Machine learning model for classifying the severity level of cybersecurity attacks

(1) * Imam Riadi Mail (Universitas Ahmad Dahlan, Indonesia)
(2) Sri Winiarti Mail (Informatics Department, Universitas Ahmad Dahlan, Indonesia)
(3) Herman Yuliansyah Mail (Informatics Department, Universitas Ahmad Dahlan, Indonesia)
(4) Muhammad ‘Arif Bin Mohamad Mail (Universiti Malaysia Pahang Al-Sultan Abdullah, Malaysia)
*corresponding author

Abstract


Cyberattacks are becoming increasingly sophisticated, necessitating defense mechanisms that go beyond simple detection to include severity assessment for prioritizing mitigation. This study proposes a comprehensive machine learning framework to classify cyberattack severity levels (Low, Medium, High) using a modern, high-dimensional dataset. Addressing the critical challenge of class imbalance, the research integrates the Synthetic Minority Oversampling Technique (SMOTE) with a rigorous feature selection process involving SelectKBest. Four algorithms Naive Bayes, K-Nearest Neighbor (KNN), Random Forest (RF), and Support Vector Machine (SVM) were evaluated using 10-fold cross-validation. The results demonstrate that the SVM model with an RBF kernel achieves superior performance with an accuracy of 97.30% and a False Negative Rate (FNR) of only 3.1% for high-severity threats. This research contributes a robust, data-driven approach to severity classification that effectively handles feature non-linearity and class imbalance, offering actionable insights for real-time security operations.

Keywords


Machine Learning; Model Classification; Cyber Security; Attack

   

DOI

https://doi.org/10.26555/ijain.v12i2.2245
      

Article metrics

Abstract views : 180 | PDF views : 1

   

Cite

   

Full Text

Download

References


[1] A. Kumar and L. K. Singh, “A Study on Machine Learning-Based Models for Cyber Attack Classification and Severity Estimation,” Int. J. Comput. Appl., vol. 187, no. 41, pp. 65–70, Sep. 2025, doi: 10.5120/ijca2025925729.

[2] J. Note, E. Mullalli, and B. CICO, “Machine Learning Algorithms for Cyber Attack Detection And Classification,” in Proceedings of the International Conference on Computer Systems and Technologies 2024, New York, NY, USA: ACM, Jun. 2024, pp. 29–36. doi: 10.1145/3674912.3674937.

[3] N. Mohamed, “Artificial intelligence and machine learning in cybersecurity: a deep dive into state-of-the-art techniques and future paradigms,” Knowl. Inf. Syst., vol. 67, no. 8, pp. 6969–7055, Aug. 2025, doi: 10.1007/s10115-025-02429-y.

[4] M. K. Hasan, R. A. Abdulkadir, S. Islam, T. R. Gadekallu, and N. Safie, “A review on machine learning techniques for secured cyber-physical systems in smart grid networks,” Energy Reports, vol. 11, pp. 1268–1290, Jun. 2024, doi: 10.1016/j.egyr.2023.12.040.

[5] M. M. Alani, L. Mauri, and E. Damiani, “A two-stage cyber attack detection and classification system for smart grids,” Internet of Things, vol. 24, p. 100926, Dec. 2023, doi: 10.1016/j.iot.2023.100926.

[6] M. Alharby, “Evaluating machine learning approaches for multiple attack classification with improved computational efficiency in IoT networks,” Sci. Rep., vol. 15, no. 1, p. 39914, Nov. 2025, doi: 10.1038/s41598-025-23711-7.

[7] I. Avci and M. Koca, “Cybersecurity Attack Detection Model, Using Machine Learning Techniques,” Acta Polytech. Hungarica, vol. 20, no. 7, pp. 29–44, 2023, doi: 10.12700/APH.20.7.2023.7.2.

[8] S. T. Hamidou and A. Mehdi, “Enhancing IDS performance through a comparative analysis of Random Forest, XGBoost, and Deep Neural Networks,” Mach. Learn. with Appl., vol. 22, no. December, p. 100738, Dec. 2025, doi: 10.1016/j.mlwa.2025.100738.

[9] F. Ebrahimi, R. Javidan, R. Akbari, and Y. Hosseini, “Intrusion detection in the internet of things using convolutional neural networks: an explainable AI approach,” Cybersecurity, vol. 8, no. 1, p. 66, Sep. 2025, doi: 10.1186/s42400-025-00369-2.

[10] S. Naeem, Aqib Ali, Sania Anam, and Muhammad Munawar Ahmed, “Machine Learning for Intrusion Detection in Cyber Security: Applications, Challenges, and Recommendations,” Innov. Comput. Rev., vol. 2, no. 2, pp. 41–64, Dec. 2022, doi: 10.32350/icr.0202.03.

