Cybersecurity Threat Detection in IT Infrastructure Using an XGBoost-Based Model

Authors

  • Temitayo Afolen Department of AI and Machine Learning, Nuvakora Technologies Ltd.
  • Amariel Nkemdilim Department of AI and Machine Learning, Nuvakora Technologies Ltd.

DOI:

https://doi.org/10.70356/josapen.v4i2.136

Keywords:

Cybersecurity, Threat Detection, XGBoost, Machine Learning

Abstract

The increasing complexity of IT infrastructure has created significant challenges in detecting cybersecurity threats, particularly malicious network activities that can evade conventional security mechanisms. This study proposes an XGBoost-based machine learning model for detecting cybersecurity threats in network traffic. A controlled cybersecurity simulation environment was used to generate 50,000 network-flow observations representing benign activities, including web browsing, DNS requests, file transfer, and client-server communication, as well as malicious activities involving DoS, DDoS, port scanning, and brute-force attacks. After preprocessing, 48,000 observations were retained and divided into 80% training and 20% testing datasets using stratified sampling. XGBoost feature importance and randomized hyperparameter optimization with five-fold cross-validation were applied to improve model performance. The optimized XGBoost model achieved 98.30% accuracy, 98.10% precision, 97.90% recall, 98.00% F1-score, and 99.20% ROC-AUC, with a reported false-positive rate of 1.20%. XGBoost also outperformed Logistic Regression, Decision Tree, Random Forest, and SVM. SHAP analysis identified Flow Packets/s, Flow Bytes/s, Flow Duration, and packet-related characteristics as influential features. These findings demonstrate the potential of XGBoost as an accurate and explainable approach for cybersecurity threat detection in IT infrastructure.

Downloads

Download data is not yet available.

References

R. Sommer and V. Paxson, “Outside the closed world: On using machine learning for network intrusion detection,” in Proc. IEEE Symp. Security and Privacy, Berkeley/Oakland, CA, USA, 2010, pp. 305–316, doi: https://doi.org/10.1109/SP.2010.25.

Z. Chiba, N. Abghour, K. Moussaid, A. El Omri, and M. Rida, “A survey of intrusion detection systems: Techniques, datasets and challenges,” Cybersecurity, vol. 2, no. 1, 2019, Art. no. 20, doi: https://doi.org/10.1186/s42400-019-0038-7.

A. L. Buczak and E. Guven, “A survey of data mining and machine learning methods for cyber security intrusion detection,” IEEE Commun. Surveys Tuts., vol. 18, no. 2, pp. 1153–1176, 2016, doi: https://doi.org/10.1109/COMST.2015.2494502.

A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, “Survey of intrusion detection systems: Techniques, datasets and challenges,” Cybersecurity, vol. 2, no. 1, pp. 1–22, 2019, doi: https://doi.org/10.1186/s42400-019-0038-7.

R. Sommer and V. Paxson, “Outside the closed world: On using machine learning for network intrusion detection,” in Proc. IEEE Symp. Security and Privacy, 2010, pp. 305–316, doi: https://doi.org/10.1109/SP.2010.25.

A. L. Buczak and E. Guven, “A survey of data mining and machine learning methods for cyber security intrusion detection,” IEEE Commun. Surveys Tuts., vol. 18, no. 2, pp. 1153–1176, 2016, doi: https://doi.org/10.1109/COMST.2015.2494502.

N. Shone, T. N. Ngoc, V. D. Phai, and Q. Shi, “A deep learning approach to network intrusion detection,” IEEE Trans. Emerg. Topics Comput. Intell., vol. 2, no. 1, pp. 41–50, 2018, doi: https://doi.org/10.1109/TETCI.2017.2772792.

N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set),” in Proc. Mil. Commun. Inf. Syst. Conf. (MilCIS), Canberra, ACT, Australia, 2015, pp. 1–6, doi: https://doi.org/10.1109/MilCIS.2015.7348942.

I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” in Proc. 4th Int. Conf. Inf. Syst. Security Privacy (ICISSP), Funchal, Portugal, 2018, pp. 108–116, doi: https://doi.org/10.5220/0006639801080116.

A. Shiravi, H. Shiravi, M. Tavallaee, and A. A. Ghorbani, “Toward developing a systematic approach to generate benchmark datasets for intrusion detection,” Comput. Security, vol. 31, no. 3, pp. 357–374, 2012, doi: https://doi.org/10.1016/j.cose.2011.12.012.

T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proc. 22nd ACM SIGKDD Int. Conf. Knowledge Discovery Data Mining, San Francisco, CA, USA, 2016, pp. 785–794, doi: https://doi.org/10.1145/2939672.2939785.

L. Breiman, “Random forests,” Mach. Learn., vol. 45, no. 1, pp. 5–32, 2001, doi: https://doi.org/10.1023/A:1010933404324.

C. Cortes and V. Vapnik, “Support-vector networks,” Mach. Learn., vol. 20, pp. 273–297, 1995, doi: https://doi.org/10.1007/BF00994018.

T. Fawcett, “An introduction to ROC analysis,” Pattern Recognit. Lett., vol. 27, no. 8, pp. 861–874, 2006, doi: https://doi.org/10.1016/j.patrec.2005.10.010.

H. He and E. A. Garcia, “Learning from imbalanced data,” IEEE Trans. Knowl. Data Eng., vol. 21, no. 9, pp. 1263–1284, 2009, doi: https://doi.org/10.1109/TKDE.2008.239.

I. Guyon, J. Weston, S. Barnhill, and V. Vapnik, “Gene selection for cancer classification using support vector machines,” Mach. Learn., vol. 46, pp. 389–422, 2002, doi: https://doi.org/10.1023/A:1012487302797.

R. Kohavi, “A study of cross-validation and bootstrap for accuracy estimation and model selection,” in Proc. 14th Int. Joint Conf. Artif. Intell. (IJCAI), Montreal, QC, Canada, 1995, pp. 1137–1145.

J. Bergstra and Y. Bengio, “Random search for hyper-parameter optimization,” J. Mach. Learn. Res., vol. 13, pp. 281–305, 2012.

S. M. Lundberg and S.-I. Lee, “A unified approach to interpreting model predictions,” in Adv. Neural Inf. Process. Syst. (NeurIPS), vol. 30, 2017, pp. 4765–4774.

H. A. Alatwi and C. Morisset, “Adversarial machine learning in network intrusion detection domain: A systematic review,” arXiv preprint arXiv:2112.03315, 2021.

Published

2026-08-29

How to Cite

Afolen, T., & Nkemdilim, A. (2026). Cybersecurity Threat Detection in IT Infrastructure Using an XGBoost-Based Model. Journal of Computer Science Application and Engineering (JOSAPEN), 4(2), 50–57. https://doi.org/10.70356/josapen.v4i2.136

Similar Articles

1 2 > >> 

You may also start an advanced similarity search for this article.