Machine Learning-Based Prediction of Cybersecurity Vulnerability Severity for Enterprise Security Management
Abstract
Cybersecurity vulnerabilities represent a growing challenge for modern information systems, particularly in large-scale cloud and enterprise environments where organizations must process a high volume of vulnerability disclosures under strict time constraints. Effective prioritization of security updates is essential for minimizing operational risk and improving resource allocation within Security Operations Centers (SOCs). However, traditional vulnerability severity assessment methods, such as the Common Vulnerability Scoring System (CVSS), rely heavily on manual analysis and expert judgment, limiting scalability in dynamic environments. This paper presents a machine learning–based framework for predicting the severity of cybersecurity vulnerabilities using structured data derived from Microsoft Security Bulletins. The dataset spans more than 15 years (2001–2017) and contains over 23,000 vulnerability records characterized by attributes such as impact type, affected product, affected component, and associated CVE identifiers. The prediction task is formulated as a multi-class classification problem with four severity levels: Critical, Important, Moderate, and Low. Several supervised learning models, including Logistic Regression, Decision Trees, Random Forest, and Gradient Boosting, are evaluated using macro-averaged precision, recall, and F1-score. Experimental results demonstrate that ensemble learning methods significantly outperform baseline classifiers. In particular, the Gradient Boosting model achieves the best performance, with a macro-F1 score of 0.982 and an overall accuracy of 99.0%. The findings demonstrate the effectiveness of machine learning techniques for automated vulnerability prioritization and highlight their practical applicability in enterprise cybersecurity management and SOC environments.
Keywords: Machine Learning, Cyber Security, Vulnerability, Enterprise Security Management
DOI: 10.54941/ahfe1008122
Cite this paper
More from this volume
- Explainability in Automated Driving: From Spatial Attention to Human-Centred Reasoning
- Design and Evaluation of an AI Academic Advisor: Insights from Student Interactions
- To boldly go where AI must not go alone: Designing for non-delegable human authority in AI-assisted expert work
- Integrating Three Modalities into One Experience: A Case Study of 2024 DigiWave—DdDd
- Improving Usability in a Smart Building Ecosystem through Heuristic Evaluation and Usability Testing
- Anchored in the Learner: A Critical Review of AI Discourse in Design Education
- Narrative as a Cognitive Scaffold for Human-Centered Design Education:A Case Study of Schema Change in Interaction Design Students
- Assessment-Before-Intervention: A WHO iSupport-Grounded Conversational AI System for Dementia Family Caregiver Support
- Analyzing Stress and Perceived Safety in Human-Cobot Collaboration: The Impact of Task Proximity, Interface Cues, and System Errors
- Metascience of content-based cognitive ergonomics
- Developing an Assistive Mobile Application for Elderly Nepali Migrants in the UK
- Integrated Home Service Robots for Ageing in Place: A Multi-Stakeholder Perspective on Acceptance and Care Needs in Taiwan


AHFE Open Access