AI-Based Malware Behavior Classification and Mitigation System Using Machine Learning

Authors

  • Sivaharish R.
  • Sharmila K.
  • Lediyal S.
  • Suriya M.

DOI:

https://doi.org/10.46610/RRMLCC.2026.v05i03.003

Keywords:

Behavior-based detection, Cybersecurity, Machine learning, Malware classification, Threat mitigation, Windows security

Abstract

The continuous evolution and technical sophistication of modern cyber threats present severe challenges to enterprise networks, endpoint devices, and personal data privacy. Conventional security measures that rely predominantly on static file signatures and hardcoded indicators of compromise frequently fail against advanced polymorphic, packed, and fileless malware strains that dynamically alter their binary structures upon replication. To overcome these critical defensive limitations, this study proposes an advanced, integrated behavior-based malware classification and automated mitigation framework specifically engineered for Windows operating environments. Instead of examining static file hashes on disk prior to execution, the proposed system captures and analyzes high-velocity, multi-variable runtime telemetry in real time. This comprehensive telemetry monitoring encompasses low-level process creation paths, parent-child execution hierarchies, CPU and memory resource utilization percentages, file system modification counts, active network socket connections, and system event triggers. These dynamic behavioral attributes are processed through optimized supervised machine learning algorithms, specifically Decision Trees, Random Forests, Support Vector Machines, and Logistic Regression, to accurately classify software execution patterns as benign or malicious while predicting specific threat types. Furthermore, the framework introduces a multi-class risk-scoring mechanism (categorizing threats into Low, Medium, High, and Critical tiers) to streamline Security Operations Center (SOC) incident triage. Upon identifying malicious behavior exceeding predefined risk thresholds, an automated mitigation pipeline initiates immediate defensive protocols, including real-time security alerts and the instantaneous termination of hazardous processes. All monitored telemetry streams, classification outputs, risk evaluations, and mitigation actions are dynamically rendered through a responsive, interactive React.js web dashboard. Comprehensive experimental benchmarking reveals that the Random Forest model achieves the highest classification accuracy at 89.2%, outperforming alternative algorithms and demonstrating strong efficacy for proactive endpoint protection and automated threat containment.

References

M. S. Akhtar and T. Feng, “Malware Analysis and Detection Using Machine Learning Algorithms,” Symmetry, vol. 14, no. 11, Nov. 2022.

H. Alqahtani, I. H. Sarker, A. Kalim, S. Md. Minhaz Hossain, S. Ikhlaq, and S. Hossain, “Cyber Intrusion Detection Using Machine Learning Classification Techniques,” Communications in Computer and Information Science, vol. 1235, pp. 121–131, 2020.

A. Bensaoud, J. Kalita, and B. Mahmoud, “A Survey of Malware Detection Using Deep Learning,” Machine Learning with Applications, vol. 16, p. 100546, Jun. 2024.

R. D, A. T, and T. M, “Malware Classification Using Machine Learning and Deep Learning: A Comprehensive Approach,” Cureus Journal of Computer Science, Jul. 2025.

B. P. Gond, A. K. Singh, and D. P. Mohapatra, “A Deep Learning Framework for Malware Classification Using NLP Techniques,” in 2024 15th International Conference on Computing Communication and Networking Technologies (ICCCNT), IEEE, Jun. 2024, pp. 1–8.

Y. Cao, A. Yang, H. Li, Q. Zeng, and J. Gao, “A Comprehensive Knowledge Map for AI Improving Security Management of Cyber-Physical System Enabled Smart Manufacturing,” Computers & Security, vol. 137, pp. 103650–103650, Feb. 2024.

A. L. Buczak and E. Guven, “A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection,” IEEE Communications Surveys & Tutorials, vol. 18, no. 2, pp. 1153–1176, 2016.

J. Saxe and H. Sanders, “Malware Data Science,” Nostarch.com. Sep. 2026.

R. Islam, R. Tian, L. M. Batten, and S. Versteeg, “Classification of Malware Based on Integrated Static and Dynamic Features,” Journal of Network and Computer Applications, vol. 36, no. 2, pp. 646–656, Mar. 2013.

E. Gandotra, D. Bansal, and S. Sofat, “Malware Analysis and Classification: A Survey,” Journal of Information Security, vol. 05, no. 02, pp. 56–64, 2014.

Published

2026-10-03

Issue

Section

Articles