[11] H. M. R. U. Rehman et al., “A systematic literature study of machine learning techniques based intrusion detection: datasets, models, challenges, and future directions,” J. Big Data, vol. 12, no. 1, p. 264, Nov. 2025, doi: 10.1186/s40537-025-01323-2.

[12] K. Kioskli and N. Polemi, “Estimating Attackers’ Profiles Results in More Realistic Vulnerability Severity Scores,” in Human Factors in Cybersecurity, AHFE Open Access, 2022, pp. 138–150. doi: 10.54941/ahfe1002211.

[13] R. Cichocki and P. Wojcik, “Cybersecurity in Maritime Transport Systems: Threats, Trends, and Countermeasures in the Last Decade,” TransNav, Int. J. Mar. Navig. Saf. Sea Transp., vol. 19, no. 3, pp. 715–722, Sep. 2025, doi: 10.12716/1001.19.03.03.

[14] U. M. Alhaji, S. E. Adewumi, and V. I. Yemi-peters, “Classification of Phishing Attacks Using Machine Learning Algorithms: A Systematic Literature Review,” J. Adv. Math. Comput. Sci., vol. 40, no. 1, pp. 26–44, Jan. 2025, doi: 10.9734/jamcs/2025/v40i11960.

[15] D. Elreedy, A. F. Atiya, and F. Kamalov, “A theoretical distribution analysis of synthetic minority oversampling technique (SMOTE) for imbalanced learning,” Mach. Learn., vol. 113, no. 7, pp. 4903–4923, Jul. 2024, doi: 10.1007/s10994-022-06296-4.

[16] P. Zhao et al., “T-SMOTE: Temporal-oriented Synthetic Minority Oversampling Technique for Imbalanced Time Series Classification,” in Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence, California: International Joint Conferences on Artificial Intelligence Organization, Jul. 2022, pp. 2406–2412. doi: 10.24963/ijcai.2022/334.

[17] S. Mateen, N. Nuthammachot, and K. Techato, “Random forest and artificial neural network-based tsunami forests classification using data fusion of Sentinel-2 and Airbus Vision-1 satellites: A case study of Garhi Chandan, Pakistan,” Open Geosci., vol. 16, no. 1, Feb. 2024, doi: 10.1515/geo-2022-0595.

[18] J. B. Jesudasan Peter et al., “SVM algorithm-based anomaly detection in network logs and firewall logs,” Indones. J. Electr. Eng. Comput. Sci., vol. 38, no. 3, p. 1642, Jun. 2025, doi: 10.11591/ijeecs.v38.i3.pp1642-1651.

[19] V. Sai Swaroop Reddy, “Cybersecurity Threat Prediction Using Machine Learning,” Int. J. Sci. Res., vol. 12, no. 4, pp. 1972–1976, Apr. 2023, doi: 10.21275/SR23048115831.

[20] s. Venkatraman, S. Kanthimathi, K. S. Jayasankar, T. Pranay Jiljith, and R. Jashwanth, “A Novel Self-Attention-Enabled Weighted Ensemble-Based Convolutional Neural Network Framework for Distributed Denial of Service Attack Classification,” IEEE Access, vol. 12, pp. 151515–151531, 2024, doi: 10.1109/ACCESS.2024.3478764.

[21] A. Z.K. Matloob, M. Ibrahim, and H. Kadem, “Machine Learning-Based Classification Models for Efficient DDoS Detection,” Int. J. Comput. Digit. Syst., vol. 17, no. 1, pp. 1–13, Jan. 2025, doi: 10.12785/ijcds/1571110617.

[22] N. R. Abid-Althaqafi and H. A. Alsalamah, “The Effect of Feature Selection on the Accuracy of X-Platform User Credibility Detection with Supervised Machine Learning,” Electronics, vol. 13, no. 1, p. 205, Jan. 2024, doi: 10.3390/electronics13010205.

[23] M. A. Tariq, “A Study on Comparative Analysis of Feature Selection Algorithms for Students Grades Prediction,” J. Inf. Organ. Sci., vol. 48, no. 1, pp. 133–147, Jun. 2024, doi: 10.31341/jios.48.1.7.

[24] S. Tarannum, M. S. Jalal, and M. N. Huda, “HALALCheck: A Multi-Faceted Approach for Intelligent Halal Packaged Food Recognition and Analysis,” IEEE Access, vol. 12, pp. 28462–28474, 2024, doi: 10.1109/ACCESS.2024.3367983.

