<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">kaz44</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Университета Шакарима. Серия технические науки</journal-title><trans-title-group xml:lang="en"><trans-title>Bulletin of Shakarim University. Technical Sciences</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2788-7995</issn><issn pub-type="epub">3006-0524</issn><publisher><publisher-name>«Шәкәрім университеті» КеАҚ</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.53360/2788-7995-2026-1(21)-7</article-id><article-id custom-type="elpub" pub-id-type="custom">kaz44-2426</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>АВТОМАТИЗАЦИЯ И ИНФОРМАЦИОННЫЕ ТЕХНОЛОГИИ (ОРИГИНАЛЬНАЯ СТАТЬЯ)</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>AUTOMATION AND INFORMATION TECHNOLOGY (ORIGINAL ARTICLE)</subject></subj-group></article-categories><title-group><article-title>ИНТЕЛЛЕКТУАЛЬНЫЕ ГИБРИДНЫЕ МОДЕЛИ НА ОСНОВЕ ГЛУБОКОГО ОБУЧЕНИЯ ДЛЯ ОБНАРУЖЕНИЯ ВРЕДОНОСНЫХ ПРОГРАММ В ИНФОРМАЦИОННО-КОММУНИКАЦИОННОЙ СРЕДЕ</article-title><trans-title-group xml:lang="en"><trans-title>INTELLIGENT DEEP LEARNING-BASED HYBRID MODELS FOR MALWARE DETECTION IN THE ICT ENVIRONMENT</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-3913-1895</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Абдураимова</surname><given-names>Б. К.</given-names></name><name name-style="western" xml:lang="en"><surname>Abduraimova</surname><given-names>B. K.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Баян Куандыковна Абдураимова – кандидат технических наук, доцент </p><p>010000, г. Астана, ул. Сатпаева, 2</p></bio><bio xml:lang="en"><p>Bayan Kuandykovna Abduraimova – candidate of technical sciences, associate professor </p><p>010000, Astana, Satpayev Street</p></bio><email xlink:type="simple">abduraimovabk@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Нурмуханбетова</surname><given-names>А. Е.</given-names></name><name name-style="western" xml:lang="en"><surname>Nurmukhanbetova</surname><given-names>A. E.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Альбина Ерланкызы Нурмуханбетова – докторант кафедры информационной безопасности факультета информационных технологий ЕНУ им. Л.Н. Гумилева </p><p>010000, г. Астана, ул. Сатпаева, 2</p></bio><bio xml:lang="en"><p>Albina Erlankyzy Nurmukhanbetova – doctoral candidate in the Department of Information Security, Faculty of Information Technologies </p><p>010000, Astana, Satpayev Street</p></bio><email xlink:type="simple">nuralbina9898@gmail.com</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Евразийский национальный университет им. Л.Н. Гумилева</institution><country>Казахстан</country></aff><aff xml:lang="en"><institution>L.N. Gumilyov Eurasian National University</institution><country>Kazakhstan</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>25</day><month>05</month><year>2026</year></pub-date><volume>1</volume><issue>1(21)</issue><fpage>64</fpage><lpage>73</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Абдураимова Б.К., Нурмуханбетова А.Е., 2026</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="ru">Абдураимова Б.К., Нурмуханбетова А.Е.</copyright-holder><copyright-holder xml:lang="en">Abduraimova B.K., Nurmukhanbetova A.E.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://tech.vestnik.shakarim.kz/jour/article/view/2426">https://tech.vestnik.shakarim.kz/jour/article/view/2426</self-uri><abstract><p>В данной работе представлено исследование и разработка интеллектуальной гибридной модели на основе методов глубокого обучения для обнаружения вредоносного программного обеспечения (ВПО) в информационно-коммуникационных инфраструктурах. Цель исследования заключается в создании архитектуры, объединяющей сверточные (CNN), рекуррентные (GRU) и графовые (GNN) нейронные сети с онтологической нормализацией признаков. Такой подход обеспечивает