Integrating Information Gain and Chi-Square for Enhanced Malware Detection Performance

Authors

  • Fauzi Adi Rafrastara Faculty of Computer Science, Universitas Dian Nuswantoro, Indonesia
  • Wildanil Ghozi Faculty of Computer Science, Universitas Dian Nuswantoro, Indonesia
  • Ramadhan Rakhmat Sani Faculty of Computer Science, Universitas Dian Nuswantoro, Indonesia
  • Abdussalam Abdussalam Faculty of Computer Science, Universitas Dian Nuswantoro, Indonesia
  • Elkaf Rahmawan Pramudya Faculty of Computer Science, Universitas Dian Nuswantoro, Indonesia
  • Faizal M. Abdollah Fakulti Teknologi Maklumat dan Komunikasi, Universiti Teknikal Malaysia Melaka, Malaysia

DOI:

https://doi.org/10.32890/jict2025.24.1.4

Keywords:

Malware detection, IGCS, feature selection, Information Gain, Chi-Square

Abstract

Malware represents a serious and continuously evolving threat in the modern digital environment. Detecting malware is essential to safeguard devices and systems from risks such as data corruption, data theft, account compromises, and unauthorized access that could result in total system takeover. As malware has progressed from its simpler, monomorphic variants to more sophisticated forms like oligomorphic, polymorphic, and metamorphic, a machine learning-based detection system is now required, surpassing the limitations of traditional signature-based methods. Recent studies have shown that this challenge can be addressed by employing machine learning algorithms for detection. Some studies have also implemented various feature selection methods to optimize detection efficiency. However, they continue to struggle with false positives and false negatives, striving to reach zero tolerance in malware detection. This study introduces the IGCS method, a combined feature selection approach that integrates Information Gain with Chi-Square (X²) to enhance both the effectiveness and efficiency of machine learning classifiers. Using IGCS, six classifiers—Random Forest, XGBoost, kNN, Decision Tree, Logistic Regression, and Naïve Bayes—achieved higher performance scores compared to other scenarios, such as when classifiers were combined with Information Gain, Chi-Square, PCA, or even without any feature selection. As a result, Random Forest with 30 features selected by IGCS proved superior to any combination of classifiers and feature selection methods in malware detection, achieving 99.0% accuracy, recall, precision, and F1-Score. This combination also demonstrated efficiency with a 52.5% decrease in training time and a 56.9% decrease in testing time.

References

Abujazoh, M., Al-Darras, D., A. Hamad, N., & Al-Sharaeh, S. (2023). Feature selection for high-dimensional imbalanced malware data using filter and wrapper selection methods. 2023 International Conference on Information Technology (ICIT), 196–201. https://doi.org/10.1109/ICIT58056.2023.10226049

Aslan, O., & Samet, R. (2020). A comprehensive review on malware detection approaches. IEEE Access, 8, 6249–6271. https://doi.org/10.1109/ACCESS.2019.2963724

Bao, H., Li, W., Chen, H., Miao, H., Wang, Q., Tang, Z., Liu, F., & Wang, W. (2024). Stories behind decisions: Towards interpretable malware family classification with hierarchical attention. Computers & Security, 144, 103943. https://doi.org/10.1016/j.cose.2024.103943

Battineni, G., Sagaro, G. G., Nalini, C., Amenta, F., & Tayebati, S. K. (2019). Comparative machine-learning approach: A follow-up study on type 2 diabetes predictions by cross-validation methods. Machines, 7(4), 74. https://doi.org/10.3390/machines7040074

Dabas, N., Ahlawat, P., & Sharma, P. (2023). An effective malware detection method using hybrid feature selection and machine learning algorithms. Arabian Journal for Science and Engineering, 48(8), 9749–9767. https://doi.org/10.1007/s13369-022-07309-z

Dissanayake, S., Gunathunga, S., Jayanetti, D., Perera, K., Liyanapathirana, C., & Rupasinghe, L. (2022). An analysis on different distance measures in KNN with PCA for Android malware detection. 2022 22nd International Conference on Advances in ICT for Emerging Regions (ICTer), 178–182. https://doi.org/10.1109/ICTer58063.2022.10024079

