Optimizing malware detection across platforms using the firefly algorithm in cyber threat intelligence
摘要
Malware detection is a critical component of cyber threat intelligence (CTI), providing essential protection against increasingly sophisticated cyber threats. This paper aims to enhance malware detection capabilities by introducing a novel framework that employs the Firefly Algorithm for feature selection within a wrapper-based approach. A Decision Tree classifier is used to guide the selection process, with the goal of reducing feature dimensionality while preserving high classification performance. The proposed method was evaluated on three benchmark datasets CIC-Evasive- PDFMa12022, CIC MalMem 2022, and CIC MalDroid 2020 representing diverse malware types: PDF-based, memory-based, and Android-based threats. These datasets were selected to assess the generalizability and robustness of the model across multiple threat vectors and computing environments. Experimental results show that the proposed framework consistently achieves superior performance, with the Firefly–Decision Tree model reaching an average accuracy of 99.86%, precision of 99.77%, recall of 99.68%, and F1-score of 99.72% across all datasets and feature sets. This performance surpasses several state-of-the-art techniques, demonstrating that the Firefly Algorithm, when combined with a Decision Tree wrapper, provides a powerful and adaptable solution for detecting various types of malware.