2026· Direct Research Journal of Engineering and Information Technology· 0 citations
TL;DR
The findings demonstrate that integrating reinforcement learning with threat intelligence can provide a highly adaptive and proactive cyber defense mechanism suitable for modern network environments.
Abstract
The increasing sophistication, frequency, and scale of cyberattacks have created significant challenges for conventional cybersecurity systems. Traditional security solutions such as firewalls, signature-based intrusion detection systems, and antivirus software are largely reactive and depend on predefined rules and known attack patterns. Consequently, these systems often struggle to detect and respond effectively to emerging threats such as Advanced Persistent Threats (APTs), zero-day attacks, ransomware, botnets, and insider attacks. Recent advancements in Artificial Intelligence (AI), particularly Reinforcement Learning (RL), have demonstrated the potential to create autonomous systems capable of learning and adapting to dynamic environments. Simultaneously, Cyber Threat Intelligence (CTI) provides valuable contextual information regarding threat actors, attack techniques, vulnerabilities, and indicators of compromise. This study proposes an Autonomous Cyber Defense Framework that integrates Reinforcement Learning and Threat Intelligence to enhance threat detection, decision-making, and automated response capabilities. The framework employs a Deep Q-Network (DQN) agent that continuously learns optimal defense actions through interaction with network environments while utilizing threat intelligence feeds to improve situational awareness. Experimental evaluation was conducted using benchmark cybersecurity datasets, including CICIDS2017 for Intrusion Detection, UNSW-NB15 for attack classification, CTU-13 for botnet detection and Custom Threat Feeds for threat intelligence. The results indicate that the proposed framework achieved a precision rate of 98.4%, a recall rate of 98.2%, an F1-score of 98.3%, and a threat mitigation rate of 96.8%. False positive rate of 1.9, False negative rate of 1.5 and Response rate of 41%, significantly outperforming traditional machine learning and signature-based security approaches. The findings demonstrate that integrating reinforcement learning with threat intelligence can provide a highly adaptive and proactive cyber defense mechanism suitable for modern network environments.
Traditional cybersecurity technologies have difficulty adapting to the increasing sophistication and numbers of cyberattacks. Typically, traditional technologies use manual interventions and static rules to defend against cyberattacks; therefore, they are limited in their ability to adapt and respond quickly to changin...
Manik Rakhra, T. Sarkar, Renupal Sood et al.· International Conference Inn...· 0 citations
Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat inte...
Nicolas Guzman Camacho· Journal of Artificial Intell...· 0 citations
Modern cyber threats evolve faster than static, signature-driven defenses can respond, creating a need for security architectures that can continuously observe, interpret, predict, and adapt to changing attack behavior. This talk presents an adaptive AI-driven cybersecurity approach that combines real-time security tel...
Kalyana Krishna Kondapalli· Proceedings of International...· 0 citations
XAI-CTI is presented, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection that achieves state-of-the-art detection accuracy and reduces analyst investigation time.
R. Yadav· Journal of Intelligent Decis...· 0 citations
A conceptual framework is proposed that combines detection, explanation, and orchestrated response in a continuous feedback loop that is suitable for zero trust and IoT-enabled critical-infrastructure environments that will allow for continuous retraining of the model.
Jayesh Dalmet· Journal of Digital Security...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.