A Hybrid Intelligent Cybersecurity Assessment System For Electronic Document Management Systems

Assylzhan Svanov, Assel Omarbekova, Gulmira Bekmanova, Alibek Barlybayev, Bibigul Razakhova, Lena Zhetkenbay, Magripa Saukhanova, Aizhan Nazyrova, Zhanar Lamasheva

Abstract


Electronic document management systems concentrate confidential and commercially sensitive information behind a single perimeter, making them a high-priority cyberattack target, while existing assessment methods remain largely static, checklist-based, or single-technique, poorly capturing configuration dynamics or prioritizing measures by expected risk reduction. The objective is to develop and validate an intelligent system for the quantitative, explainable cybersecurity assessment of such systems. The novelty and contribution are a hybrid architecture jointly integrating Mamdani fuzzy inference, a stacking ensemble of machine-learning classifiers (random forest, gradient boosting, and a multilayer perceptron), and a Bayesian threat network with an attack graph, unified by a shared domain ontology of document-management assets and threats weighted by confidentiality, integrity, and availability. These heterogeneous estimates are aggregated into a composite cybersecurity assessment index via a fuzzy analytic hierarchy process with adaptive re-weighting from confirmed incidents, while a two-level explainability layer traces each score to its features, fired rules, and probable attack paths. The system was evaluated on 10,239 labelled configuration states from an operational deployment using cross-validation, comparison against seven baseline models, and an ablation study. It achieved the best results among all compared approaches, with an F1-score of 0.946, a Matthews correlation coefficient of 0.927, and an area under the ROC curve of 0.972 – a gain of 2.4 percentage points over the strongest baseline and 10.4 over logistic regression – and the ablation study confirmed that the fuzzy and Bayesian components contribute complementary gains. These findings show that combining data-driven learning with expert-interpretable reasoning yields a more accurate and stable assessment than any single paradigm, and indicate that the framework can support continuous, evidence-based cybersecurity monitoring in document-centric organizations, with future work on adversarial robustness and multi-organization validation.


Article Metrics

Abstract: 17 Viewers PDF: 8 Viewers

Keywords


Cybersecurity; Electronic Document Management System; Risk Assessment; Fuzzy Logic; Machine Learning; Fuzzy AHP; Bayesian Network; Explainable AI

Full Text:

PDF


Refbacks

  • There are currently no refbacks.



Barcode

Journal of Applied Data Sciences

ISSN : 2723-6471 (Online)
Publisher : Bright Publisher
Website : http://bright-journal.org/JADS
Email : taqwa@amikompurwokerto.ac.id (principal contact)
    support@bright-journal.org (technical issues)

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0