комплексный анализ статических, поведенческих и структурных характеристик вредоносных программ, повышая устойчивость к атакам нулевого дня и полиморфным угрозам. Для экспериментальной проверки использовались открытые наборы данных EMBER-2018, Malimg, CICAndMal2017 и CICMalDroid-2020. Проведённые эксперименты показали, что предложенная гибридная архитектура обеспечивает точность классификации 98.7% и ROC-AUC 0.99, превосходя изолированные модели глубокого обучения и традиционные методы машинного анализа. Введение онтологической модели знаний позволило повысить интерпретируемость системы и снизить уровень ложноположительных срабатываний до 1.7 %. Разработанный программный прототип продемонстрировал применимость решения в системах реального времени (SOC/IDS) и показал потенциал для дальнейшего масштабирования и внедрения в практические системы кибербезопасности. Научная новизна исследования заключается в интеграции мультимодального анализа и онтологического моделирования, что обеспечивает более точное и объяснимое выявление вредоносных объектов в сложных цифровых средах.</p></abstract><trans-abstract xml:lang="en"><p>This paper presents the research and development of an intelligent hybrid model based on deep learning methods for malware detection in information and communication infrastructures. The goal of the study is to create an architecture combining convolutional (CNN), recurrent (GRU), and graph (GNN) neural networks with ontology-based feature normalization. This approach provides a comprehensive analysis of the static, behavioral, and structural characteristics of malware, increasing resilience to zero-day attacks and polymorphic threats. The EMBER-2018, Malimg, CICAndMal2017, and CICMalDroid-2020 open datasets were used for experimental validation. The experiments showed that the proposed hybrid architecture provides a classification accuracy of 98.7% and a ROC-AUC of 0.99, outperforming isolated deep learning models and traditional machine analysis methods. The introduction of an ontological knowledge model increased the system's interpretability and reduced the false-positive rate to 1.7%. The developed software prototype demonstrated the solution's applicability in real-time systems (SOC/IDS) and demonstrated potential for further scaling and implementation in practical cybersecurity systems. The scientific novelty of the study lies in the integration of multimodal analysis and ontological modeling, which enables more accurate and explainable detection of malicious objects in complex digital environments.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>вредоносное программное обеспечение</kwd><kwd>глубокое обучение</kwd><kwd>сверточные нейронные сети (CNN)</kwd><kwd>рекуррентные нейронные сети (GRU)</kwd><kwd>графовые нейронные сети (GNN)</kwd><kwd>обнаружение атак нулевого дня</kwd><kwd>гибридная архитектура</kwd><kwd>кибербезопасность</kwd></kwd-group><kwd-group xml:lang="en"><kwd>malware</kwd><kwd>deep learning</kwd><kwd>convolutional neural networks (CNN)</kwd><kwd>recurrent neural networks (GRU)</kwd><kwd>graph neural networks (GNN)</kwd><kwd>zero-day attack detection</kwd><kwd>hybrid architecture</kwd><kwd>cybersecurity</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">CHislo – goda resheniya laboratorii Laboratoriya Kasperskogo ezhednevno obnaruzhivayut 467 tysyach novyh vredonosnyh fajlov // Press-reliz. – Moskovskaya obl., 4 dek. 2024. https://www.kaspersky.ru/about/press-releases/chislo-goda-resheniya-laboratorii-kasperskogoezhednevno-obnaruzhivayut-467-tysyach-novyh-vredonosnyh-fajlov.</mixed-citation><mixed-citation xml:lang="en">CHislo – goda resheniya laboratorii Laboratoriya Kasperskogo ezhednevno obnaruzhivayut 467 tysyach novyh vredonosnyh fajlov // Press-reliz. – Moskovskaya obl., 4 dek. 2024. https://www.kaspersky.ru/about/press-releases/chislo-goda-resheniya-laboratorii-kasperskogoezhednevno-obnaruzhivayut-467-tysyach-novyh-vredonosnyh-fajlov.