Application of Machine Learning Algorithms for Cybersecurity: Detection and Classification of Malware, DDoS, and Phishing Attacks
Dušan Čatloch, Eva Chovancová, Martin Chovanec, Martin Štancel · 2025
Cybersecurity has become a critical aspect of safe-guarding personal, organizational, and national infrastructures in the past years. The ever-evolving nature of cyber threats, including malware, Distributed Denial of Service (DDoS), and phishing attacks, necessitates innovative approaches to threat detection and mitigation. This article investigates the application of machine learning algorithms—logistic regression, K-Nearest Neighbors (KNN), decision trees, and K-Means clustering—to enhance the detection and classification of these cyber threats. The study emphasizes the importance of dataset selection, preprocessing, and the evaluation of model performance using metrics such as accuracy, precision, recall, and F1 score. By conducting extensive experiments, we compare the strengths and limitations of supervised and unsupervised learning methods in detecting diverse types of cyber attacks. The results reveal that while supervised learning methods offer higher precision for specific attack types, unsupervised methods such as K-Means demonstrate adaptability in identifying novel attack patterns. Furthermore, the study explores the integration of these models into practical cybersecurity systems, highlighting their potential to adapt to new threats and enhance real-time detection capabilities. This research contributes to the development of data-driven, scalable, and adaptive security frameworks, paving the way for more resilient defenses against increasingly sophisticated cyber adversaries.