Integrating Information Gain and Chi-Square for Enhanced Malware Detection Performance
DOI:
https://doi.org/10.32890/jict2025.24.1.4Keywords:
Malware detection, IGCS, feature selection, Information Gain, Chi-SquareAbstract
Malware represents a serious and continuously evolving threat in the modern digital environment. Detecting malware is essential to safeguard devices and systems from risks such as data corruption, data theft, account compromises, and unauthorized access that could result in total system takeover. As malware has progressed from its simpler, monomorphic variants to more sophisticated forms like oligomorphic, polymorphic, and metamorphic, a machine learning-based detection system is now required, surpassing the limitations of traditional signature-based methods. Recent studies have shown that this challenge can be addressed by employing machine learning algorithms for detection. Some studies have also implemented various feature selection methods to optimize detection efficiency. However, they continue to struggle with false positives and false negatives, striving to reach zero tolerance in malware detection. This study introduces the IGCS method, a combined feature selection approach that integrates Information Gain with Chi-Square (X²) to enhance both the effectiveness and efficiency of machine learning classifiers. Using IGCS, six classifiers—Random Forest, XGBoost, kNN, Decision Tree, Logistic Regression, and Naïve Bayes—achieved higher performance scores compared to other scenarios, such as when classifiers were combined with Information Gain, Chi-Square, PCA, or even without any feature selection. As a result, Random Forest with 30 features selected by IGCS proved superior to any combination of classifiers and feature selection methods in malware detection, achieving 99.0% accuracy, recall, precision, and F1-Score. This combination also demonstrated efficiency with a 52.5% decrease in training time and a 56.9% decrease in testing time.
References
Abujazoh, M., Al-Darras, D., A. Hamad, N., & Al-Sharaeh, S. (2023). Feature selection for high-dimensional imbalanced malware data using filter and wrapper selection methods. 2023 International Conference on Information Technology (ICIT), 196–201. https://doi.org/10.1109/ICIT58056.2023.10226049
Aslan, O., & Samet, R. (2020). A comprehensive review on malware detection approaches. IEEE Access, 8, 6249–6271. https://doi.org/10.1109/ACCESS.2019.2963724
Bao, H., Li, W., Chen, H., Miao, H., Wang, Q., Tang, Z., Liu, F., & Wang, W. (2024). Stories behind decisions: Towards interpretable malware family classification with hierarchical attention. Computers & Security, 144, 103943. https://doi.org/10.1016/j.cose.2024.103943
Battineni, G., Sagaro, G. G., Nalini, C., Amenta, F., & Tayebati, S. K. (2019). Comparative machine-learning approach: A follow-up study on type 2 diabetes predictions by cross-validation methods. Machines, 7(4), 74. https://doi.org/10.3390/machines7040074
Dabas, N., Ahlawat, P., & Sharma, P. (2023). An effective malware detection method using hybrid feature selection and machine learning algorithms. Arabian Journal for Science and Engineering, 48(8), 9749–9767. https://doi.org/10.1007/s13369-022-07309-z
Dissanayake, S., Gunathunga, S., Jayanetti, D., Perera, K., Liyanapathirana, C., & Rupasinghe, L. (2022). An analysis on different distance measures in KNN with PCA for Android malware detection. 2022 22nd International Conference on Advances in ICT for Emerging Regions (ICTer), 178–182. https://doi.org/10.1109/ICTer58063.2022.10024079
Fan, Q., Wang, Z., Li, D., Gao, D., & Zha, H. (2017). Entropy-based fuzzy support vector machine for imbalanced datasets. Knowledge-Based Systems, 115, 87–99. https://doi.org/10.1016/j. knosys.2016.09.032
Hossain, Md. A., Haque, M. A., Ahmad, S., Abdeljaber, H. A. M., Eljialy, A. E. M., Alanazi, A., Sonal, D., Chaudhary, K., & Nazeer, J. (2024). AI-enabled approach for enhancing obfuscated malware detection: A hybrid ensemble learning with combined feature selection techniques. International Journal of System Assurance Engineering and Management. https://doi.org/10.1007/s13198-024-02294-y
Kale, G., Bostancı, G. E., & Çelebi, F. V. (2024). Evolutionary feature selection for machine learning based malware classification. Engineering Science and Technology, an International Journal, 56, 101762. https://doi.org/10.1016/j.jestch.2024.101762
Keshkeh, K., Jantan, A., & Alieyan, K. (2022). A machine learning classification approach to detect tls-based malware using entropy-based flow set features. Journal of Information and Communication Technology, 21. https://doi.org/10.32890/jict2022.21.3.1
Kurniabudi, Stiawan, D., Darmawijoyo, Bin Idris, M. Y., Bamhdi, A. M., & Budiarto, R. (2020). CICIDS-2017 dataset feature analysis with information gain for anomaly detection. IEEE Access, 8, 132911–132921. https://doi.org/10.1109/ACCESS.2020.3009843
Liu, J., Xiao, Q., Xin, L., Wang, Q., Yao, Y., & Jiang, Z. (2023). M3F: A novel multi-session and multi-protocol based malware traffic fingerprinting. Computer Networks, 227, 109723. https://doi.org/10.1016/j.comnet.2023.109723
Lu, J., Ren, X., Zhang, J., & Wang, T. (2023). CPL-Net: A malware detection network based on parallel CNN and LSTM feature fusion. Electronics, 12(19), 4025. https://doi.org/10.3390/ electronics12194025
Malware static and dynamic features VxHeaven and Virus Total. (2019). [Dataset]. UCI Machine Learning Repository. https://doi.org/10.24432/C58K6H
Omuya, E. O., Okeyo, G. O., & Kimwele, M. W. (2021). Feature selection for classification using principal component analysis and information gain. Expert Systems with Applications, 174, 114765. https://doi.org/10.1016/j.eswa.2021.114765
Orrù, G., Monaro, M., Conversano, C., Gemignani, A., & Sartori, G. (2020). Machine learning in psychometrics and psychological research. Frontiers in Psychology, 10, 2970. https://doi.org/10.3389/fpsyg.2019.02970
Pandey, A., & Jain, A. (2017). Comparative analysis of KNN algorithm using various normalization techniques. International Journal of Computer Network and Information Security, 9(11), 36–42. https://doi.org/10.5815/ijcnis.2017.11.04
Rafrastara, F. A., Supriyanto, C., Amiral, A., Amalia, S. R., Fahreza, M. D. A., & Ahmed, F. (2024). Performance comparison of k-Nearest Neighbour algorithm with various k values and distance metrics for malware detection. Jurnal Media Informatika Budidarma, 8, 450-458.