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Malware visualization for deep learning detection / Q. Cui et al // IEEE Access. – 2022. – Т. 10. – Р. 24435-24447.</mixed-citation><mixed-citation xml:lang="en">Malware visualization for deep learning detection / Q. Cui et al // IEEE Access. – 2022. – Т. 10. – Р. 24435-24447.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Saxe J. Deep Neural Network Based Malware Detection Using Two-Dimensional Binary Program Features / J. Saxe, K. Berlin // Proc. 10th Int. Conf. on Malicious and Unwanted Software (MALWARE). – 2015. – Р. 11-20. https://doi.org/10.1109/MALWARE.2015.7413680.</mixed-citation><mixed-citation xml:lang="en">Saxe J. Deep Neural Network Based Malware Detection Using Two-Dimensional Binary Program Features / J. Saxe, K. Berlin // Proc. 10th Int. Conf. on Malicious and Unwanted Software (MALWARE). – 2015. – Р. 11-20. https://doi.org/10.1109/MALWARE.2015.7413680.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Hybrid static and dynamic analysis for malware detection / A. Marastoni et al // Computers &amp; Security. – 2024. – Vol. 135. – Article 109934.</mixed-citation><mixed-citation xml:lang="en">Hybrid static and dynamic analysis for malware detection / A. Marastoni et al // Computers &amp; Security. – 2024. – Vol. 135. – Article 109934.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">AV-Comparatives. Real-World Protection Test 2024 – Summary Report // AVComparatives.org. – 2024.</mixed-citation><mixed-citation xml:lang="en">AV-Comparatives. Real-World Protection Test 2024 – Summary Report // AVComparatives.org. – 2024.</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Anderson H.S. EMBER: An open dataset for training static PE malware machine learning models / H.S. Anderson, P. Roth // arXiv. – 2018. – arXiv:1804.04637.</mixed-citation><mixed-citation xml:lang="en">Anderson H.S. EMBER: An open dataset for training static PE malware machine learning models / H.S. Anderson, P. Roth // arXiv. – 2018. – arXiv:1804.04637.</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Malware Images: Visualization and Automatic Classification / L. Nataraj et al // Proc. International Symposium on Visualization for Cyber Security (VizSec). – Jul 2011. – P. 1-7. https://doi.org/10.1145/2016904.2016908.</mixed-citation><mixed-citation xml:lang="en">Malware Images: Visualization and Automatic Classification / L. Nataraj et al // Proc. International Symposium on Visualization for Cyber Security (VizSec). – Jul 2011. – P. 1-7. https://doi.org/10.1145/2016904.2016908.</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Poornima P. Automated malware detection using machine learning and deep learning approaches for android applications / P. Poornima, G. Mahalakshmi // Expert Systems with Applications. – 2024. – Т. 237. – Article 121456.</mixed-citation><mixed-citation xml:lang="en">Poornima P. Automated malware detection using machine learning and deep learning approaches for android applications / P. Poornima, G. Mahalakshmi // Expert Systems with Applications. – 2024. – Т. 237. – Article 121456.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Graph Neural Networks for Malware Detection: A Survey / Y. Zhu et al // IEEE Access. – 2023. – Т. 11. – Р. 85123-85147.</mixed-citation><mixed-citation xml:lang="en">Graph Neural Networks for Malware Detection: A Survey / Y. Zhu et al // IEEE Access. – 2023. – Т. 11. – Р. 85123-85147.</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Ding Y. Ontology-based knowledge representation for malware individuals and families / Y. Ding, R. Wu, X. Xiao // Computers &amp; Security. – 2019. – Vol. 87. – Art. 101574. https://doi.org/10.1016/j.cose.2019.101574.