{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T01:38:29Z","timestamp":1760060309312,"version":"build-2065373602"},"reference-count":74,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,8,16]],"date-time":"2025-08-16T00:00:00Z","timestamp":1755302400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>The growing sophistication of cyber threats has posed significant challenges for organizations in terms of accurately detecting and responding to incidents in a coordinated manner. Despite advances in the application of machine learning and automation, many solutions still face limitations such as high false positive rates, low scalability, and difficulties in interorganizational cooperation. This study presents MICRA (Modular Intelligent Cybersecurity Response Architecture), a modular conceptual proposal that integrates dynamic data acquisition, cognitive threat analysis, multi-layer validation, adaptive response orchestration, and collaborative intelligence sharing. The architecture consists of six interoperable modules and incorporates techniques such as supervised learning, heuristic analysis, and behavioral modeling. The modules are designed for operation in diverse environments, including corporate networks, educational networks, and critical infrastructures. MICRA seeks to establish a flexible and scalable foundation for proactive cyber defense, reconciling automation, collaborative intelligence, and adaptability. This proposal aims to support future implementations and research on incident response and cyber resilience in complex operational contexts.<\/jats:p>","DOI":"10.3390\/jcp5030060","type":"journal-article","created":{"date-parts":[[2025,8,18]],"date-time":"2025-08-18T15:34:53Z","timestamp":1755531293000},"page":"60","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["MICRA: A Modular Intelligent Cybersecurity Response Architecture with Machine Learning Integration"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7951-7066","authenticated-orcid":false,"given":"Alessandro Carvalho","family":"Coutinho","sequence":"first","affiliation":[{"name":"School of Arts, Sciences and Humanities of University of S\u00e3o Paulo, S\u00e3o Paulo 03828-000, Brazil"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Luciano Vieira de","family":"Ara\u00fajo","sequence":"additional","affiliation":[{"name":"School of Arts, Sciences and Humanities of University of S\u00e3o Paulo, S\u00e3o Paulo 03828-000, Brazil"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,8,16]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"11","DOI":"10.26483\/ijarcs.v11i1.6502","article-title":"Advanced Persistent Threats and its Role in Network Security Vulnerabilities","volume":"11","year":"2020","journal-title":"Int. J. Adv. Res. Comput. Sci."},{"key":"ref_2","first-page":"24","article-title":"Cybersecurity Management: Developing Robust Strategies for Protecting Corporate Information Systems","volume":"3","author":"Kaushik","year":"2024","journal-title":"Int. J. Glob. Acad. Sci. Res."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"89467","DOI":"10.1109\/ACCESS.2024.3420238","article-title":"Identifying Anomaly in IoT Traffic Flow With Locality Sensitive Hashes","volume":"12","author":"Charyyev","year":"2024","journal-title":"IEEE Access"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1186\/s40537-020-00363-0","article-title":"A Survey of Methods Supporting Cyber Situational Awareness in the Context of Smart Cities","volume":"7","author":"Neshenko","year":"2020","journal-title":"J. Big Data"},{"doi-asserted-by":"crossref","unstructured":"Dave, D., Sawhney, G., Aggarwal, P., Silswal, N., and Khut, D. (2023). The New Frontier of Cybersecurity: Emerging Threats and Innovations. arXiv.","key":"ref_5","DOI":"10.1109\/ICT60153.2023.10374044"},{"unstructured":"Karras, D.A., and