«Тағам инженериясы және биотехнология», «Химиялық технология», "Техникалық физика және Жылу энергетикасы" және «Автоматтандыру және ақпараттық технологиялар» бағыттары бойынша үшінші нөмірге жарияланымдар қабылдау жабылды!

Прием публикаций на третий номер по направлениям «Пищевая инженерия и биотехнология», «Химическая технология», «Техническая физика и теплоэнергетика» и «Автоматизация и информационные технологии» закрыт!

Submissions for the third issue in the fields of “Food Engineering and Biotechnology”, “Chemical Technology”, "Technical physics and thermal power engineering" and “Automation and Information Technologies” are closed!

Preview

Bulletin of Shakarim University. Technical Sciences

Advanced search

INTELLIGENT DEEP LEARNING-BASED HYBRID MODELS FOR MALWARE DETECTION IN THE ICT ENVIRONMENT

https://doi.org/10.53360/2788-7995-2026-1(21)-7

Abstract

This paper presents the research and development of an intelligent hybrid model based on deep learning methods for malware detection in information and communication infrastructures. The goal of the study is to create an architecture combining convolutional (CNN), recurrent (GRU), and graph (GNN) neural networks with ontology-based feature normalization. This approach provides a comprehensive analysis of the static, behavioral, and structural characteristics of malware, increasing resilience to zero-day attacks and polymorphic threats. The EMBER-2018, Malimg, CICAndMal2017, and CICMalDroid-2020 open datasets were used for experimental validation. The experiments showed that the proposed hybrid architecture provides a classification accuracy of 98.7% and a ROC-AUC of 0.99, outperforming isolated deep learning models and traditional machine analysis methods. The introduction of an ontological knowledge model increased the system's interpretability and reduced the false-positive rate to 1.7%. The developed software prototype demonstrated the solution's applicability in real-time systems (SOC/IDS) and demonstrated potential for further scaling and implementation in practical cybersecurity systems. The scientific novelty of the study lies in the integration of multimodal analysis and ontological modeling, which enables more accurate and explainable detection of malicious objects in complex digital environments.

About the Authors

B. K. Abduraimova
L.N. Gumilyov Eurasian National University
Kazakhstan

Bayan Kuandykovna Abduraimova – candidate of technical sciences, associate professor 

010000, Astana, Satpayev Street



A. E. Nurmukhanbetova
L.N. Gumilyov Eurasian National University
Kazakhstan

Albina Erlankyzy Nurmukhanbetova – doctoral candidate in the Department of Information Security, Faculty of Information Technologies 

010000, Astana, Satpayev Street



References

1. CHislo – goda resheniya laboratorii Laboratoriya Kasperskogo ezhednevno obnaruzhivayut 467 tysyach novyh vredonosnyh fajlov // Press-reliz. – Moskovskaya obl., 4 dek. 2024. https://www.kaspersky.ru/about/press-releases/chislo-goda-resheniya-laboratorii-kasperskogoezhednevno-obnaruzhivayut-467-tysyach-novyh-vredonosnyh-fajlov.

2. Malware visualization for deep learning detection / Q. Cui et al // IEEE Access. – 2022. – Т. 10. – Р. 24435-24447.

3. Saxe J. Deep Neural Network Based Malware Detection Using Two-Dimensional Binary Program Features / J. Saxe, K. Berlin // Proc. 10th Int. Conf. on Malicious and Unwanted Software (MALWARE). – 2015. – Р. 11-20. https://doi.org/10.1109/MALWARE.2015.7413680.

4. Hybrid static and dynamic analysis for malware detection / A. Marastoni et al // Computers & Security. – 2024. – Vol. 135. – Article 109934.

5. AV-Comparatives. Real-World Protection Test 2024 – Summary Report // AVComparatives.org. – 2024.

6. Anderson H.S. EMBER: An open dataset for training static PE malware machine learning models / H.S. Anderson, P. Roth // arXiv. – 2018. – arXiv:1804.04637.

7. Malware Images: Visualization and Automatic Classification / L. Nataraj et al // Proc. International Symposium on Visualization for Cyber Security (VizSec). – Jul 2011. – P. 1-7. https://doi.org/10.1145/2016904.2016908.

8. Poornima P. Automated malware detection using machine learning and deep learning approaches for android applications / P. Poornima, G. Mahalakshmi // Expert Systems with Applications. – 2024. – Т. 237. – Article 121456.

