Hybrid Threat Detection Using Wazuh, DBSCAN, Random Forest, and MISP Threat Intelligence
DOI:
https://doi.org/10.59261/jequi.v8i4.419Keywords:
DBSCAN, Cyber Threat Intelligence, MISP, Random Forest, SIEM, WazuhAbstract
Background: Cyber-attacks continue to grow in volume and sophistication, and small-to-medium organizations are increasingly exposed because of limited budgets and security personnel. Open-source Security Information and Event Management (SIEM) platforms such as Wazuh offer a low-cost alternative to commercial solutions, yet their reliance on static, rule-based correlation logic limits their ability to detect previously unseen or evolving threats and tends to generate a high rate of false positives.
Objective: This study evaluates a layered Wazuh pipeline in which DBSCAN supplies density-context features to a Random Forest classifier and MISP provides post-classification IOC enrichment within a controlled AIT-ADS laboratory setting.
Methods: The experimental evaluation is conducted using the AIT-ADS dataset, which consists of 423,499 alerts. A within-class blocked temporal split produced 338,799 train set and 84,700 test set. Four strictly causal temporal features were combined with ten row-local features; DBSCAN was fitted only on the train set (ε = 0.466428, min_samples = 5) and added four density-context features, yielding 18 classifier inputs before being cross-checked against MISP indicators of compromise.
Results: Experimental results show DBSCAN+Random Forest achieved macro-F1 = 0.2976, balanced accuracy = 0.3747, and MCC = 0.4940. Its binary matrix changed from TP = 84,266, TN = 63, FP = 241, FN = 130 to TP = 84,284, TN = 63, FP = 241, FN = 112 after MISP, a 13.85% FN reduction with no induced FP. XGBoost FN decreased from 72 to 54 (25.00%), but FP increased from 270 to 272.
Conclusion: The proposed hybrid pipeline demonstrates that machine-learning-based alert classification can reduce false positives in Wazuh while preserving high threat detection sensitivity. However, the results also show that performance remains uneven across minority attack classes, and the benefits of DBSCAN and MISP depend on data characteristics and IOC coverage. Overall, Random Forest provides a more suitable operational trade-off for reducing alert burden in the evaluated scenario.
Downloads
References
Akinrinade, O., & Du, C. (2025). Skin cancer detection using deep machine learning techniques. Intelligence-Based Medicine, 11. https://doi.org/10.1016/j.ibmed.2024.100191
Ali, M. A., & Al-Sharafi, S. A. H. (2025). Intrusion detection in IoT networks using machine learning and deep learning approaches for MitM attack mitigation. Discover Internet of Things, 5(1). https://doi.org/10.1007/s43926-025-00104-w
Ali, M. L., Thakur, K., Schmeelk, S., Debello, J., & Dragos, D. (2025). Deep Learning vs. Machine Learning for Intrusion Detection in Computer Networks: A Comparative Study. Applied Sciences (Switzerland), 15(4). https://doi.org/10.3390/app15041903
Alzahrani, I. Y., Lee, S., & Kim, K. (2024). Enhancing cyber-threat intelligence in the Arab world: Leveraging IoC and MISP integration. Electronics, 13(13). https://doi.org/10.3390/electronics13132526
Ariyanto, Y., Syaifudin, Y. W., Ratsanjani, M. H., Muladawila, A. R., Fatmawati, T., Saputra, P. Y., & Setiadi, C. (2025). Cyber Threat Detection and Automated Response Using Wazuh and Telegram API. MATRIK : Jurnal Manajemen, Teknik Informatika Dan Rekayasa Komputer, 25(1). https://doi.org/10.30812/matrik.v25i1.5610
Bin Sarhan, B., & Altwaijry, N. (2023). Insider Threat Detection Using Machine Learning Approach. Applied Sciences (Switzerland), 13(1). https://doi.org/10.3390/app13010259
Chamkar, S. A., Zaydi, M., Maleh, Y., & Gherabi, N. (2025). Improving threat detection in Wazuh using machine learning techniques. Journal of Cybersecurity and Privacy, 5(2), 1–25. https://doi.org/10.3390/jcp5020034
Chidukwani, A., Zander, S., & Koutsakis, P. (2024). Cybersecurity preparedness of small-to-medium businesses: A Western Australia study with broader implications. Computers & Security, 145, 104026. https://doi.org/10.1016/j.cose.2024.104026
Chicco, D., & Jurman, G. (2023). The Matthews correlation coefficient (MCC) should replace the ROC AUC as the standard metric for assessing binary classification. BioData Mining 2023 16:1, 16(1), 4-. https://doi.org/10.1186/S13040-023-00322-4
Dhanya, K. A., Vajipayajula, S., Srinivasan, K., Tibrewal, A., Kumar, T. S., & Kumar, T. G. (2023). Detection of network attacks using machine learning and deep learning models. Procedia Computer Science, 218, 57–66. https://doi.org/10.1016/j.procs.2022.12.401
Deng, D. (2020). DBSCAN clustering algorithm based on density. Proceedings of the 2020 7th International Forum on Electrical Engineering and Automation, 949–953. https://doi.org/10.1109/IFEEA51475.2020.00199
ENISA. (2025). ENISA, “Threat Landscape for Financial Sector,” European Union Agency for Cybersecurity. ENISA Threat Landscape: Finance Sector.
