Machine Learning-Based Prediction of Cybersecurity Vulnerability Severity for Enterprise Security Management

Open Access
Article
Conference Proceedings
Authors: Adnan AgbariaIyad Suleiman
Abstract

Cybersecurity vulnerabilities represent a growing challenge for modern information systems, particularly in large-scale cloud and enterprise environments where organizations must process a high volume of vulnerability disclosures under strict time constraints. Effective prioritization of security updates is essential for minimizing operational risk and improving resource allocation within Security Operations Centers (SOCs). However, traditional vulnerability severity assessment methods, such as the Common Vulnerability Scoring System (CVSS), rely heavily on manual analysis and expert judgment, limiting scalability in dynamic environments. This paper presents a machine learning–based framework for predicting the severity of cybersecurity vulnerabilities using structured data derived from Microsoft Security Bulletins. The dataset spans more than 15 years (2001–2017) and contains over 23,000 vulnerability records characterized by attributes such as impact type, affected product, affected component, and associated CVE identifiers. The prediction task is formulated as a multi-class classification problem with four severity levels: Critical, Important, Moderate, and Low. Several supervised learning models, including Logistic Regression, Decision Trees, Random Forest, and Gradient Boosting, are evaluated using macro-averaged precision, recall, and F1-score. Experimental results demonstrate that ensemble learning methods significantly outperform baseline classifiers. In particular, the Gradient Boosting model achieves the best performance, with a macro-F1 score of 0.982 and an overall accuracy of 99.0%. The findings demonstrate the effectiveness of machine learning techniques for automated vulnerability prioritization and highlight their practical applicability in enterprise cybersecurity management and SOC environments.

Keywords: Machine Learning, Cyber Security, Vulnerability, Enterprise Security Management

DOI: 10.54941/ahfe1008122

Cite this paper
Downloads
0
Visits
3
Download PDF

More from this volume

Human Factors Challenges in Future Remote Operations for Electrified Short-Sea Ro-Ro FerriesCognitive training for adults with developmental deficits led by a socially intelligent robot
View all articles in Human Interaction and Emerging Technologies (IHIET 2026)