A Unified Machine Learning-Based IDS/IPS Framework with Bio-Inspired Feature Selection for Real-Time Detection of Malware-Laden URLs

Authors

  • Mohammad Sh. Daoud College of Engineering, Al Ain University, Abu Dhabi, United Arab Emirates
  • Mosleh M. Abualhaj Department of Networks and Cybersecurity, Al-Ahliyya Amman University, Amman, Jordan
  • Sumaya S. Al-Khatib Department of Computer Science, Al-Ahliyya Amman University, Amman, Jordan
  • Mahran Al-Zyoud Department of Networks and Cybersecurity, Al-Ahliyya Amman University, Amman, Jordan
  • Ahmad Abu-Shareha Department of Data Science and Artificial Intelligence, Al-Ahliyya Amman University, Amman, Jordan
  • Hussain Al-Aqrabi Higher College of Technology, Sharjah, United Arab Emirates
  • Mohammad A. Alsharaiah Department of Information Technology, King Abdullah II School of Information, Jordan
  • Mohamad Anbar Cybersecurity Research Center (CYRES), Universiti Sains Malaysia, Malaysia

DOI:

https://doi.org/10.32890/jict2026.25.3.1

Keywords:

Bat algorithm, feature selection, Harris Hawks Optimization, intrusion detection prevention systems, machine learning

Abstract

Cybersecurity threats have become increasingly sophisticated and dynamic due to the rapid evolution of malicious software and attack techniques. However, the reliance of traditional IDS/IPS implementations on signature-based detection limits their ability to identify novel, rapidly evolving, and adaptive malware, despite their effectiveness against known cyber threats. This paper presents a unified machine-learning framework for defence against malware-laden URLs, which simultaneously targets intrusion detection (accuracy first, out of band) and intrusion prevention (latency first, inline) through module-aware, bio-inspired feature selection. The detection module employs random forest (RF) with the bat algorithm (BA), achieving 99.52% accuracy under stratified fivefold validation. This approach yields thousands of additional correct decisions per million URLs and reduces false negatives and false positives without adverse throughput effects. The prevention module utilizes a decision tree (DT) with the HHO ∩ BA consensus subset, achieving an inference time of 1 ms per URL with competitive accuracy (98.96%), enabling more than 1,000 URLs per second per core and meeting strict inline decision budgets. Standard metrics, such as accuracy, precision, recall, and F1-score, along with timing analyses, confirm that aligning feature selection with module objectives strikes a practical balance between detection quality and latency. The resulting guidance is direct: employ RF with BA for intrusion detection when optimal discriminative performance is essential, and adopt DT with the HHO ∩ BA subset for intrusion prevention when millisecond-scale latency dictates deployment.

References

Abu Al-Haija, Q., & Al-Fayoumi, M. (2023). An intelligent identification and classification system for malicious uniform resource locators (URLs). Neural Computing and Applications, 35(23), 16995–17011. https://doi.org/10.1007/s00521-023-08592-z

Abualhaj, M. M., & Al-Khatib, S. N. (2024). Using decision tree classifier to detect Trojan Horse based on memory data. TELKOMNIKA (Telecommunication Computing Electronics and Control), 22(2), 393–400. https://doi.org/10.12928/telkomnika.v22i2.25753

Abualhaj, M. M., Abu-Shareha, A. A., Alkhatib, S. N., Shambour, Q. Y., & Alsaaidah, A. M. (2025). Detecting spam using Harris Hawks optimizer as a feature selection algorithm. Bulletin of Electrical Engineering and Informatics, 14(3), 2361–2369. https://doi.org/10.11591/eei. v14i3.9198

Abualhaj, M. M., Abu-Shareha, A. A., Shambour, Q. Y., Al-Khatib, S. N., & Hiari, M. O. (2024). Tuning the K value in K-nearest neighbors for malware detection. IAES International Journal of Artificial Intelligence (IJ-AI), 13(2), 2275–2282. https://doi.org/10.11591/ijai.v13.i2. pp2275-2282

Abualhaj, M. M., Al-Khatib, S. N., Al Zyoud, M., Qaddara, I., & Anbar, M. (2025). Enhancing intrusion detection system performance using a hybrid of Harris Hawks and Whale Optimization algorithms. Engineering, Technology & Applied Science Research, 15(4), 24354–24361. https://doi.org/10.48084/etasr.10919

