Skip to content
Open access

Machine Learning-Based Prediction of Cybersecurity Vulnerability Severity for Enterprise Security Management

2026 · AHFE International · Vol 236 · 0 citations

TL;DR

A machine learning–based framework for predicting the severity of cybersecurity vulnerabilities using structured data derived from Microsoft Security Bulletins is presented, demonstrating the effectiveness of machine learning techniques for automated vulnerability prioritization and highlighting their practical applicability in enterprise cybersecurity management and SOC environments.

Abstract

Cybersecurity vulnerabilities represent a growing challenge for modern information systems, particularly in large-scale cloud and enterprise environments where organizations must process a high volume of vulnerability disclosures under strict time constraints. Effective prioritization of security updates is essential for minimizing operational risk and improving resource allocation within Security Operations Centers (SOCs). However, traditional vulnerability severity assessment methods, such as the Common Vulnerability Scoring System (CVSS), rely heavily on manual analysis and expert judgment, limiting scalability in dynamic environments. This paper presents a machine learning–based framework for predicting the severity of cybersecurity vulnerabilities using structured data derived from Microsoft Security Bulletins. The dataset spans more than 15 years (2001–2017) and contains over 23,000 vulnerability records characterized by attributes such as impact type, affected product, affected component, and associated CVE identifiers. The prediction task is formulated as a multi-class classification problem with four severity levels: Critical, Important, Moderate, and Low. Several supervised learning models, including Logistic Regression, Decision Trees, Random Forest, and Gradient Boosting, are evaluated using macro-averaged precision, recall, and F1-score. Experimental results demonstrate that ensemble learning methods significantly outperform baseline classifiers. In particular, the Gradient Boosting model achieves the best performance, with a macro-F1 score of 0.982 and an overall accuracy of 99.0%. The findings demonstrate the effectiveness of machine learning techniques for automated vulnerability prioritization and highlight their practical applicability in enterprise cybersecurity management and SOC environments.

Read PDF

Similar papers

Open access Sep 2026

Machine Learning-Based Domain Risk Assessment for Cybersecurity Monitoring in Industrial Systems

In the field of cybersecurity, malicious website classification plays a crucial role in protecting industrial systems. For this reason, research has been undertaken to analyze cybersecurity threats, with the long-term objective of developing methods for the effective detection and classification of malicious websites....

J. Wilk-Jakubowski, Aleksandra Sikora, J. Zapała · 0 citations
Open access Sep 2026

HYBRID INTELLIGENT DECISION-SUPPORT SYSTEM FOR CYBERSECURITY RISK ASSESSMENT AND SECURITY ACTION SELECTION

Selecting appropriate information security systems is a complex task influenced by organizational risks, infrastructure characteristics, evolving cyber threats, and regulatory requirements. Traditional approaches based on manual analysis and expert judgment often lack adaptability, scalability, and consistency in dynam...

A. Amirbayeva · 0 citations
Conference Aug 2026

Active Learning-Based Smart Contract Vulnerability Detection Using Ensemble Classifiers

Smart contract vulnerabilities continue to threaten the security and reliability of blockchain-based applications, especially as blockchain systems are increasingly integrated into digital finance, supply chains, identity management, and other intelligent service environments. In these convergent digital systems, depen...

G. A. Sampedro, Arlene R. Caballero · 0 citations
Open access Sep 2026

A Dual-Module Machine Learning Framework for Vulnerability Assessment of Government Payment Gateways: Static Prioritisation and Runtime Detection

A dual-module machine learning framework that unifies static prioritisation of disclosed vulnerabilities with runtime detection of malicious traffic is presented, contributing the first data-driven, reproducible vulnerability-assessment model developed specifically for the Tanzanian Government Electronic Payment Gatewa...

Maneno Sudayi, S. Wambura, G. Tesha et al. · 0 citations
Open access 2026

Adaptive threat intelligence models for protecting educational cloud infrastructures

The quick transfer of academic processes to cloud-based systems has increased the cyber-attack area of academic institutions significantly by introducing systemic weaknesses into the learning management systems (LMS), enterprise resource planning (ERP) tools, as well as databases housing student data. Traditional secur...

S. Ramesh, Viswa Bharath Kolla, R. Amte et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.