</mixed-citation><mixed-citation xml:lang="en">Ding Y. Ontology-based knowledge representation for malware individuals and families / Y. Ding, R. Wu, X. Xiao // Computers &amp; Security. – 2019. – Vol. 87. – Art. 101574. https://doi.org/10.1016/j.cose.2019.101574.</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Deldar F. Deep Learning for Zero-day Malware Detection and Classification: A Survey / F. Deldar, M. Abadi // ACM Computing Surveys. – 2023. – Vol. 56, № 2. – P. 1-37. https://doi.org/10.1145/3605775.</mixed-citation><mixed-citation xml:lang="en">Deldar F. Deep Learning for Zero-day Malware Detection and Classification: A Survey / F. Deldar, M. Abadi // ACM Computing Surveys. – 2023. – Vol. 56, № 2. – P. 1-37. https://doi.org/10.1145/3605775.</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">ScaleMalNet: A Scalable Hybrid Deep Learning Model for Malware Classification / R. Vinayakumar et al // Future Generation Computer Systems. – 2020. – Т. 115. – P. 280-292.</mixed-citation><mixed-citation xml:lang="en">ScaleMalNet: A Scalable Hybrid Deep Learning Model for Malware Classification / R. Vinayakumar et al // Future Generation Computer Systems. – 2020. – Т. 115. – P. 280-292.</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Alshoulie M. Deep Learning Approaches for Malware Detection: A Comprehensive Review of Techniques, Challenges, and Future Directions / M. Alshoulie, A. Mehmood // IEEE Access. – 2025. – Т. 13. – P. 118652-118677. https://doi.org/10.1109/ACCESS.2025.3582875.</mixed-citation><mixed-citation xml:lang="en">Alshoulie M. Deep Learning Approaches for Malware Detection: A Comprehensive Review of Techniques, Challenges, and Future Directions / M. Alshoulie, A. Mehmood // IEEE Access. – 2025. – Т. 13. – P. 118652-118677. https://doi.org/10.1109/ACCESS.2025.3582875.</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Machine learning based fileless malware traffic classification using image visualization / F.A. Demmese et al // Cybersecurity. – 2023. – Т. 6, № 1. – Art. 32. https://doi.org/10.1186/s42400-023-00170-z.</mixed-citation><mixed-citation xml:lang="en">Machine learning based fileless malware traffic classification using image visualization / F.A. Demmese et al // Cybersecurity. – 2023. – Т. 6, № 1. – Art. 32. https://doi.org/10.1186/s42400-023-00170-z.</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">A framework for detecting zero-day exploits in network flows / A. Touré et al // Computer Networks. – 2024. – Vol. 224. – Art. 110476. https://doi.org/10.1016/j.comnet.2024.110476.</mixed-citation><mixed-citation xml:lang="en">A framework for detecting zero-day exploits in network flows / A. Touré et al // Computer Networks. – 2024. – Vol. 224. – Art. 110476. https://doi.org/10.1016/j.comnet.2024.110476.</mixed-citation></citation-alternatives></ref><ref id="cit16"><label>16</label><citation-alternatives><mixed-citation xml:lang="ru">Grad-CAM: Visual Explanations from Deep Networks via Gradient-Based Localization / R.R. Selvaraju et al // Proceedings of the IEEE International Conference on Computer Vision (ICCV). – 2017. – P. 618-626. https://doi.org/10.1109/ICCV.2017.74. https://doi.org/10.48550/arXiv.1610.02391</mixed-citation><mixed-citation xml:lang="en">Grad-CAM: Visual Explanations from Deep Networks via Gradient-Based Localization / R.R. Selvaraju et al // Proceedings of the IEEE International Conference on Computer Vision (ICCV). – 2017. – P. 618-626. https://doi.org/10.1109/ICCV.2017.74. https://doi.org/10.48550/arXiv.1610.02391</mixed-citation></citation-alternatives></ref><ref id="cit17"><label>17</label><citation-alternatives><mixed-citation xml:lang="ru">GNNExplainer: Generating Explanations for Graph Neural Networks / R. Ying et al // Advances in Neural Information Processing Systems (NeurIPS). – 2019. – Vol. 32. – P. 9240-9251. https://doi.org/10.48550/arXiv.1903.03894.