Gheisari, M. (2024, January 23\u201325). Synergizing Next-Generation Firewalls and Defense-in-Depth Strategies in a Dynamic Cybersecurity Landscape. Proceedings of the International Conference on Computer Network Security and Software Engineering (CNSSE 2024), Sanya, China.","key":"ref_6"},{"unstructured":"Al-Haija, Q.A. (2024). ZTA-DEVSECOPS: Strategies Towards Network Zero Trust Architecture and DevSecops in Cybersecurity and IIoT Environments. Advances in Information Security, Privacy, and Ethics, IGI Global.","key":"ref_7"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"3","DOI":"10.29121\/granthaalayah.v12.i5.2024.5655","article-title":"Towards Improved Threat Mitigation in Digital Environments: A Comprehensive Framework for Cybersecurity Enhancement","volume":"12","author":"Balisane","year":"2024","journal-title":"Int. J. Res. Granthaalayah"},{"doi-asserted-by":"crossref","unstructured":"Balaram, A., Umashankari, E., Dutt, A., Bharadwaj, G., V, R., and Albawi, A. (2024, January 9\u201311). Addressing the Rising Challenge of Malware Innovative Detection and Mitigation Techniques. Proceedings of the 2024 International Conference on Communication, Computer Sciences and Engineering (IC3SE), Gautam Buddha Nagar, India.","key":"ref_9","DOI":"10.1109\/IC3SE62002.2024.10593567"},{"key":"ref_10","first-page":"12","article-title":"A Review of Cybersecurity Strategies in Modern Organizations: Examining the Evolution and Effectiveness of Cybersecurity Measures for Data Protection","volume":"5","author":"Temitayo","year":"2024","journal-title":"Comput. Sci. IT Res. J."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"327","DOI":"10.3390\/jcp3030017","article-title":"A Dynamic and Adaptive Cybersecurity Governance Framework","volume":"3","author":"Melaku","year":"2023","journal-title":"J. Cybersecur. Priv."},{"doi-asserted-by":"crossref","unstructured":"Chechkin, A., Pleshakova, E., and Gataullin, S. (2025). A Hybrid KAN-BiLSTM Transformer with Multi-Domain Dynamic Attention Model for Cybersecurity. Technologies, 13.","key":"ref_12","DOI":"10.3390\/technologies13060223"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1186\/s13677-024-00609-9","article-title":"A Fog-Edge-Enabled Intrusion Detection System for Smart Grids","volume":"13","author":"Tariq","year":"2024","journal-title":"J. Cloud Comput."},{"doi-asserted-by":"crossref","unstructured":"Nguyen, P., Dautov, R., Song, H., Rego, A., Iturbe, E., Rios, E., Sagasti, D., Nicolas, G., Vald\u00e9s, V., and Mallouli, W. (2023, January 4\u20136). Towards Smarter Security Orchestration and Automatic Response for CPS and IoT. Proceedings of the 2023 IEEE International Conference on Cloud Computing Technology and Science (CloudCom), Napoli, Italy.","key":"ref_14","DOI":"10.1109\/CloudCom59040.2023.00055"},{"doi-asserted-by":"crossref","unstructured":"Hasan, S.M., Alotaibi, A.M., Talukder, S., and Shahid, A.R. (2024, January 2\u20134). Distributed Threat Intelligence at the Edge Devices: A Large Language Model-Driven Approach. Proceedings of the 2024 IEEE 48th Annual Computers, Software, and Applications Conference (COMPSAC), Osaka, Japan.","key":"ref_15","DOI":"10.1109\/COMPSAC61105.2024.00206"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1186\/s40537-024-00957-y","article-title":"Advancing Cybersecurity: A Comprehensive Review of AI-Driven Detection Techniques","volume":"11","author":"Salem","year":"2024","journal-title":"J. Big Data"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1186\/s42400-018-0016-5","article-title":"Forecasting Cyberattacks with Incomplete, Imbalanced, and Insignificant Data","volume":"1","author":"Okutan","year":"2018","journal-title":"Cybersecurity"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1186\/s40537-020-00318-5","article-title":"Cybersecurity Data Science: An Overview from Machine Learning