Rafrastara, F. A., Supriyanto, C., Paramita, C., Astuti, Y. P., & Ahmed, F. (2023). Performance improvement of random forest algorithm for malware detection on imbalanced dataset using random under-sampling method. Jurnal Informatika: Jurnal Pengembangan IT, 8(2), 113–118. https://doi.org/10.30591/jpit.v8i2.5207
Rasheed, A. F., Zarkoosh, M., & Al-Azzawi, S. S. (2023). The impact of feature selection on malware classification using Chi-square and machine learning. 2023 9th International Conference on Computer and Communication Engineering (ICCCE), 211–216. https://doi.org/10.1109/ ICCCE58854.2023.10246084
Root, S. J., Throckmorton, P., Tacke, J., Benjamin, J., Haney, M., & Borrelli, R. A. (2023). Cyber hardening of nuclear power plants with real-time nuclear reactor operation, 1. Preliminary operational testing. Progress in Nuclear Energy, 162, 104742. https://doi.org/10.1016/ j.pnucene.2023.104742
Sachdeva, S., Bhatia, S., Al Harrasi, A., Shah, Y. A., Anwer, Md. K., Philip, A. K., Shah, S. F. A., Khan, A., & Ahsan Halim, S. (2024). Unraveling the role of cloud computing in health care system and biomedical sciences. Heliyon, 10(7), e29044. https://doi.org/10.1016/j.heliyon. 2024.e29044
Shahid, N., Aziz-ur Rehman, M., Khalid, A., Fatima, U., Sumbal Shaikh, T., Ahmed, N., Alotaibi, H., Rafiq, M., Khan, I., & Sooppy Nisar, K. (2021). Mathematical analysis and numerical investigation of advection-reaction-diffusion computer virus model. Results in Physics, 26, 104294. https://doi.org/10.1016/j.rinp.2021.104294
Singh, D., & Singh, B. (2020). Investigating the impact of data normalization on classification performance. Applied Soft Computing, 97, 105524. https://doi.org/10.1016/j.asoc.2019.105524
Supriyanto, C., Rafrastara, F. A., Amiral, A., Amalia, S. R., Daffa, M., & Fahreza, A. (2024). Malware detection using K-nearest neighbour algorithm and feature selection. Jurnal Media Informatika Budidarma, 8(1), 412-420
Teodorescu, C. A. (2022). Perspectives and reviews in the development and evolution of the zero-day attacks. Informatica Economica, 26(2/2022), 46–56. https://doi.org/10.24818/issn14531305/ 26.2.2022.05
Vostoupal, J. (2024). Stuxnet vs WannaCry and Albania: Cyber-attribution on trial. Computer Law & Security Review, 54, 106008. https://doi.org/10.1016/j.clsr.2024.106008
Wang, H., Cui, B., Yuan, Q., Shi, R., & Huang, M. (2024). A review of deep learning based malware detection techniques. Neurocomputing, 598, 128010. https://doi.org/10.1016/j.neucom. 2024.128010
Warwicker, J. A., & Rebennack, S. (2024). Support vector machines within a bivariate mixed-integer linear programming framework. Expert Systems with Applications, 245, 122998. https://doi.org/10.1016/j.eswa.2023.122998
Yan, C., & Razmjooy, N. (2023). Optimal lung cancer detection based on CNN optimized and improved snake optimization algorithm. Biomedical Signal Processing and Control, 86, 105319. https://doi.org/10.1016/j.bspc.2023.105319
Yang, F., Xu, Z., Wang, H., Sun, L., Zhai, M., & Zhang, J. (2024). A hybrid feature selection algorithm combining information gain and grouping particle swarm optimization for cancer diagnosis. PLOS ONE, 19(3), e0290332. https://doi.org/10.1371/journal.pone.0290332
Yin, Y., Jang-Jaccard, J., Xu, W., Singh, A., Zhu, J., Sabrina, F., & Kwak, J. (2023). IGRF-RFE: A hybrid feature selection method for MLP-based network intrusion detection on UNSW-NB15 dataset. Journal of Big Data, 10(1), 15. https://doi.org/10.1186/s40537-023-00694-8
Zhao, Z., Yang, S., & Zhao, D. (2023). A new framework for visual classification of multi-channel malware based on transfer learning. Applied Sciences, 13(4), 2484. https://doi.org/10.3390/ app13042484
Published
Issue
Section
License
Copyright (c) 2025 Journal of Information and Communication Technology

This work is licensed under a Creative Commons Attribution 4.0 International License.
How to Cite
Research impact
Harvested 2026-09-05Counts differ between services because each indexes a different body of literature. None of them is the whole picture.
2002 - 2020






















