Skip to content
Open access

A Dual-Module Machine Learning Framework for Vulnerability Assessment of Government Payment Gateways: Static Prioritisation and Runtime Detection

Sep 2026 · East African Journal of Information Technology · 0 citations

TL;DR

A dual-module machine learning framework that unifies static prioritisation of disclosed vulnerabilities with runtime detection of malicious traffic is presented, contributing the first data-driven, reproducible vulnerability-assessment model developed specifically for the Tanzanian Government Electronic Payment Gateway (GePG) context.

Abstract

Government electronic payment gateways concentrate public revenue and citizen data, making them high-value targets whose compromise carries national-security consequences. Yet vulnerability assessment in many public institutions remains manual, severity-driven, and unable to scale against both the growing volume of disclosed weaknesses and the continuous stream of live attack traffic. To address both vulnerability surfaces within a single coherent assessment layer, this paper presents a dual-module machine learning framework that unifies static prioritisation of disclosed vulnerabilities with runtime detection of malicious traffic. Methodologically, the static module prioritises disclosed vulnerabilities by pairing Term Frequency–Inverse Document Frequency (TF-IDF) text representation with Bayesian-optimised XGBoost multi-class classification over a corpus of 386,337 records, built by expanding National Vulnerability Database (NVD) records across their affected libraries using Open Source Vulnerabilities (OSV) data; the runtime module detects malicious HTTP requests using twelve engineered request features and Bayesian-optimised XGBoost binary classification on the CSIC 2010 dataset of 61,065 requests. On the key results, the static module attains a test accuracy of 0.8630, a macro-averaged F1-score of 0.8475, and High-tier recall of 0.9356; the runtime module attains an accuracy of 0.9101, an F1-score of 0.8879, and a ROC-AUC of 0.9796, raising attack recall from 0.087 under a rule-based signature baseline to 0.868. These results demonstrate that interpretable, low-cost learning models can strengthen vulnerability assessment for government payment infrastructure in resource-constrained settings, contributing the first data-driven, reproducible vulnerability-assessment model developed specifically for the Tanzanian Government Electronic Payment Gateway (GePG) context. As principal limitations, we identify the proxy-label limitation, on which the static module is trained against library-exposure breadth rather than a severity or exploitation measure, and the need for institution-specific validation on live GePG traffic, which together define the principal paths for refinement.

Read PDF

Similar papers

Open access 2026

Machine Learning-Based Prediction of Cybersecurity Vulnerability Severity for Enterprise Security Management

A machine learning–based framework for predicting the severity of cybersecurity vulnerabilities using structured data derived from Microsoft Security Bulletins is presented, demonstrating the effectiveness of machine learning techniques for automated vulnerability prioritization and highlighting their practical applica...

Adnan Agbaria, Iyad Suleiman · 0 citations
Open access Sep 2026

Comparative evaluation of active learning, random sampling, and deep learning for smart contract vulnerability detection

Findings indicate that ensemble-based classifiers (Random Forest, CatBoost) are better suited to this structured smart contract feature representation than the evaluated deep learning baselines.

G. A. Sampedro, Yan-Hui Cheng, Arlene R. Caballero et al. · 0 citations
Open access Sep 2026

A Feature-Based Machine Learning Ensemble Model for Enhanced Malware Detection in Digital Banking Security

The rapid expansion of digital banking has introduced significant cybersecurity vulnerabilities, particularly from sophisticated malware threats that exploit polymorphic and zero-day evasion techniques. Traditional signature-based defenses demonstrate critical inadequacy in detecting novel threats, creating exploita...

Jennifer Ibimina Princewill · 0 citations
Open access Aug 2026

Tri-Level Network Attack Risk Stratification Using IDS-Contextual Ensemble Learning

An Intrusion Detection System (IDS)-contextual ensemble learning framework that assigns network traffic to three operationally meaningful risk tiers: High, Medium and Low is presented.

Reeta Mishra, Neelu Chaudhary · 0 citations
Open access Aug 2026

Application of C4.5 Decision Tree Algorithm for Detecting Cyber Attacks Using IDS

This work constructs a web-based Intrusion Detection System prototype by training an entropy-based Decision Tree classifier, conceptually grounded in the C4.5 framework, on the NSL-KDD benchmark.

Daniel Erick Witopo, Hartana Wijaya · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.