Perspective","volume":"7","author":"Sarker","year":"2020","journal-title":"J. Big Data"},{"doi-asserted-by":"crossref","unstructured":"Silaen, K.E., Meyliana, M., Warnars, H.L.H.S., Prabowo, H., Hidayanto, A.N., and Anggreainy, M.S. (2023, January 1\u20132). Usefulness of Honeypots Towards Data Security: A Systematic Literature Review. Proceedings of the 2023 International Workshop on Artificial Intelligence and Image Processing (IWAIIP), Yogyakarta, Indonesia.","key":"ref_19","DOI":"10.1109\/IWAIIP58158.2023.10462777"},{"doi-asserted-by":"crossref","unstructured":"Skrobanek, P. (2011). Intrusion Detection Systems, BoD\u2013Books on Demand.","key":"ref_20","DOI":"10.5772\/593"},{"unstructured":"(2025, August 07). MISP MISP Open Source Threat Intelligence Platform & Open Standards For Threat Information Sharing. Available online: https:\/\/www.misp-project.org\/.","key":"ref_21"},{"doi-asserted-by":"crossref","unstructured":"Alzahrani, I., Lee, S., and Kim, K. (2024). Practical Cyber Threat and OSINT Analysis based on Implementation of CTI Sharing Platform. Electronics, 13.","key":"ref_22","DOI":"10.20944\/preprints202405.0277.v1"},{"doi-asserted-by":"crossref","unstructured":"Szczepanik, W., and Niemiec, M. (2022). Heuristic Intrusion Detection Based on Traffic Flow Statistical Analysis. Energies, 15.","key":"ref_23","DOI":"10.3390\/en15113951"},{"doi-asserted-by":"crossref","unstructured":"Iwabuchi, M., and Nakamura, A. (2024, January 1\u20132). A Heuristics and Machine Learning Hybrid Approach to Adaptive Cyberattack Detection. Proceedings of the 2024 International Conference on Artificial Intelligence, Computer, Data Sciences and Applications (ACDSA), Victoria, Seychelles.","key":"ref_24","DOI":"10.1109\/ACDSA59508.2024.10467929"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"88","DOI":"10.58496\/BJN\/2024\/010","article-title":"Integrating Behavioral Analytics and Intrusion Detection Systems to Protect Critical Infrastructure and Smart Cities","volume":"2024","author":"Amirthayogam","year":"2024","journal-title":"Babylon. J. Netw."},{"doi-asserted-by":"crossref","unstructured":"Krajewska, A., and Niewiadomska-Szynkiewicz, E. (2024). Clustering Network Traffic Using Semi-Supervised Learning. Electronics, 13.","key":"ref_26","DOI":"10.3390\/electronics13142769"},{"doi-asserted-by":"crossref","unstructured":"Wang, J., Yang, L., Wu, J., and Abawajy, J.H. (2017, January 21\u201325). Clustering Analysis for Malicious Network Traffic. Proceedings of the 2017 IEEE International Conference on Communications (ICC), Paris, France.","key":"ref_27","DOI":"10.1109\/ICC.2017.7997375"},{"doi-asserted-by":"crossref","unstructured":"Pascoe, C., Quinn, S., and Scarfone, K. (2024). The NIST Cybersecurity Framework (CSF) 2.0, NIST.","key":"ref_28","DOI":"10.6028\/NIST.SP.1301.por"},{"unstructured":"(2025, August 07). OpenCTI Platform. Available online: https:\/\/filigran.io\/platforms\/opencti\/.","key":"ref_29"},{"unstructured":"(2025, July 24). Cowrie. Available online: https:\/\/docs.cowrie.org\/en\/latest\/index.html.","key":"ref_30"},{"unstructured":"(2025, August 07). Welcome to Dionaea\u2019s Documentation!\u2014Dionaea 0.11.0 Documentation. Available online: https:\/\/dionaea.readthedocs.io\/en\/latest\/.","key":"ref_31"},{"unstructured":"(2025, August 07). Developments of the Honeyd Virtual Honeypot | Honeyd. Available online: https:\/\/www.honeyd.org\/.","key":"ref_32"},{"doi-asserted-by":"crossref","unstructured":"Claise, B. (2004). Cisco Systems NetFlow Services Export Version 9, Internet Engineering Task Force.","key":"ref_33","DOI":"10.17487\/rfc3954"},{"unstructured":"Panchen, S., McKee, N., and Phaal, P. (2001). InMon Corporation\u2019s sFlow: A Method for Monitoring Traffic in Switched and Routed Networks, Internet Engineering Task Force.","key":"ref_34"},{"unstructured":"Zseby, T., Claise, B., Quittek, J., and