Abualhaj, M. M., Al-Shamayleh, A. S., Munther, A., Alkhatib, S. N., Hiari, M. O., & Anbar, M. (2024). Enhancing spyware detection by utilizing decision trees with hyperparameter optimization. Bulletin of Electrical Engineering and Informatics, 13(5), 3653–3662. https://doi.org/10.11591/eei.v13i5.7939

Abualhaj, M. M., Hiari, M. O., Alsaaidah, A., & Al-Zyoud, M. M. (2025). Comparative analysis of whale and Harris Hawks optimization for feature selection in intrusion detection. Indonesian Journal of Electrical Engineering and Computer Science, 37(1), 179–185. https://doi.org/10. 11591/ijeecs.v37.i1.pp179-185

Abualhaj, M. M., Shambour, Q. Y., Abu-Shareha, A. A., Al-Khatib, S. N., & Amer, A. (2025). Enhancing malware detection through self-union feature selection using gray wolf optimizer. Indonesian Journal of Electrical Engineering and Computer Science, 37(1), 197–205. https://doi.org/10.11591/ijeecs.v37.i1.pp197-205

Abu-Shareha, A. A. (2024). A Framework for Diabetes Detection Using Machine Learning and Data Preprocessing. Journal of Applied Data Sciences, 5(4), 1654–1667. https://doi.org/10.47738/ jads.v5i4.363

Afshar, F., Seyedabrishami, S., & Moridpour, S. (2022). Application of extremely randomised trees for exploring influential factors on variant crash severity data. Scientific Reports, 12, Article 11476. https://doi.org/10.1038/s41598-022-15693-

Al Saaidah, A., Abualhaj, M. M., Shambour, Q. Y., Abu-Shareha, A. A., Abualigah, L., Al-Khatib, S. N., & Alraba’nah, Y. H. (2024). Enhancing malware detection performance: Leveraging K-nearest neighbors with Firefly Optimization Algorithm. Multimedia Tools and Applications, 84, 10071–10094. https://doi.org/10.1007/s11042-024-18914-

Al-Dabbas, L., & Abu-Shareha, A. A. (2024). Early detection of female type-2 diabetes using machine learning and oversampling techniques. Journal of Applied Data Sciences, 5(3), 1237–1245. https://doi.org/10.47738/jads.v5i3.298

Almomani, A., Akour, I., Manasrah, A., Almomani, O., Alauthman, M., Abdullah, E., Shwait, A., & Sharaa, R. (2023). Ensemble-Based Approach for Efficient Intrusion Detection in Network Traffic. Intelligent Automation & Soft Computing, 37(2), 2499–2517. https://doi.org/10. 32604/iasc.2023.039687

Almomani, O., Alsaaidah, A., Abu-Shareha, A. A., Alzaqebah, A., Almaiah, M. A., & Shambour, Q. (2025). Enhance URL defacement attack detection using particle swarm optimization and machine learning. Journal of Computational and Cognitive Engineering, 4(3), 296–308. https://doi.org/10.47852/bonviewJCCE52024668

Alraba’nah, Y., Al-Sharaeh, S., & Al Hindi, G. (2025). Enhancing Intrusion Detection Using Hybrid Long Short-Term Memory and XGBoost. Journal of Soft Computing and Data Mining, 6(1), 247–261.

Alraba'nah, Y., & Toghuj, W. (2024). A deep learning based architecture for malaria parasite detection. Bulletin of Electrical Engineering and Informatics, 13(1), 292–299. https://doi.org/10.11591/eei.v13i1.5485

AlTalhi, R., Saqib, M. N., Saeed, U., & Alghamdi, A. S. (2021). Malicious URL detection using streaming feature selection. In Proceedings of the 5th International Conference on Future Networks & Distributed Systems (pp. 100–104). ACM. https://doi.org/10.1145/3508072. 3508088

Anne, W. R., & CarolinJeeva, S. (2021). Performance analysis of boosting techniques for classification and detection of malicious websites. Proceedings of the International Conference on Combinatorial and Optimization (ICCAP), 405–415.

