EVALUATING AI-POWERED CYBER DEFENSE MECHANISMS AGAINST ZERO-DAY ATTACKS

Main Article Content

V.S.Balaji, Radhakrishnan Arikrishna Perumal, Dinesha H A, Vijayakumar Sangamesvarappa, Anupa Amol Pawar, Swathi Nelavalli

Abstract

The ability to identify known or unknown cyber threats is an urgent need that can only be addressed with adaptive cyber defense strategies. This study evaluates the use of AI-powered defense mechanisms based on the use of supervised machine learning and anomaly detection models within the UGRansome dataset, a large dataset of behavioral, transactional and network-level indicators associated with ransomware activity. The methodology combines Random Forest, Support Vector Machine and Naive Bayes classifiers with a zero-day simulation where ransomware families are withheld during the training process, and a model of Isolation Forest with data on only known ransomware families to detect deviations in the behavior of unknown ransomware attacks. Results show that Random Forest has a near perfect accuracy on known families (99.31%) and has high generalization under the zero-day environment (96.22%), and SVM has also a competitive performance, but Naive Bayes has serious limitations. The Isolation Forest detector further puts a separation between zero-day families with a much higher anomaly rate (+23.37%), which makes it a useful complementary behavioral layer. These findings underscore the power of hybrid architectures of artificial intelligence defence approaches that make use of both supervised classification and anomaly detection in order to build more resilience to evolving threats. The study ends with stressing the importance of conducting real-time evaluation, deep learning models, and adversarial robustness studies to further enhance AI-driven cyber security systems

Article Details

Section
Articles