<p>Malware detection is a critical component of cyber threat intelligence (CTI), providing essential protection against increasingly sophisticated cyber threats. This paper aims to enhance malware detection capabilities by introducing a novel framework that employs the Firefly Algorithm for feature selection within a wrapper-based approach. A Decision Tree classifier is used to guide the selection process, with the goal of reducing feature dimensionality while preserving high classification performance. The proposed method was evaluated on three benchmark datasets CIC-Evasive- PDFMa12022, CIC MalMem 2022, and CIC MalDroid 2020 representing diverse malware types: PDF-based, memory-based, and Android-based threats. These datasets were selected to assess the generalizability and robustness of the model across multiple threat vectors and computing environments. Experimental results show that the proposed framework consistently achieves superior performance, with the Firefly–Decision Tree model reaching an average accuracy of 99.86%, precision of 99.77%, recall of 99.68%, and F1-score of 99.72% across all datasets and feature sets. This performance surpasses several state-of-the-art techniques, demonstrating that the Firefly Algorithm, when combined with a Decision Tree wrapper, provides a powerful and adaptable solution for detecting various types of malware.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Optimizing malware detection across platforms using the firefly algorithm in cyber threat intelligence

  • Hadeel Alazzam,
  • Orieb Abualghanam,
  • Moutaz Alazab

摘要

Malware detection is a critical component of cyber threat intelligence (CTI), providing essential protection against increasingly sophisticated cyber threats. This paper aims to enhance malware detection capabilities by introducing a novel framework that employs the Firefly Algorithm for feature selection within a wrapper-based approach. A Decision Tree classifier is used to guide the selection process, with the goal of reducing feature dimensionality while preserving high classification performance. The proposed method was evaluated on three benchmark datasets CIC-Evasive- PDFMa12022, CIC MalMem 2022, and CIC MalDroid 2020 representing diverse malware types: PDF-based, memory-based, and Android-based threats. These datasets were selected to assess the generalizability and robustness of the model across multiple threat vectors and computing environments. Experimental results show that the proposed framework consistently achieves superior performance, with the Firefly–Decision Tree model reaching an average accuracy of 99.86%, precision of 99.77%, recall of 99.68%, and F1-score of 99.72% across all datasets and feature sets. This performance surpasses several state-of-the-art techniques, demonstrating that the Firefly Algorithm, when combined with a Decision Tree wrapper, provides a powerful and adaptable solution for detecting various types of malware.