Fan, C., Chen, M., Wang, X., Wang, J., & Huang, B. (2021). A review on data preprocessing techniques toward efficient and reliable knowledge discovery from building operational data. Frontiers in Energy Research, 9, Article 652801. https://doi.org/10.3389/fenrg.2021.652801

Gopal, S. B., Poongodi, C., Nanthiya, D., Kirubakaran, T., Logeshwar, D., & Saravanan, B. K. (2022). Autoencoder based architecture for mitigating phishing URL attack in the internet of things (IoT) using deep neural networks. Proceedings of the International Conference on Devices, Circuits and Systems (ICDCS), 427–431. IEEE.10.1109/ICDCS54290.2022. 9780673

Gu, R., Fei, J., Wang, D., Zhu, Y., Yu, H. & Guo, F. (2024). A malicious encrypted traffic detection method based on hybrid feature selection. Proceedings of Fifth International Conference on Computer Communication and Network Security (CCNS 2024), 13228, 517-526. https://doi.org/10.1117/12.3038339

Hamdan Mohammad, A., Alwada’n, T., Almomani, O., Smadi, S., & ElOmari, N. (2022). Bio-inspired Hybrid Feature Selection Model for Intrusion Detection. Computers, Materials & Continua, 73(1), 133–150. https://doi.org/10.32604/cmc.2022.027475

Hasan, R., Biswas, B., Samiun, M., Saleh, M. A., Prabha, M., Akter, J., Joya, F. H., & Abdullah, M. (2025). Enhancing malware detection with feature selection and scaling techniques using machine learning models. Scientific Reports, 15(1), 9122. https://doi.org/10.1038/s41598-025-93447-x

Heidar, A. A., Mirjalili, S., Faris, H., Aljarah, I., Mafarja, M., & Chen, H. (2019). Harris hawks optimization: Algorithm and applications. Future Generation Computer Systems, 97, 849–872. https://doi.org/10.1016/j.future.2019.02.

Hersyaputra, M. S., Jaya, M. T. T., & Anggraini, R. N. E. (2026). A hybrid machine learning model for streaming frequency-based anomaly detection in banking transactions. Journal of Information and Communication Technology, 25(1), 64-78. https://doi.org/10.32890/jict2026. 25.1.

Hoang, X. D., Nguyen, B. C., & Thu, T. (2023). Detecting malware based on statistics and machine learning using opcode N-Grams. 2023 RIVF International Conference on Computing and Communication Technologyies (RIVF). https://doi.org/10.1109/rivf60135.2023.10471824

Hussain, A. S., Pati, K. D., Atiyah, A. K., & Tashtoush, M. A. (2025). Rate of occurrence estimation in geometric processes with Maxwell distribution: A comparative study between artificial intelligence and classical methods. International Journal of Advances in Soft Computing and Its Applications, 17(1), 1–15. https://doi.org/10.15849/ijasca.250330.

Kocev, D., Geurts, P., Wehenkel, L., & Džeroski, J. (2020). Ensembles of extremely randomized predictive clustering trees. Machine Learning, 101(1-3), 139–172. https://doi.org/10.1007/ s10994‑020‑05894‑

Kumi, S., Lim, C., & Lee, S.-G. (2021). Malicious URL detection based on associative classification. Entropy, 23(2), 182. https://doi.org/10.3390/e23020182

Le, H., Pham, Q., Sahoo, D., & Hoi, S. C. H. (2018). URLNet: Learning a URL representation with deep learning for malicious URL detection. arXiv. https://doi.org/10.48550/arXiv.1802.03162

Lee, J., Jang, H., Ha, S., & Yoon, Y. (2021). Android malware detection using machine learning with feature selection based on the genetic algorithm. Mathematics, 9(21), 2813. https://doi.org/10.3390/math9212813

Liu, Z., Chang, B., & Cheng, F. (2021). An interactive filter-wrapper multi-objective evolutionary algorithm for feature selection. Swarm and Evolutionary Computation, 65, 100925. https://doi.org/10.1016/j.swevo.2021.100925

Mamun, M. S. I., Rathore, M. A., Lashkari, A. H., Stakhanova, N., & Ghorbani, A. A. (2016). Detecting malicious URLs using lexical analysis. In J. Chen, V. Piuri, C. Su, & M. Yung (Eds.), Network and system security (Lecture Notes in Computer Science, Vol. 9955). Springer. https://doi.org/10.1007/978-3-319-46298-1_

Okunnuga, I. D. (2023). Prediction and detection of malicious URL using machine learning. International Journal of Advance Research, Ideas and Innovations in Technology, 10(1), 195-219.