Ester, M., Kriegel, H. P., Sander, J., & Xu, X. (1996, August). A density-based algorithm for discovering clusters in large spatial databases with noise. In kdd (Vol. 96, No. 34, pp. 226-231).
Hidayat, M. R. T., Widiyasono, N., & Gunawan, R. (2025). Optimasi Deteksi Malware Pada Siem Wazuh Melalui Integrasi Cyber Threat Intelligence Dengan Misp Dan Dfir-Iris. Jurnal Informatika Dan Teknik Elektro Terapan, 13(1). https://doi.org/10.23960/jitet.v13i1.5686
Jakub Ziolek, D. B. J. L. I. B. I. C. G. F. K. L. Jussi O. (2025). ENISA Threat Landscape 2025 — Part 2. In European Union Agency for Cybersecurity, ENISA (Number October).
Lee, S., Mujammami, A. A. H., & Kim, K. (2025). Leveraging Social Networks for Cyber Threat Intelligence: Analyzing Attack Trends and TTPs in the Arab World. IEEE Access, 13. https://doi.org/10.1109/ACCESS.2024.3508025
Lella, I. (2024). ENISA threat landscape 2024. European Union Agency for Cybersecurity.
Lones, M. A. (2024). Avoiding common machine learning pitfalls. Patterns, 5(10). https://doi.org/10.1016/j.patter.2024.101046
Luay, M., Layeghy, S., Noorbin, N., Sarhan, M., Kulatilleke, G., Moustafa, N., & Portmann, M. (2026). Time Matters: Temporal NetFlow Features for ML-Based Network Intrusion Detection. IEEE Access, 14, 66899–66913. https://doi.org/10.1109/ACCESS.2026.3688204
Manzoor, J., Waleed, A., Jamali, A. F., & Masood, A. (2024). Cybersecurity on a budget: Evaluating security and performance of open-source SIEM solutions for SMEs. PLOS ONE, 19(3), e0301183. https://doi.org/10.1371/journal.pone.0301183
Nalliah, R. P., Praveen, S., Allareddy, T. V., Gajendrareddy, P., Lee, M. K., Oubaidin, M., & Allareddy, V. (2025). Cybersecurity threats and preparedness: Implications for dental schools. Journal of Dental Education, 89(4). https://doi.org/10.1002/jdd.13758
Negara, B. S. dan S. (2025). Threat Intelligence Report: Indonesian Critical Infrastructure Cybersecurity Status. BSSN.
Sahin, O., & Uludag, S. (2025). Leveraging inter-arrival time for efficient threat filtering: A parsimonious approach. Computers & Security, 154, 104471. https://doi.org/10.1016/J.COSE.2025.104471
Shakir, Y. H., Abdelhamied, M. M., Al Mandhari, E. A. A., Alkhazraji, A., & Reda, N. M. (2026). An efficient approach for cyber-attack detection by using machine learning and deep learning algorithms. IAES International Journal of Artificial Intelligence, 15(2). https://doi.org/10.11591/ijai.v15.i2.pp1219-1235
Tariq, A., Manzoor, J., Aziz, M. A., Tariq, Z. U. A., & Masood, A. (2023). Open source SIEM solutions for an enterprise. Information and Computer Security, 31(1). https://doi.org/10.1108/ICS-09-2021-0146
Uccello, F., Pawlicki, M., D’Antonio, S., Kozik, R., & Choraś, M. (2024). Towards Hybrid NIDS: Combining Rule-Based SIEM with AI-Based Intrusion Detectors. Lecture Notes in Networks and Systems, 956 LNNS, 244–255. https://doi.org/10.1007/978-3-031-56950-0_21
Vazão, A. P., Santos, L., Costa, R. L. de C., & Rabadão, C. (2023). Implementing and evaluating a GDPR-compliant open-source SIEM solution. Journal of Information Security and Applications, 75. https://doi.org/10.1016/j.jisa.2023.103509
Wagner, C., Dulaunoy, A., Wagener, G., & Iklody, A. (2016). Misp: The design and implementation of a collaborative threat intelligence sharing platform. In Proceedings of the 2016 ACM on workshop on information sharing and collaborative security (pp. 49-56).
Yin, L., Hu, H., Li, K., Zheng, G., Qu, Y., & Chen, H. (2023). Improvement of DBSCAN Algorithm Based on K-Dist Graph for Adaptive Determining Parameters. Electronics (Switzerland), 12(15). https://doi.org/10.3390/electronics12153213
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Miko Dewi Hatmanti, Rojali Rojali

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.