Zander, S. (2004). Requirements for IP Flow Information Export (IPFIX), Internet Engineering Task Force.","key":"ref_35"},{"unstructured":"nProbe (2025, August 07). ntop. Available online: https:\/\/www.ntop.org\/products\/netflow-probes\/nprobe\/.","key":"ref_36"},{"unstructured":"(2025, August 07). The Zeek Network Security Monitor. Available online: https:\/\/zeek.org\/.","key":"ref_37"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"1565","DOI":"10.1038\/nbt1206-1565","article-title":"What Is a Support Vector Machine?","volume":"24","author":"Noble","year":"2006","journal-title":"Nat. Biotechnol."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"1937","DOI":"10.1007\/s10462-020-09896-5","article-title":"A Comparative Analysis of Gradient Boosting Algorithms","volume":"54","year":"2021","journal-title":"Artif. Intell. Rev."},{"key":"ref_40","first-page":"1063","article-title":"Analysis of a Random Forests Model","volume":"13","author":"Biau","year":"2012","journal-title":"J Mach Learn Res"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"261","DOI":"10.1007\/s10462-011-9272-4","article-title":"Decision Trees: A Recent Overview","volume":"39","author":"Kotsiantis","year":"2013","journal-title":"Artif. Intell. Rev."},{"doi-asserted-by":"crossref","unstructured":"Norouzi, M., and Fleet, D.J. (2013, January 23\u201328). Cartesian K-Means. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Portland, OR, USA.","key":"ref_42","DOI":"10.1109\/CVPR.2013.388"},{"doi-asserted-by":"crossref","unstructured":"Singh, H.V., Girdhar, A., and Dahiya, S. (2022, January 25\u201327). A Literature Survey Based on DBSCAN Algorithms. Proceedings of the 2022 6th International Conference on Intelligent Computing and Control Systems (ICICCS), Madurai, Tamil Nadu, India.","key":"ref_43","DOI":"10.1109\/ICICCS53718.2022.9788440"},{"doi-asserted-by":"crossref","unstructured":"Rawat, R., Kassem, A.A., Dixit, K.K., Deepak, A., Pushkarna, G., and Harikrishna, M. (2024, January 9\u201311). Real-Time Anomaly Detection in Large-Scale Sensor Networks Using Isolation Forests. Proceedings of the 2024 International Conference on Communication, Computer Sciences and Engineering (IC3SE), Gautam Buddha Nagar, India.","key":"ref_44","DOI":"10.1109\/IC3SE62002.2024.10593443"},{"doi-asserted-by":"crossref","unstructured":"Tien, C.-W., Huang, T.-Y., Chen, P.-C., and Wang, J.-H. (2021). Using Autoencoders for Anomaly Detection and Transfer Learning in IoT. Computers, 10.","key":"ref_45","DOI":"10.3390\/computers10070088"},{"doi-asserted-by":"crossref","unstructured":"Xiao, J., and Zhou, Z. (2020, January 27\u201329). Research Progress of RNN Language Model. Proceedings of the 2020 IEEE International Conference on Artificial Intelligence and Computer Applications (ICAICA), Dalian, China.","key":"ref_46","DOI":"10.1109\/ICAICA50127.2020.9182390"},{"unstructured":"(2025, August 07). VirusTotal-Home. Available online: https:\/\/www.virustotal.com\/gui\/home\/upload.","key":"ref_47"},{"unstructured":"Cortex (2025, August 07). StrangeBee. Available online: https:\/\/strangebee.com\/cortex\/.","key":"ref_48"},{"unstructured":"(2025, August 07). AbuseIPDB-IP Address Abuse Reports-Making the Internet Safer, One IP at a Time. Available online: https:\/\/www.abuseipdb.com\/.","key":"ref_49"},{"unstructured":"(2025, August 07). PhishTank | Join the Fight Against Phishing. Available online: https:\/\/phishtank.org\/.","key":"ref_50"},{"unstructured":"Wazuh Wazuh-Open Source XDR (2025, August 07). Open Source SIEM. Available online: https:\/\/wazuh.com\/.","key":"ref_51"},{"unstructured":"(2025, August 07). Graylog. Available online: https:\/\/graylog.org\/.","key":"ref_52"},{"unstructured":"(2025, August 07). MariaDB Foundation. Available online: https:\/\/mariadb.org\/.","key":"ref_53"},{"unstructured":"(2025, August 