UGC Approved Journal no 63975(19)
New UGC Peer-Reviewed Rules

ISSN: 2349-5162 | ESTD Year : 2014
Volume 13 | Issue 9 | September 2026

JETIREXPLORE- Search Thousands of research papers



WhatsApp Contact
Click Here

Published in:

Volume 13 Issue 9
September-2026
eISSN: 2349-5162

UGC and ISSN approved 7.95 impact factor UGC Approved Journal no 63975

7.95 impact factor calculated by Google scholar

Unique Identifier

Published Paper ID:
JETIR2609152


Registration ID:
585980

Page Number

b458-b464

Share This Article


Jetir RMS

Title

A Rule-First and Evidence-Driven MLOps Framework for Cybersecurity Anomaly Detection and Investigation

Abstract

Modern cybersecurity setups generate amounts of mixed logs and events which makes it really hard to find the threats that are important and look into suspicious activity fast. Rule based detection is still useful because the logic is clear and easy for analysts to believe in while machine learning based anomaly detection can find behavior that no rule was written for. But in reality these two methods usually work in systems so the signals from anomalies rarely connect properly to security evidence, investigation steps or the daily management of the models that create them. This paper introduces AegisML, a rule-first evidence-driven MLOps framework made for cybersecurity anomaly detection and investigation. It combines detection rules, policies, signatures IOC matching and event correlation with an Isolation Forest based behavioral anomaly model. Importantly the ML part is not asked to decide if something is an attack; instead it provides extra behavioral evidence that analysts can use with all other information. AegisML also connects events, detections, findings and investigations through relationships based on evidence. Includes MLOps practices like dataset management, experiment tracking, model versioning, registration, drift monitoring and controlled retraining. In short AegisML bridges the gap, between security detection and ML lifecycle management by bringing evidence, analysis, investigation and model governance together in one system. Its main contribution is not an anomaly detection algorithm but a more connected, trackable and controlled way of doing cybersecurity anomaly detection.

Key Words

Cybersecurity, Anomaly Detection, MLOps, Security Logs, Isolation Forest, Evidence Driven Investigation, Security Analytics, Model Lifecycle, Drift Detection, Model Governance.

Cite This Article

"A Rule-First and Evidence-Driven MLOps Framework for Cybersecurity Anomaly Detection and Investigation", International Journal of Emerging Technologies and Innovative Research (www.jetir.org), ISSN:2349-5162, Vol.13, Issue 9, page no.b458-b464, September-2026, Available :http://www.jetir.org/papers/JETIR2609152.pdf

ISSN


2349-5162 | Impact Factor 7.95 Calculate by Google Scholar

An International Scholarly Open Access Journal, Peer-Reviewed, Refereed Journal Impact Factor 7.95 Calculate by Google Scholar and Semantic Scholar | AI-Powered Research Tool, Multidisciplinary, Monthly, Multilanguage Journal Indexing in All Major Database & Metadata, Citation Generator

Cite This Article

"A Rule-First and Evidence-Driven MLOps Framework for Cybersecurity Anomaly Detection and Investigation", International Journal of Emerging Technologies and Innovative Research (www.jetir.org | UGC and issn Approved), ISSN:2349-5162, Vol.13, Issue 9, page no. ppb458-b464, September-2026, Available at : http://www.jetir.org/papers/JETIR2609152.pdf

Publication Details

Published Paper ID: JETIR2609152
Registration ID: 585980
Published In: Volume 13 | Issue 9 | Year September-2026
DOI (Digital Object Identifier):
Page No: b458-b464
Country: Mumbai, Maharashtra, India .
Area: Science & Technology
ISSN Number: 2349-5162
Publisher: IJ Publication


Preview This Article


Downlaod

Click here for Article Preview

Download PDF

Downloads

0006

Print This Page

Current Call For Paper

Jetir RMS