</mixed-citation><mixed-citation xml:lang="en">GNNExplainer: Generating Explanations for Graph Neural Networks / R. Ying et al // Advances in Neural Information Processing Systems (NeurIPS). – 2019. – Vol. 32. – P. 9240-9251. https://doi.org/10.48550/arXiv.1903.03894.</mixed-citation></citation-alternatives></ref><ref id="cit18"><label>18</label><citation-alternatives><mixed-citation xml:lang="ru">Abduraimova B. Comparative study of machine learning applications in malware forensics / B. Abduraimova, S. Gnatyuk, A. Nurmukhanbetova // Proceedings of the Workshop on Cybersecurity Providing in Information and Telecommunication Systems II (CPITS-II 2024). – Kyiv, Ukraine, October 26, 2024. – CEUR Workshop Proceedings, Vol. 3826. – P. 139-152. https://ceur-ws.org/Vol3826/paper13.pdf (date of request: 03.11.2025).</mixed-citation><mixed-citation xml:lang="en">Abduraimova B. Comparative study of machine learning applications in malware forensics / B. Abduraimova, S. Gnatyuk, A. Nurmukhanbetova // Proceedings of the Workshop on Cybersecurity Providing in Information and Telecommunication Systems II (CPITS-II 2024). – Kyiv, Ukraine, October 26, 2024. – CEUR Workshop Proceedings, Vol. 3826. – P. 139-152. https://ceur-ws.org/Vol3826/paper13.pdf (date of request: 03.11.2025).</mixed-citation></citation-alternatives></ref><ref id="cit19"><label>19</label><citation-alternatives><mixed-citation xml:lang="ru">AlOmari H. A comparative analysis of machine learning algorithms for Android malware detection / H. AlOmari, Q.M. Yaseen, M.A. Al-Betar // Procedia Computer Science. – 2023. – Vol. 220. – P. 763-768. https://doi.org/10.1016/j.procs.2023.03.101.</mixed-citation><mixed-citation xml:lang="en">AlOmari H. A comparative analysis of machine learning algorithms for Android malware detection / H. AlOmari, Q.M. Yaseen, M.A. Al-Betar // Procedia Computer Science. – 2023. – Vol. 220. – P. 763-768. https://doi.org/10.1016/j.procs.2023.03.101.</mixed-citation></citation-alternatives></ref><ref id="cit20"><label>20</label><citation-alternatives><mixed-citation xml:lang="ru">Analyzing and comparing the effectiveness of malware detection: A study of machine learning approaches / M. Azeem et al // Heliyon Computer Science. – 2024. – Vol. 10, № 1. – Art. e24058. https://www.sciencedirect.com/science/article/pii/S2405844023107821.</mixed-citation><mixed-citation xml:lang="en">Analyzing and comparing the effectiveness of malware detection: A study of machine learning approaches / M. Azeem et al // Heliyon Computer Science. – 2024. – Vol. 10, № 1. – Art. e24058. https://www.sciencedirect.com/science/article/pii/S2405844023107821.</mixed-citation></citation-alternatives></ref><ref id="cit21"><label>21</label><citation-alternatives><mixed-citation xml:lang="ru">A robust machine learning-based mechanism for malware attack detection and analysis / R. Bakshi et al // Procedia Computer Science. – 2025. – Vol. 242. – P. 876-885. https://www.sciencedirect.com/science/article/pii/S1877050925010646.</mixed-citation><mixed-citation xml:lang="en">A robust machine learning-based mechanism for malware attack detection and analysis / R. Bakshi et al // Procedia Computer Science. – 2025. – Vol. 242. – P. 876-885. https://www.sciencedirect.com/science/article/pii/S1877050925010646.</mixed-citation></citation-alternatives></ref><ref id="cit22"><label>22</label><citation-alternatives><mixed-citation xml:lang="ru">Efficient malware detection using NLP and deep learning model / U. Gupta et al // Alexandria Engineering Journal. – 2025. – Vol. 124. – P. 550-564. https://www.sciencedirect.com/science/article/pii/S1110016825004260.</mixed-citation><mixed-citation xml:lang="en">Efficient malware detection using NLP and deep learning model / U. Gupta et al // Alexandria Engineering Journal. – 2025. – Vol. 124. – P. 550-564. https://www.sciencedirect.com/science/article/pii/S1110016825004260.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