[25] P. Mukherji, S. Rajput, and V. Mudaliar, “A novel accelerated sparse Support Vector Machine (AS-SVM) algorithm for binary classification of DNA sequences,” Franklin Open, vol. 13, no. December, p. 100427, Dec. 2025, doi: 10.1016/j.fraope.2025.100427.

[26] L. Bergamin and F. Aiolli, “An investigation into creating counterfactual examples for non-linear Support Vector Machines,” Neurocomputing, vol. 651, no. October, p. 130809, Oct. 2025, doi: 10.1016/j.neucom.2025.130809.

[27] A. Y. Shdefat, N. Mostafa, Z. Al-Arnaout, Y. Kotb, and S. Alabed, “Optimizing HAR Systems: Comparative Analysis of Enhanced SVM and k-NN Classifiers,” Int. J. Comput. Intell. Syst., vol. 17, no. 1, p. 150, Jun. 2024, doi: 10.1007/s44196-024-00554-0.

[28] Y. Nataliani, C. Arthur, T. Wellem, K. D. Hartomo, and N. H. A. Wahab, “Multi-Objective k-Nearest Neighbor for Breast Cancer Detection,” JOIV Int. J. Informatics Vis., vol. 9, no. 1, p. 241, Jan. 2025, doi: 10.62527/joiv.9.1.2669.

[29] A. Mustafid, M. M. Pamuji, and S. Helmiyah, “A Comparative Study of Transfer Learning and Fine-Tuning Method on Deep Learning Models for Wayang Dataset Classification,” IJID (International J. Informatics Dev., vol. 9, no. 2, pp. 100–110, Dec. 2020, doi: 10.14421/ijid.2020.09207.

[30] M. Sabri, R. Verde, and A. Balzanella, “FWLMkNN: Efficient functional K-nearest neighbor based on clustering and functional data analysis,” Expert Syst. Appl., vol. 292, no. November, p. 128567, Nov. 2025, doi: 10.1016/j.eswa.2025.128567.

[31] K. C. Waghmare and B. A., “Modified K-nearest Neighbor Algorithm with Variant K Values,” Int. J. Adv. Comput. Sci. Appl., vol. 11, no. 10, pp. 220–224, Oct. 2020, doi: 10.14569/IJACSA.2020.0111029.

[32] T. Winarti, H. Indriyawati, V. Vydia, and F. W. Christanto, “Performance comparison between naive bayes and k- nearest neighbor algorithm for the classification of Indonesian language articles,” IAES Int. J. Artif. Intell., vol. 10, no. 2, p. 452, Jun. 2021, doi: 10.11591/ijai.v10.i2.pp452-457.

[33] P. Changpetch, A. Pitpeng, S. Hiriote, and C. Yuangyai, “Integrating Data Mining Techniques for Naïve Bayes Classification: Applications to Medical Datasets,” Computation, vol. 9, no. 9, p. 99, Sep. 2021, doi: 10.3390/computation9090099.

[34] K. Zhang, J. Luo, C. Zhang, Y. Qiu, M. Shen, and H. Duan, “A remote sensing-based spatial prediction framework using a Naive Bayes approach for cyanobacterial blooms in eutrophic lakes of China,” J. Hydrol. Reg. Stud., vol. 62, no. December, p. 102894, Dec. 2025, doi: 10.1016/j.ejrh.2025.102894.

[35] N. Y. Nikitin and A. А. Stepashkin, “Classification of tensile test results of unidirectional carbon fiber-polysulfone composite material based on random forest, KNN and CNN methods,” Results Mater., vol. 28, no. December, p. 100788, Dec. 2025, doi: 10.1016/j.rinma.2025.100788.

[36] I. Afiqah et al., “Enhancing rock slope stability prediction using random forest machine learning: A case study,” China Geol., vol. 8, no. 4, pp. 691–706, Aug. 2025, doi: 10.31035/cg2023102.

[37] R. Blanquero, E. Carrizosa, P. Ramírez-Cobo, and M. R. Sillero-Denamiel, “Variable selection for Naïve Bayes classification,” Comput. Oper. Res., vol. 135, no. November, p. 105456, Nov. 2021, doi: 10.1016/j.cor.2021.105456.




Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

___________________________________________________________
International Journal of Advances in Intelligent Informatics
ISSN 2442-6571  (print) | 2548-3161 (online)
Organized by UAD and ASCEE Computer Society
Published by Universitas Ahmad Dahlan
W: http://ijain.org
E: info@ijain.org (paper handling issues)
 andri.pranolo.id@ieee.org (publication issues)

View IJAIN Stats

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0