Fan, Q., Wang, Z., Li, D., Gao, D., & Zha, H. (2017). Entropy-based fuzzy support vector machine for imbalanced datasets. Knowledge-Based Systems, 115, 87–99. https://doi.org/10.1016/j. knosys.2016.09.032

Hossain, Md. A., Haque, M. A., Ahmad, S., Abdeljaber, H. A. M., Eljialy, A. E. M., Alanazi, A., Sonal, D., Chaudhary, K., & Nazeer, J. (2024). AI-enabled approach for enhancing obfuscated malware detection: A hybrid ensemble learning with combined feature selection techniques. International Journal of System Assurance Engineering and Management. https://doi.org/10.1007/s13198-024-02294-y

Kale, G., Bostancı, G. E., & Çelebi, F. V. (2024). Evolutionary feature selection for machine learning based malware classification. Engineering Science and Technology, an International Journal, 56, 101762. https://doi.org/10.1016/j.jestch.2024.101762

Keshkeh, K., Jantan, A., & Alieyan, K. (2022). A machine learning classification approach to detect tls-based malware using entropy-based flow set features. Journal of Information and Communication Technology, 21. https://doi.org/10.32890/jict2022.21.3.1

Kurniabudi, Stiawan, D., Darmawijoyo, Bin Idris, M. Y., Bamhdi, A. M., & Budiarto, R. (2020). CICIDS-2017 dataset feature analysis with information gain for anomaly detection. IEEE Access, 8, 132911–132921. https://doi.org/10.1109/ACCESS.2020.3009843

Liu, J., Xiao, Q., Xin, L., Wang, Q., Yao, Y., & Jiang, Z. (2023). M3F: A novel multi-session and multi-protocol based malware traffic fingerprinting. Computer Networks, 227, 109723. https://doi.org/10.1016/j.comnet.2023.109723

Lu, J., Ren, X., Zhang, J., & Wang, T. (2023). CPL-Net: A malware detection network based on parallel CNN and LSTM feature fusion. Electronics, 12(19), 4025. https://doi.org/10.3390/ electronics12194025

Malware static and dynamic features VxHeaven and Virus Total. (2019). [Dataset]. UCI Machine Learning Repository. https://doi.org/10.24432/C58K6H

Omuya, E. O., Okeyo, G. O., & Kimwele, M. W. (2021). Feature selection for classification using principal component analysis and information gain. Expert Systems with Applications, 174, 114765. https://doi.org/10.1016/j.eswa.2021.114765

Orrù, G., Monaro, M., Conversano, C., Gemignani, A., & Sartori, G. (2020). Machine learning in psychometrics and psychological research. Frontiers in Psychology, 10, 2970. https://doi.org/10.3389/fpsyg.2019.02970

Pandey, A., & Jain, A. (2017). Comparative analysis of KNN algorithm using various normalization techniques. International Journal of Computer Network and Information Security, 9(11), 36–42. https://doi.org/10.5815/ijcnis.2017.11.04

Rafrastara, F. A., Supriyanto, C., Amiral, A., Amalia, S. R., Fahreza, M. D. A., & Ahmed, F. (2024). Performance comparison of k-Nearest Neighbour algorithm with various k values and distance metrics for malware detection. Jurnal Media Informatika Budidarma, 8, 450-458.

Rafrastara, F. A., Supriyanto, C., Paramita, C., Astuti, Y. P., & Ahmed, F. (2023). Performance improvement of random forest algorithm for malware detection on imbalanced dataset using random under-sampling method. Jurnal Informatika: Jurnal Pengembangan IT, 8(2), 113–118. https://doi.org/10.30591/jpit.v8i2.5207

Rasheed, A. F., Zarkoosh, M., & Al-Azzawi, S. S. (2023). The impact of feature selection on malware classification using Chi-square and machine learning. 2023 9th International Conference on Computer and Communication Engineering (ICCCE), 211–216. https://doi.org/10.1109/ ICCCE58854.2023.10246084

Root, S. J., Throckmorton, P., Tacke, J., Benjamin, J., Haney, M., & Borrelli, R. A. (2023). Cyber hardening of nuclear power plants with real-time nuclear reactor operation, 1. Preliminary operational testing. Progress in Nuclear Energy, 162, 104742. https://doi.org/10.1016/ j.pnucene.2023.104742

Sachdeva, S., Bhatia, S., Al Harrasi, A., Shah, Y. A., Anwer, Md. K., Philip, A. K., Shah, S. F. A., Khan, A., & Ahsan Halim, S. (2024). Unraveling the role of cloud computing in health care system and biomedical sciences. Heliyon, 10(7), e29044. https://doi.org/10.1016/j.heliyon. 2024.e29044

Shahid, N., Aziz-ur Rehman, M., Khalid, A., Fatima, U., Sumbal Shaikh, T., Ahmed, N., Alotaibi, H., Rafiq, M., Khan, I., & Sooppy Nisar, K. (2021). Mathematical analysis and numerical investigation of advection-reaction-diffusion computer virus model. Results in Physics, 26, 104294. https://doi.org/10.1016/j.rinp.2021.104294

Singh, D., & Singh, B. (2020). Investigating the impact of data normalization on classification performance. Applied Soft Computing, 97, 105524. https://doi.org/10.1016/j.asoc.2019.105524

Supriyanto, C., Rafrastara, F. A., Amiral, A., Amalia, S. R., Daffa, M., & Fahreza, A. (2024). Malware detection using K-nearest neighbour algorithm and feature selection. Jurnal Media Informatika Budidarma, 8(1), 412-420

Teodorescu, C. A. (2022). Perspectives and reviews in the development and evolution of the zero-day attacks. Informatica Economica, 26(2/2022), 46–56. https://doi.org/10.24818/issn14531305/ 26.2.2022.05

Vostoupal, J. (2024). Stuxnet vs WannaCry and Albania: Cyber-attribution on trial. Computer Law & Security Review, 54, 106008. https://doi.org/10.1016/j.clsr.2024.106008

Wang, H., Cui, B., Yuan, Q., Shi, R., & Huang, M. (2024). A review of deep learning based malware detection techniques. Neurocomputing, 598, 128010. https://doi.org/10.1016/j.neucom. 2024.128010

Warwicker, J. A., & Rebennack, S. (2024). Support vector machines within a bivariate mixed-integer linear programming framework. Expert Systems with Applications, 245, 122998. https://doi.org/10.1016/j.eswa.2023.122998

Yan, C., & Razmjooy, N. (2023). Optimal lung cancer detection based on CNN optimized and improved snake optimization algorithm. Biomedical Signal Processing and Control, 86, 105319. https://doi.org/10.1016/j.bspc.2023.105319

Yang, F., Xu, Z., Wang, H., Sun, L., Zhai, M., & Zhang, J. (2024). A hybrid feature selection algorithm combining information gain and grouping particle swarm optimization for cancer diagnosis. PLOS ONE, 19(3), e0290332. https://doi.org/10.1371/journal.pone.0290332

Yin, Y., Jang-Jaccard, J., Xu, W., Singh, A., Zhu, J., Sabrina, F., & Kwak, J. (2023). IGRF-RFE: A hybrid feature selection method for MLP-based network intrusion detection on UNSW-NB15 dataset. Journal of Big Data, 10(1), 15. https://doi.org/10.1186/s40537-023-00694-8

Zhao, Z., Yang, S., & Zhao, D. (2023). A new framework for visual classification of multi-channel malware based on transfer learning. Applied Sciences, 13(4), 2484. https://doi.org/10.3390/ app13042484

Downloads

Published

28-01-2025

How to Cite

Rafrastara, F. A., Ghozi, W., Sani, R. R., Abdussalam, A., Pramudya, E. R., & Abdollah, F. M. (2025). Integrating Information Gain and Chi-Square for Enhanced Malware Detection Performance. Journal of Information and Communication Technology, 24(1), 79-101. https://doi.org/10.32890/jict2025.24.1.4

Research impact

Harvested 2026-09-05
3 citations, from OpenAlex — the highest of the sources checked

Counts differ between services because each indexes a different body of literature. None of them is the whole picture.

Identifiers DOI 10.32890/jict2025.24.1.4 OpenAlex W4406891825 Scopus 85217463901