[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119483-en":3,"doc-seo-119483-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119483,962075114765,"Quinn","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Comparative Analysis of Machine Learning Models to Predict Common Vulnerabilities and Exposure","Predicting Common Vulnerabilities and Exposures (CVE) is a difficult task driven by cyberattacks’ growing complexity and the scale of available threat data. Accurate prediction models support faster security response and stronger proactive vulnerability management. This study compares supervised and unsupervised machine learning approaches for CVE prediction, using Gaussian Naive Bayes alongside clustering methods (K-means and DBSCAN). Performance is evaluated with accuracy, precision, recall, and F1-score, where Gaussian Naive Bayes achieves 99.79% accuracy and outperforms clustering models in class label effectiveness.","*For correspondence:  \n[noraziahadzhar@umpsa.edu](noraziahadzhar@umpsa.edu).my  \nReceived: 27 Aug. 2024  \nAccepted: 04 Nov. 2024  \n© Copyright Sheh Rahman. This article is distributed under the terms of the  \nCreative Commons Attribution License, which permits unrestricted use and redistribution provided that the original author and source are credited.  \nRESEARCH ARTICLE  \nComparative Analysis of Machine Learning Models to Predict Common Vulnerabilities and Exposure  \nShaesta Khan Sheh Rahmana, Noraziah Adzhara* , Nazri Ahmad Zamanib  \naCentre for Mathematical Sciences, Universiti Malaysia Pahang Al-Sultan Abdullah, Lebuh Persiaran Tun Khalil Yaakob, 26300 Kuantan, Pahang, Malaysia; bCyber Threat Intelligence Department , Cybersecurity Malaysia, Menara Cyber Axis, Jalan Impact, 63000 Cyberjaya , Selangor, Malaysia  \nAbstract Predicting Common Vulnerabilities and Exposures (CVE) is a challenging task due to the increasing complexity of cyberattacks and the vast amount of threat data available. Effective prediction models are crucial for enabling cybersecurity teams to respond quickly and prevent potential exploits. This study aims to provide a comparative analysis of machine learning techniques for CVE prediction to enhance proactive vulnerability management and strengthening cybersecurity practices. The supervised machine learning model which is Gaussian Naive Bayes and unsupervised machine learning models that utilize clustering algorithms which are K-means and DBSCAN were employed for the predictive modelling. The performance of these models was compared using performance metrics such as accuracy, precision, recall, and F1-score. Among these models, the Gaussian Naive Bayes achieved an accuracy rate of 99.79%, and outperformed the clustering-based machine learning models in effectively determining the class labels or results of the data it was trained on or tested against. The outcome of this study will provide a proof of concept to Cybersecurity Malaysia, offering insights into the CVE model.  \nKeywords: Cyber threat, common vulnerabilities and exposures , unsupervised and supervised machine learning models, accuracy.  \nIntroduction  \nCyber threats are sporadic and not limited to governments but also companies and individuals [1,2] . Growing threats have been identified in emerging technologies such as social media, cloud computing, web applications, and smartphone technologies [3,4] . The rise of cyber threat incidents highlights the urgent need for vulnerability management and effective mitigation strategies. Vulnerabilities are weaknesses that attackers exploit to access and conduct illegitimate activities unlawfully [5] . This includes executing code, installing various types of malwares [6], acquire, modify, or even destroy sensitive data. The most recent threat landscape demonstrates how tough it is to stop an incident since attackers can aim weaknesses in people, procedures, and technology [7] . This is due to advancementsin hackers' strategies and tactics, which have become increasingly difficult to detect, investigate and resolve. In [7] it also said that the organized crime groups that use ransomware to encrypt vital data and systems have an impact on a lot of businesses.  \nIn cybersecurity, the Common Vulnerabilities and Exposures (CVE) initiative by MITRE Corporation [8], initiated in 1999, provides a framework for detecting and classifying vulnerabilities. The Common Weakness Enumeration (CWE) system further assists by identifying, categorizing, and explaining common software problems, acting as a tool for addressing flaws. As the field of cybersecurity continues to advance, so does the severity of cyber threats. Attackers employ increasingly sophisticated methods to compromise systems, escalating the stakes. The prevailing reactive approach to cyberattack response, which addresses threats only after systems have been breached, is no longer sufficient. Detecting concealed threats in vast, complex environments ","cbCaidofCzsZfQ4s","https://ap.wps.com/l/cbCaidofCzsZfQ4s","pdf",711537,1,10,"English","en",105,"# Introduction\n## CVE/CWE background and motivation\n## Machine learning in cybersecurity\n# Methodology and model comparison\n## Supervised learning: Gaussian Naive Bayes\n## Unsupervised learning: K-means and DBSCAN\n# Evaluation and results\n## Metrics and performance comparison\n# Conclusion","[{\"question\":\"Why is predicting Common Vulnerabilities and Exposures (CVE) challenging?\",\"answer\":\"CVE prediction is difficult because cyberattacks are becoming more complex and threat intelligence data is large and varied. This increases the difficulty of extracting reliable patterns for forecasting vulnerabilities.\"},{\"question\":\"Which machine learning models are used for CVE prediction in this study?\",\"answer\":\"The study uses Gaussian Naive Bayes as the supervised model and K-means and DBSCAN as unsupervised clustering-based models. These approaches are compared to assess predictive effectiveness.\"},{\"question\":\"How is model performance evaluated?\",\"answer\":\"Models are compared using accuracy, precision, recall, and F1-score. Gaussian Naive Bayes reaches an accuracy rate of 99.79%, outperforming the clustering-based models in classification effectiveness.\"}]","Comparative Analysis of Machine Learning Models to Predict Common Vulnerabilities and Exposure | PDF",1785724543,25,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"comparative-analysis-of-machine-learning-models-to-predict-common-vulnerabilities-and-exposure","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/comparative-analysis-of-machine-learning-models-to-predict-common-vulnerabilities-and-exposure/119483/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is predicting Common Vulnerabilities and Exposures (CVE) challenging?","Question",{"text":75,"@type":76},"CVE prediction is difficult because cyberattacks are becoming more complex and threat intelligence data is large and varied. This increases the difficulty of extracting reliable patterns for forecasting vulnerabilities.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which machine learning models are used for CVE prediction in this study?",{"text":80,"@type":76},"The study uses Gaussian Naive Bayes as the supervised model and K-means and DBSCAN as unsupervised clustering-based models. These approaches are compared to assess predictive effectiveness.",{"name":82,"@type":73,"acceptedAnswer":83},"How is model performance evaluated?",{"text":84,"@type":76},"Models are compared using accuracy, precision, recall, and F1-score. Gaussian Naive Bayes reaches an accuracy rate of 99.79%, outperforming the clustering-based models in classification effectiveness.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":21,"slug":133},"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]