07). PostgreSQL. Available online: https:\/\/www.postgresql.org\/.","key":"ref_54"},{"unstructured":"(2025, August 07). MongoDB: The World\u2019s Leading Modern Database. Available online: https:\/\/www.mongodb.com\/.","key":"ref_55"},{"unstructured":"(2025, August 07). Elasticsearch: The Official Distributed Search & Analytics Engine. Available online: https:\/\/www.elastic.co\/elasticsearch.","key":"ref_56"},{"unstructured":"(2025, August 07). Exascale Object Store for AI | MinIO. Available online: https:\/\/www.min.io.","key":"ref_57"},{"unstructured":"(2025, August 07). Ceph. Available online: https:\/\/ceph.io\/en\/.","key":"ref_58"},{"unstructured":"(2025, August 07). Apache Hadoop. Available online: https:\/\/hadoop.apache.org\/.","key":"ref_59"},{"unstructured":"(2025, August 07). The Open Source SOAR for All Purposes. Available online: https:\/\/shuffler.io.","key":"ref_60"},{"unstructured":"(2025, August 07). Suricata. Available online: https:\/\/suricata.io\/.","key":"ref_61"},{"unstructured":"(2025, August 07). Snort-Network Intrusion Detection & Prevention System. Available online: https:\/\/www.snort.org\/.","key":"ref_62"},{"unstructured":"(2025, August 07). SQLAlchemy. Available online: https:\/\/www.sqlalchemy.org.","key":"ref_63"},{"unstructured":"(2025, August 07). Pandas-Python Data Analysis Library. Available online: https:\/\/pandas.pydata.org\/.","key":"ref_64"},{"unstructured":"(2025, August 07). Deliver Trusted Data with Dbt | Dbt Labs. Available online: https:\/\/www.getdbt.com\/.","key":"ref_65"},{"unstructured":"(2025, August 07). Superset. Available online: https:\/\/superset.apache.org\/.","key":"ref_66"},{"unstructured":"(2025, August 07). Open Source Business Intelligence and Embedded Analytics. Available online: https:\/\/www.metabase.com\/.","key":"ref_67"},{"unstructured":"(2025, August 07). Project Jupyter. Available online: https:\/\/jupyter.org.","key":"ref_68"},{"unstructured":"Shiva Darshan, S.L., Manoj Kumar, M.V., Prashanth, B.S., and Vishnu Srinivasa Murthy, Y. (2023). Malware Detection Using Yara Rules in SIEM: In Advances in Information Security, Privacy, and Ethics, IGI Global.","key":"ref_69"},{"unstructured":"(2025, August 07). SigmaHQ\/Sigma. Available online: https:\/\/github.com\/SigmaHQ\/sigma.","key":"ref_70"},{"unstructured":"(2025, August 07). Osquery | Easily Ask Questions About Your Linux, Windows, and MacOS Infrastructure. Available online: https:\/\/www.osquery.io\/.","key":"ref_71"},{"key":"ref_72","doi-asserted-by":"crossref","first-page":"155859","DOI":"10.1109\/ACCESS.2020.3019330","article-title":"A Flexible SDN-Based Architecture for Identifying and Mitigating Low-Rate DDoS Attacks Using Machine Learning","volume":"8","author":"Valdovinos","year":"2020","journal-title":"IEEE Access"},{"key":"ref_73","doi-asserted-by":"crossref","first-page":"1331","DOI":"10.1109\/TDSC.2023.3278857","article-title":"Ablation Analysis for Multi-Device Deep Learning-Based Physical Side-Channel Analysis","volume":"21","author":"Wu","year":"2024","journal-title":"IEEE Trans Dependable Secur. Comput."},{"unstructured":"(2025, July 24). IDS 2017 | Datasets | Research | Canadian Institute for Cybersecurity | UNB. Available online: https:\/\/www.unb.ca\/cic\/datasets\/ids-2017.html.","key":"ref_74"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/60\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:29:00Z","timestamp":1760034540000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/60"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,16]]},"references-count":74,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["jcp5030060"],"URL":"https:\/\/doi.org\/10.3390\/jcp5030060","relation":{},"ISSN":["2624-800X"],"issn-type":[{"type":"electronic","value":"2624-800X"}],"subject":[],"published":{"date-parts":[[2025,8,16]]}}}