9. Graph Neural Networks for Malware Detection: A Survey / Y. Zhu et al // IEEE Access. – 2023. – Т. 11. – Р. 85123-85147.

10. Ding Y. Ontology-based knowledge representation for malware individuals and families / Y. Ding, R. Wu, X. Xiao // Computers & Security. – 2019. – Vol. 87. – Art. 101574. https://doi.org/10.1016/j.cose.2019.101574.

11. Deldar F. Deep Learning for Zero-day Malware Detection and Classification: A Survey / F. Deldar, M. Abadi // ACM Computing Surveys. – 2023. – Vol. 56, № 2. – P. 1-37. https://doi.org/10.1145/3605775.

12. ScaleMalNet: A Scalable Hybrid Deep Learning Model for Malware Classification / R. Vinayakumar et al // Future Generation Computer Systems. – 2020. – Т. 115. – P. 280-292.

13. Alshoulie M. Deep Learning Approaches for Malware Detection: A Comprehensive Review of Techniques, Challenges, and Future Directions / M. Alshoulie, A. Mehmood // IEEE Access. – 2025. – Т. 13. – P. 118652-118677. https://doi.org/10.1109/ACCESS.2025.3582875.

14. Machine learning based fileless malware traffic classification using image visualization / F.A. Demmese et al // Cybersecurity. – 2023. – Т. 6, № 1. – Art. 32. https://doi.org/10.1186/s42400-023-00170-z.

15. A framework for detecting zero-day exploits in network flows / A. Touré et al // Computer Networks. – 2024. – Vol. 224. – Art. 110476. https://doi.org/10.1016/j.comnet.2024.110476.

16. Grad-CAM: Visual Explanations from Deep Networks via Gradient-Based Localization / R.R. Selvaraju et al // Proceedings of the IEEE International Conference on Computer Vision (ICCV). – 2017. – P. 618-626. https://doi.org/10.1109/ICCV.2017.74. https://doi.org/10.48550/arXiv.1610.02391

17. GNNExplainer: Generating Explanations for Graph Neural Networks / R. Ying et al // Advances in Neural Information Processing Systems (NeurIPS). – 2019. – Vol. 32. – P. 9240-9251. https://doi.org/10.48550/arXiv.1903.03894.

18. Abduraimova B. Comparative study of machine learning applications in malware forensics / B. Abduraimova, S. Gnatyuk, A. Nurmukhanbetova // Proceedings of the Workshop on Cybersecurity Providing in Information and Telecommunication Systems II (CPITS-II 2024). – Kyiv, Ukraine, October 26, 2024. – CEUR Workshop Proceedings, Vol. 3826. – P. 139-152. https://ceur-ws.org/Vol3826/paper13.pdf (date of request: 03.11.2025).

19. AlOmari H. A comparative analysis of machine learning algorithms for Android malware detection / H. AlOmari, Q.M. Yaseen, M.A. Al-Betar // Procedia Computer Science. – 2023. – Vol. 220. – P. 763-768. https://doi.org/10.1016/j.procs.2023.03.101.

20. Analyzing and comparing the effectiveness of malware detection: A study of machine learning approaches / M. Azeem et al // Heliyon Computer Science. – 2024. – Vol. 10, № 1. – Art. e24058. https://www.sciencedirect.com/science/article/pii/S2405844023107821.

21. A robust machine learning-based mechanism for malware attack detection and analysis / R. Bakshi et al // Procedia Computer Science. – 2025. – Vol. 242. – P. 876-885. https://www.sciencedirect.com/science/article/pii/S1877050925010646.

22. Efficient malware detection using NLP and deep learning model / U. Gupta et al // Alexandria Engineering Journal. – 2025. – Vol. 124. – P. 550-564. https://www.sciencedirect.com/science/article/pii/S1110016825004260.


Review

For citations:


Abduraimova B.K., Nurmukhanbetova A.E. INTELLIGENT DEEP LEARNING-BASED HYBRID MODELS FOR MALWARE DETECTION IN THE ICT ENVIRONMENT. Bulletin of Shakarim University. Technical Sciences. 2026;1(1(21)):64-73. (In Kazakh) https://doi.org/10.53360/2788-7995-2026-1(21)-7

Views: 140

JATS XML


Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.


ISSN 2788-7995 (Print)
ISSN 3006-0524 (Online)
X