Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

A Feature-Based Machine Learning Ensemble Model for Enhanced Malware Detection in Digital Banking Security

Princewill, Jennifer Ibimina1, N. D. Nwiabu2 and O. E. Taylor3

Abstract

The rapid expansion of digital banking has introduced significant cybersecurity vulnerabilities, particularly from sophisticated malware threats that exploit polymorphic and zero-day evasion techniques. Traditional signature-based defenses demonstrate critical inadequacy in detecting novel threats, creating exploitable security gaps that threaten financial integrity and customer trust. This research addresses these challenges by developing and validating a high- performance, feature-based malware detection framework specifically tailored for digital banking security. The primary objectives are to develop an optimized Machine Learning ensemble algorithm for robust static malware classification, implement a feature-based approach utilizing Portable Executable (PE) file analysis, integrate Explainable AI techniques for model transparency, and rigorously evaluate performance using standard metrics. The research employs Object-Oriented Analysis and Design alongside a quantitative experimental methodology, utilizing the EMBER dataset of Windows PE files. Static features including header information, section entropy, and import table characteristics were extracted and optimized using Recursive Feature Elimination with Cross-Validation , reducing the feature space to 11 critical attributes. The proposed RF-XGBoost Ensemble Model was implemented using Python and compared against benchmark classifiers including Support Vector Machine, K-Nearest Neighbors, and Logistic Regression. The experimental results demonstrate exceptional performance: the RF-XGBoost Ensemble achieved an accuracy of 96.16% and an F1-score of 96.20%, significantly outperforming the weakest benchmark (Logistic Regression at 67.89% accuracy). Critically, the ensemble model achieved a False Negative rate of only 2.34% with just 10 missed threats, compared to 41 for SVM and 92 for Logistic Regression, demonstrating superior security robustness. The near-perfect AUC-ROC of 99.87% confirms excellent discriminatory power. Feature importance analysis identified general_size, section_127, and header_0 as the most influential PE attributes, providing security analysts with clear, actionable insights for threat mitigation and regulatory compliance. This research delivers substantial contributions to both cybersecurity and digital banking domains by establishing a new standard for robust, interpretable, and operationally efficient malware detection, effectively addressing the "black box" problem while maintaining high accuracy with minimal computational overhead suitable for real-time deployment.

References

[1] Zhu, X., & Chen, Y. (2020). Digital banking transformation: Opportunities and challenges. Journal of Financial Services Research, 58(2), 101–120. [2] Daniel, E. (1999). Provision of electronic banking in the UK and the Republic of Ireland. International Journal of Bank Marketing, 17(2), 72–82. [3] United Nations, Department of Economic and Social Affairs, Population Division. (2018). World urbanization prospects: The 2018 revision, key facts. [4] Akhter, S. (2014). Security issues in digital banking: Challenges and solutions. Journal of Internet Banking and Commerce, 19(3), 1–15. [5] Ojha, R. P., & Pandey, S. K. (2017). Cybersecurity challenges in digital banking: Threats and countermeasures. International Journal of Advanced Research in Computer Science, 8(5), 123–130. [6] Kaspersky. (2024). Financial Cyberthreats Report 2024: 3.6 times surge in mobile banking malware and 83% crypto phishing spike. Kaspersky Securelist. [7] Yadav, S., & Nath, A. (2016). Malware detection in banking systems: Challenges and solutions. International Journal of Computer Applications, 145(7), 34–40. [8] Chavan, J. (2013). Internet banking: Benefits and challenges in an emerging economy. International Journal of Research in Business Management, 1(1), 19–26. [9] Rana, N. P., Dwivedi, Y. K., & Williams, M. D. (2019). Open banking and its impact on financial services: A review. International Journal of Information Management, 48, 100–110. [10] Chakrabarty, N., Gupta, S., & Biswas, S. (2018). AI-driven malware detection in financial systems. Journal of Network Security, 20(4), 678–690. [11] Singh, A., Singh, R., & Tewari, R. (2022). Hybrid machine learning models for malware detection: A comprehensive study. IEEE Transactions on Information Forensics and Security, 17, 1234–1247. [12] Kim, D., & Solomon, M. G. (2016). Fundamentals of information systems security (3rd ed.). Jones & Bartlett Learning. [13] Kumar, A., & Singh, P. (2021). Machine learning approaches for malware detection. Journal of Computer Security, 28(4), 445–462. [14] Ucci, D., Aniello, L., & Baldoni, R. (2019). Survey of machine learning techniques for malware analysis. Computers & Security, 81, 123–147. [15] Kolbitsch, C., Comparetti, P. M., Kruegel, C., Kirda, E., Zhou, X., & Wang, X. (2009). Effective and efficient malware detection at the end host. Proceedings of the 18th USENIX Security Symposium, 351–366. [16] Albishry, N., AlGhamdi, R., Almalawi, A., Khan, A. I., Kshirsagar, P. R., & Debtera, B. (2022). An attribute extraction for automated malware attack classification and detection using soft computing techniques. Computational Intelligence and Neuroscience, 2022, Article 5061059. [17] Anderson, H. S., & Pirozzo, M. (2020). Leveraging stable PE features for efficient malware detection. Proceedings of the 2020 IEEE Symposium on Security and Privacy, 456–470. [18] Gibert, D., Mateu, C., Planes, J., & Vicens, R. (2019). Using convolutional neural networks for classification of malware represented as images. Journal of Computer Virology and Hacking Techniques, 15(1), 15–28. [19] Huang, J., Li, Y., & Deng, Y. (2019). Recurrent neural networks for dynamic malware analysis. IEEE Transactions on Information Forensics and Security, 14(6), 1490–1502. [20] Demetrio, L., Biggio, B., Lagorio, G., Roli, F., & Armando, A. (2021). Explaining vulnerabilities of deep learning to adversarial malware binaries. International Journal of Machine Learning and Cybernetics, 12(3), 721–734. [21] Abawajy, J., Darem, A., & Alhashmi, A. A. (2020). Feature selection for malware detection based on deep autoencoders. International Journal of Advanced Computer Science and Applications, 11(8), 123–130. [22] Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5–32. [23] Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 785–794.

More Articles from INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND MATHEMATICAL THEORY

Advances in Algorithmic Contract Scoring for Pre-Negotiation Yield Optimization and Risk Retention

Author: Ngozi Samuel Uzougbo, Michael Ominyi, Cyril Chimelie Anichukwueze, Blessing, Chika Jones

DevTest flow: Designing a Scalable Continuous Testing Pipeline for High-Velocity Software Delivery

Author: Lawal Ahmed Oladimeji, Achori Busayo, Akeju BusayoZainab, Saka Samson, Damilare, Mbah Demian Chidi, Runsewe Similoluwa Mayowa, Oladiti Luqman, Abiodun