Skip to content
Open access

Cybersecurity Threat Detection in IT Infrastructure Using an XGBoost-Based Model

Aug 2026 · Journal of Computer Science Application and Engineering (JOSAPEN) · 0 citations · 17 references

TL;DR

The potential of XGBoost as an accurate and explainable approach for cybersecurity threat detection in IT infrastructure is demonstrated and the model outperformed Logistic Regression, Decision Tree, Random Forest, and SVM.

Abstract

The increasing complexity of IT infrastructure has created significant challenges in detecting cybersecurity threats, particularly malicious network activities that can evade conventional security mechanisms. This study proposes an XGBoost-based machine learning model for detecting cybersecurity threats in network traffic. A controlled cybersecurity simulation environment was used to generate 50,000 network-flow observations representing benign activities, including web browsing, DNS requests, file transfer, and client-server communication, as well as malicious activities involving DoS, DDoS, port scanning, and brute-force attacks. After preprocessing, 48,000 observations were retained and divided into 80% training and 20% testing datasets using stratified sampling. XGBoost feature importance and randomized hyperparameter optimization with five-fold cross-validation were applied to improve model performance. The optimized XGBoost model achieved 98.30% accuracy, 98.10% precision, 97.90% recall, 98.00% F1-score, and 99.20% ROC-AUC, with a reported false-positive rate of 1.20%. XGBoost also outperformed Logistic Regression, Decision Tree, Random Forest, and SVM. SHAP analysis identified Flow Packets/s, Flow Bytes/s, Flow Duration, and packet-related characteristics as influential features. These findings demonstrate the potential of XGBoost as an accurate and explainable approach for cybersecurity threat detection in IT infrastructure.

Read PDF

Similar papers

Conference Aug 2026

Advanced Cybersecurity in IIoT: A Machine Learning Perspective on Attack Detection

While integrating the Industrial Internet of Things (IIoT) into smart factories massively boosts efficiency, it also opens the door to severe cyberattacks, such as malware and denial-of-service, that can actually disable physical machinery. To protect these vulnerable systems, researchers developed an edge computing-ba...

Firoz Ahmed Mansuri, Anita Seth · 0 citations
Conference Aug 2026

SecureEnsembleNet: Intelligent Cyber Threat Detection with Ensemble Learning

The rapid growth of network-connected systems has made cyber threat detection a critical priority for modern infrastructures. Traditional signature-based intrusion detection systems (IDSs) struggle to detect novel and evolving attacks, creating the need for intelligent learning-based approaches. This paper presents Sec...

Buddha Dev Sarker, Md Fahim Ahammed, Md Rasheduzzaman Labu et al. · 0 citations
Open access Sep 2026

Machine Learning-Based Domain Risk Assessment for Cybersecurity Monitoring in Industrial Systems

In the field of cybersecurity, malicious website classification plays a crucial role in protecting industrial systems. For this reason, research has been undertaken to analyze cybersecurity threats, with the long-term objective of developing methods for the effective detection and classification of malicious websites....

J. Wilk-Jakubowski, Aleksandra Sikora, J. Zapała · 0 citations
Open access 2026

AI-DRIVEN THREAT DETECTION USING DATA SCIENCE: A COMPARATIVE STUDY OF MACHINE LEARNING MODELS ON CYBERSECURITY DATASETS

They originate from the rapid rise of cyber threats such as malware, phishing, ransomware, denial of service, and unauthorised network intrusion, which have proven to be so difficult to tackle that traditional security measures can hardly deal with the issue. Signature-based intrusion detection system techniques in par...

Praveen Kumar Reddy Gouni · 0 citations
Open access Aug 2026

Predictive Models for Cybersecurity in Smart Cities Network Using NSL-KDD Dataset

Smart Cities increasingly rely on interconnected digital infrastructures and Internet of Things (IoT) systems, which expand the attack surface and create new cybersecurity challenges. Traditional intrusion detection systems (IDS) based on signatures and rules are limited in scalability and adaptability against zero-day...

Tonatiuh Guadalupe, Nava-Razon, Francisco Salcedo-Arancibia et al. · 0 citations
Aug 2026

AI-Based Cybersecurity Threat Detection Using Machine Learning

A multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time is introduced.

Ameen Pasha.A · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.