| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Machine learning-based detection of complex cyberattacks
Authors:ID Hölbl, Marko (Author)
ID Rotovnik, Maja (Author)
Files:.pdf s10586-026-06367-4.pdf (2,27 MB)
MD5: 3A35B635C8C2C3D34FDD7726A1993F31
 
URL https://link.springer.com/article/10.1007/s10586-026-06367-4?utm_source=rct_congratemailt&utm_medium=email&utm_campaign=oa_20260723&utm_content=10.1007/s10586-026-06367-4
 
Language:English
Work type:Article
Typology:1.01 - Original Scientific Article
Organization:FERI - Faculty of Electrical Engineering and Computer Science
Abstract:With the increasing complexity of modern cyberattacks, such as advanced persistent threats, reconnaissance, and stegan ography, traditional rule-based and signature-based detection methods are becoming less effective. Machine learning (ML) provides advanced capabilities for identifying sophisticated and stealthy attacks by efficiently processing large volumes of data and uncovering hidden patterns. This paper presents a systematic review of existing approaches to complex cyberat tack detection based on machine learning techniques, encompassing an analysis of 68 research articles. The review evalu ates the performance of individual algorithms compared to ensemble approaches, examines commonly used ML methods, and analyzes datasets used in experimental studies. The results show that ensemble models generally outperform indi vidual classifiers, with detection accuracy improvements ranging from 0.4 % to 28.52 %. Machine learning methods such as XGBoost, Random Forest, and LightGBM are identified as particularly effective across various attack types. Supervised learning remains dominant, though interest in unsupervised and semi-supervised methods is increasing to address novel threats. Frequently used datasets include NSL-KDD, UNSW-NB15, and newer APT-focused datasets such as DAPT2020 and SCVIC-APT-2021. The findings confirm the strong potential of ML for adaptive and proactive cybersecurity systems.
Keywords:complex cyberattacks, machine learning, ensemble methods, advanced persistent threats, reconnaissance, steganography
Publication status:Published
Publication version:Version of Record
Submitted for review:26.02.2026
Article acceptance date:03.07.2026
Publication date:23.07.2026
Publisher:Springer Nature
Year of publishing:2026
Number of pages:23 str.
Numbering:Vol. 29, [article no.] 551
PID:20.500.12556/DKUM-99001 New window
UDC:004.85:004.056.5
ISSN on article:1573-7543
COBISS.SI-ID:285910275 New window
DOI:10.1007/s10586-026-06367-4 New window
Publication date in DKUM:24.07.2026
Views:235
Downloads:14
Metadata:XML DC-XML DC-RDF
Categories:Misc.
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Record is a part of a journal

Title:Cluster computing
Shortened title:Cluster comput.
Publisher:Kluwer
ISSN:1573-7543
COBISS.SI-ID:513137689 New window

Document is financed by a project

Funder:ARIS - Slovenian Research and Innovation Agency
Project number:P2-0057-2018
Name:Informacijski sistemi

Licences

License:CC BY 4.0, Creative Commons Attribution 4.0 International
Link:http://creativecommons.org/licenses/by/4.0/
Description:This is the standard Creative Commons license that gives others maximum freedom to do what they want with the work as long as they credit the author.

Secondary language

Language:Slovenian
Keywords:kibernetska varnost, kibernetski napadi, strojno učenje, napredne trajne grožnje, izvidništvo


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica