DEVELOPMENT OF EXPLAINABLE MALWARE INTELLIGENCE FRAMEWORK FOR DEFENSIVE CYBERSECURITY USING HYBRID FEATURE ENGINEERING, OPTIMIZED MACHINE LEARNING

Authors

  • Peter Wonah Odey Center for Cyberspace, Nasarawa State University, Keffi,
  • Akinshola-Awe Funmilayo Jumoke Center for Cyberspace, Nasarawa State University, Keffi,
  • Buter Daniel Ioryue Center for Cyberspace, Nasarawa State University, Keffi,

Abstract

The growing sophistication of malware, combined with the limits of signature-based detection and the opacity of many machine learning models, poses major challenges for cybersecurity. While machine learning improves detection accuracy, most approaches lack transparency and fail to convert predictions into actionable threat intelligence. Current XAI frameworks remain insufficient, focusing mainly on feature attribution rather than operational insights. This study introduces the Explainable Malware Intelligence Framework (EMIF), which integrates hybrid feature engineering, optimized machine learning, XAI, and the MITRE ATT&CK framework to support offensive and defensive operations. EMIF applies SMOTE–Tomek, PCA, Information Gain, and Chi-Square to build an optimized feature space. SVM, Decision Tree, and KNN classifiers were tuned using Grid Search, Random Search, and Genetic Algorithms. Transparency was achieved through SHAP and LIME, with behavioral features mapped to MITRE ATT&CK tactics for actionable intelligence. Evaluation used two datasets: a static PE set (19,611 samples) and the dynamic CICMalMem2022 set (58,596 samples). Grid Search–optimized SVM achieved the best results, with an F1-score and ROC-AUC of 99.98% on CICMalMem2022. Key behavioral indicators included process execution, thread management, Windows services, and dynamic library use, linked to ATT&CK techniques such as T1106, T1055, and T1543.003. EMIF advances malware detection by bridging optimized ML, explainability, and operational intelligence for forensics, threat hunting, and incident response.

Downloads

Published

2026-10-04

Issue

Section

ARTICLES