错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Intelligent Automation of Security Policy Decisions Using AI: Analysis of ML and DL Approach

  • Samir N. Ajani,
  • Samit Shivadekar,
  • Vaidehi Pareek,
  • Ira Joshi,
  • Dattatraya Babanrao Nalawade,
  • Chandrakant D. Kokane

摘要

In today's cybersecurity environment, the increasing complexity of security policy choices has led to the investigation of advanced technologies to strengthen organizational defenses. This study explores the smart automation of security policy decisions through a thorough examination of machine learning (ML) and deep learning (DL) methods. The introduction discusses the challenges presented by the constantly changing cyberthreats and emphasizes the necessity for creative solutions to improve security policy decision-making. The work offers insights into various methodologies, datasets, and algorithms used in designing and optimizing intrusion detection systems (IDS) for security policy decisions with the use of artificial intelligence (AI). This sets the groundwork for comprehending the historical development of security policy choices and the incorporation of AI in cybersecurity. The study provides a detailed comparison of machine learning (ML) and deep learning (DL) methods such as random forest, isolation forest, XGBoost, convolutional neural network (CNN), and long short-term memory (LSTM) models, focusing on important performance metrics. XGBoost is the best-performing model, demonstrating high accuracy, precision, recall, and F1 score. Every method is assessed based on its predictive abilities as well as its explainability, data sensitivity, anomaly detection, and threat classification. The study concludes that XGBoost has the potential for real-time decision-making in security policy automation, stressing the importance of understanding the trade-offs between accuracy and interpretability. The abstract ends by proposing future research directions, including improving model interpretability, investigating hybrid methods, dealing with scalability issues, and adjusting to the changing threat environment.