Artificial Intelligence-Driven Cybersecurity Framework for Enterprise Threat Detection: A Machine Learning Approach
Sanjida Akter Tisha , Master of Science in Information Technology, Washington University of Science and Technology, USA Md Yassir Mottalib , Master of Science in Information System Technology, Wilmington University, USA Eklachur Rahman Bhuiyan , Master of Science in Information Technology, Washington University of Science and Technology, USA Asaduzzaman Anik , Master of Business Administration (MBA) in management, Stanton University, Los Angeles, California SM Wali Ullah , Department of Business Administration and Management, Stanton University, USA Marjahan Risalat , Department of Business Administration and Management, Stanton University, USA Shimita Lopa Chockroborty , Master’s in Accounting, National University, Dhaka, BangladeshAbstract
The increasing complexity of cyber threats has exposed the limitations of traditional signature-based intrusion detection systems, creating a need for intelligent and adaptive cybersecurity solutions. This study proposes an artificial intelligence-driven cybersecurity framework for enterprise threat detection using the CICIDS2017 benchmark dataset. The framework incorporates data preprocessing, feature engineering, and supervised machine learning to classify network traffic as benign or malicious. Seven machine learning algorithms, including Logistic Regression, Decision Tree, Support Vector Machine, Random Forest, Extra Trees, LightGBM, and XGBoost, were evaluated using accuracy, precision, recall, F1-score, and AUC-ROC. The results indicate that ensemble learning models outperform conventional classifiers, with XGBoost achieving the highest performance, recording 99.42% accuracy, 99.39% precision, 99.31% recall, 99.35% F1-score, and an AUC-ROC of 0.999. LightGBM also demonstrated excellent performance with lower computational time. The findings suggest that the proposed XGBoost-based framework provides an accurate, scalable, and efficient solution for real-time enterprise threat detection and can be effectively integrated into modern cybersecurity infrastructures to enhance organizational cyber resilience.
Keywords
Artificial Intelligence, Cybersecurity, Machine Learning, Enterprise Threat Detection, Intrusion Detection System, XGBoost.
References
Brynjolfsson, E., & Hitt, L. M. (2013). Beyond computation: Information technology, organizational transformation, and business performance. Journal of Economic Perspectives,14(4), 23–48.
Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153–1176. https://doi.org/10.1109/COMST.2015.2494502
Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 785–794. https://doi.org/10.1145/2939672.2939785
Cybersecurity and Infrastructure Security Agency. (2024). Cybersecurity overview. https://www.cisa.gov
IBM Security. (2024). Cost of a data breach report 2024. https://www.ibm.com/reports/data-breach
Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy, 108–116. https://doi.org/10.5220/0006639801080116
Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. 2010 IEEE Symposium on Security and Privacy, 305–316. https://doi.org/10.1109/SP.2010.25
Stallings, W. (2020). Network security essentials: Applications and standards (7th ed.). Pearson.
Aljawarneh, S., Aldwairi, M., & Yassein, M. B. (2018). Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model. Journal of Computational Science, 25, 152–160. https://doi.org/10.1016/j.jocs.2018.01.006
Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5–32. https://doi.org/10.1023/A:1010933404324
Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153–1176. https://doi.org/10.1109/COMST.2015.2494502
Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 785–794. https://doi.org/10.1145/2939672.2939785
Guyon, I., & Elisseeff, A. (2003). An introduction to variable and feature selection. Journal of Machine Learning Research, 3, 1157–1182.
Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the International Conference on Information Systems Security and Privacy, 108–116. https://doi.org/10.5220/0006639801080116
Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. 2010 IEEE Symposium on Security and Privacy, 305–316. https://doi.org/10.1109/SP.2010.25
Stallings, W. (2020). Network security essentials: Applications and standards (7th ed.). Pearson.
Tavallaee, M., Bagheri, E., Lu, W., & Ghorbani, A. A. (2009). A detailed analysis of the KDD Cup 99 dataset. Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, 1–6. https://doi.org/10.1109/CISDA.2009.5356528
Vinayakumar, R., Alazab, M., Soman, K. P., Poornachandran, P., Al-Nemrat, A., & Venkatraman, S. (2019). Deep learning approach for intelligent intrusion detection system. IEEE Access, 7, 41525–41550. https://doi.org/10.1109/ACCESS.2019.2895334
Mohammad Musa Mia, Molay Kumar Roy, I K M SAAMEEN YASSAR, Md Yassir Mottalib, Syed Yezdani, Alifa Majumder Nijhum, … Md Kafil Uddin. (2025). Integrating Blockchain Security and Machine Learning for Fraud Detection in the U.S. Banking System. The American Journal of Engineering and Technology, 7(11), 65–76. https://doi.org/10.37547/tajet/Volume07Issue11-08
Jamee, S. S., Arif, M., Rahman, M. M., YASSAR, I. S., & Hossain, M. A. (2025). Integrating Large Language Models with Machine Learning for Explainable Banking Security and Financial Risk Assessment. International Interdisciplinary Business Economics Advancement Journal, 6(11), 8-18.
Mottalib, M. Y., Nobe, N., Islam, M. T., Hossain, M. R., Jisan, A. H., & Hossen, M. E. (2026). Ensemble Machine Learning and Natural Language Processing for Automated Cancer Indicator Detection in Clinical Notes. Nvpubhouse Library for International Journal of Medical Science and Public Health Research, 7(03), 27-37.
Umam, S., & Razzak, R. B. (2024, October). Linguistic disparities in mental health services: Analyzing the impact of spanish language support availability in saint louis region, Missouri. In APHA 2024 Annual Meeting and Expo. APHA.
Umam, S., & Razzak, R. B. (2025, November). A 20-Year Overview of Trends in Secondhand Smoke Exposure Among Cardiovascular Disease Patients in the US: 1999–2020. In APHA 2025 Annual Meeting and Expo. APHA.
Download and View Statistics
Copyright License
Copyright (c) 2026 Sanjida Akter Tisha, Md Yassir Mottalib, Eklachur Rahman Bhuiyan, Asaduzzaman Anik, SM Wali Ullah, Marjahan Risalat, Shimita Lopa Chockroborty

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors retain the copyright of their manuscripts, and all Open Access articles are disseminated under the terms of the Creative Commons Attribution License 4.0 (CC-BY), which licenses unrestricted use, distribution, and reproduction in any medium, provided that the original work is appropriately cited. The use of general descriptive names, trade names, trademarks, and so forth in this publication, even if not specifically identified, does not imply that these names are not protected by the relevant laws and regulations.

Engineering and Technology
| Open Access |
DOI: