Logo Lanfrica
  • Home
  • Atlas
  • Insights
  • Docs
  • Sign in

© 2026 Lanfrica. All rights reserved. All copyrights of the resources shown on the Lanfrica website belong to the original copyright holders, unless explicitly stated otherwise.

CYBERSECURITY THREAT INTELLIGENCE FRAMEWORK FOR FINANCIAL INSTITUTIONS IN NIGERIA: LEVERAGING MACHINE LEARNING AND DATA ANALYTICS

Domain:

digital infrastructure

Record type:

paperdataset
Creator:
BelTajAdaAis
Publisher:
University of Abuja
Host:
This studyevaluates the Cybersecurity Threat Intelligence Framework for Nigerian Financial Institutions (CTIF-NG). CTIF-NG is a five-layer architecture that brings together supervised and unsupervised machine learning algorithms, big-data analytics pipelines, and sector-specific threat-indicator feeds calibrated to documented Nigerian financial threat taxonomies. It is not a generic framework retrofitted for Nigeria it was designed around the CBN (2022), NDPA (2023), ISO/IEC 27035-2, and NIST SP 800-150 requirementsthat Nigerian institutions actually face. To evaluate the classification engine at its core, we constructed a structured simulation dataset of 20,000 records across seven threat classes. Feature distributions were drawn from published NSL-KDD (Tavallaee et al., 2009) and CICIDS-2017 (Sharafaldin et al., 2018) benchmark statistics and adapted to the Nigerian financial threat taxonomy. Real scikit-learn v1.8.0 experiments on the proposed RF and GBM and MLP Soft-Vote Ensemble produced: detection accuracy of 99.30%, macro-precision of 98.42%, macro-recall of 98.18%, F1-score of 98.30%, Matthews Correlation Coefficient of 0.9896, and AUC-ROC of 0.9999. All seven baseline classifiers were outperformed. APT class recall came in at 95.0% the lowest of all classes which was anticipated given that APT features were deliberately configured to overlap with normal traffic. Scenario projections suggest CTIF-NG can reduce mean time-to-detect by 64.8% and mean time-to-respond by 71.3% compared to conventional SIEM-only baselines, though live SOC validation is still required before these figures can be relied upon operationally

Visit

doi.org