent on perimeter defense, and the false positives/negatives. These vulnerabilities lead to increased Phishing attacks, Ransomware attacks, DDoS, MitM attacks, SQL Injection, IOT exploitation, and Social Engineering attacks. So, several data-driven computational models such as AI and ML have been revolutionized to address these security issues. The pillar of AI and ML in security lies in their potential to inspect vast amounts of data, make predictions, and detect patterns or decisions without explicit programming. Feature engineering methodology selects, manipulates, and builds essential features from raw data to improve the effectiveness of machine learning models in detecting and preventing cyber-attacks. These processes contribute to developing a clean, informative, and balanced dataset to train accurate and trustworthy machine learning models for cybersecurity tasks. Integrating real-time detection with WAF provides a proactive and dynamic security mechanism, allowing enterprises to respond quickly to developing cyber threats and defend their web applications from diverse attacks. This chapter elaborates on the technique for leveraging AI and ML in cybersecurity, emphasizing their synergistic role in improving attack detection, response, and overall system resilience.

Read the paper · More papers on PaperTik