From Intrusion Classification to Threat Forecasting: A Systematic Mapping Review of Machine Learning Research

Alih Rama Hamda, Bisyron Wahyudi

Abstract


This review examines whether machine-learning intrusion detection studies genuinely forecast future cyber threats or mainly classify current observations, and evaluates their readiness for cyber threat intelligence operations. A systematic mapping review used two Scopus searches covering English articles and reviews from 2015 to 2025. The searches returned 310 records. After seven duplicates were removed, 303 records were screened. Twenty-two secondary studies were separated, and 281 primary studies were coded by publication characteristics, methods, datasets, evaluation evidence, temporal objective, and operational readiness. Publications increased from two in 2016 to seventy-seven in 2025. Of the primary studies, 260 performed contemporaneous detection or classification, eleven forecast future attack sequences, plans, targets, or trends, seven addressed early or pre-event detection, and three implemented adaptive or continual learning. Accuracy was reported far more often than latency, external validation, statistical uncertainty, or integration with security operations. Explicit cyber threat intelligence terminology appeared in eleven studies, while direct integration with security information and event management or security operations centers was rare. The literature is expanding rapidly but remains dominated by benchmark-based classification rather than operational forecasting. This review contributes a task-timing taxonomy and a five-dimensional readiness framework covering temporal validity, data realism, deployment feasibility, analyst interpretability, and cyber threat intelligence integration. Future studies should report prediction horizon, lead time, chronological validation, calibration, latency, and operational utility.

Keywords


cyber threat intelligence; early warning; concept drift; benchmark dataset; operational readiness; attack sequence; explainable artificial intelligence.

Full Text:

PDF


DOI: http://dx.doi.org/10.52155/ijpsat.v58.2.8532

Refbacks

  • There are currently no refbacks.


Copyright (c) 2026 Alih R Hamda

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 International License.