Pethe, Y. S., Gourisaria, M. K., Singh, P. K., & Das, H. (2024). FSBOA: Feature selection using bat optimization algorithm for software fault detection. Discover Internet of Things, 4(1). https://doi.org/10.1007/s43926-024-00059-

Potharlanka, J. L., & M, N. B. (2024). Feature importance feedback with Deep Q process in ensemble-based metaheuristic feature selection algorithms. Scientific Reports, 14(1), 2923. https://doi.org/10.1038/s41598-024-53141-w

Qaddara, I., & Alraba’nah, Y. (2025). Enhancing requirements classification using machine learning techniques. SN Computer Science, 6(6). https://doi.org/10.1007/s42979-025-04158-z

Rafrastara, F. A., Ghozi, W., Sani, R. R., Handoko, L. B., Abdussalam, Pramudya, E. R., & Abdollah, F. M. (2025). Integrating information gain and chi-square for enhanced malware detection performance. Journal of Information and Communication Technology, 24(1), 79-101. https://doi.org/10.32890/jict 2025.24.1.

Sagagi, I. T., Adamu, A., Abdulrahman, S. M., & Zainon, W. M. N. (2024). Unsupervised feature selection technique with enhanced binary bat algorithm. In 2024 IEEE 5th International Conference on Electro-Computing Technologies for Humanity (NIGERCON). IEEE. https://doi.org/10.1109/NIGERCON62786.2024.10926980

Saheed, Y. K., Kehinde, T. O., Ayobami Raji, M., & Baba, U. A. (2023). Feature selection in intrusion detection systems: A new hybrid fusion of bat algorithm and Residue Number System. Journal of Information and Telecommunication, 8(2), 189-207. https://doi.org/10.1080/24751839.2023.2272484

Scarfone, K., & Mell, P. (2007). Guide to Intrusion Detection and Prevention Systems (IDPS) (NIST Special Publication 800-94). National Institute of Standards and Technology https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=901146

Shambour, Q., Qandeel, N., Alrabanah, Y., Abumariam, A., & Shambour, M. K. (2024). Artificial intelligence techniques for early autism detection in toddlers: A comparative analysis. Journal of Applied Data Sciences, 5(4), 1754-1764.

Sheikh, A. M., Islam, M. R., Habaebi, M. H., Zabidi, S. A., Rahman, A., & Kabbani, A. (2025). A survey on edge computing (EC) security challenges: Classification, threats, and mitigation strategies. Future Internet, 17(4), 175–175. https://doi.org/10.3390/fi17040175

Spooner, A., Mohammadi, G., Sachdev, P. S., Brodaty, H., & Arcot Sowmya. (2023). Ensemble feature selection with data-driven thresholding for Alzheimer’s disease biomarker discovery. BMC Bioinformatics, 24(1). https://doi.org/10.1186/s12859-022-05132-

Swetha, T., Seshaiah, M., Hemalatha, K. L., Murthy, S. V. N., & Manjunatha Kumar, B. H. (2024). Hybrid machine learning approach for real-time malicious URL detection using SOM-RMO and RBFN with tabu search. International Journal of Advanced Computer Science and Applications, 15(8), 450–458. https://doi.org/10.14569/ijacsa.2024.0150844

Tripathy, B. K., Maddikunta, P. K. R., Pham, Q.-V., Gadekallu, T. R., Dev, K., Pandya, S., & ElHalawany, B. M. (2022). Harris Hawk optimization: A survey on variants and applications. Computational Intelligence and Neuroscience, 2022, Article 2218594. https://doi.org/10. 1155/2022/2218594

Tung, S. P., Wong, K. Y., Kuzminykh, I., Bakhshi, T., & Ghita, B. (2022). Using a machine learning model for malicious URL type detection. Lecture Notes in Computer Science, 493–505. https://doi.org/10.1007/978-3-030-97777-1_41

Yab, L. Y., Wahid, N., & Hamid, R. A. (2024). Impact of balanced exploration and exploitation on high-dimensional feature selection with hierarchical whale optimisation algorithm. Journal of Information and Communication Technology, 23(4), 593-626. https://doi.org/10.32890/jict 2024.23.4.

Yeop, N. S., Zakaria, N. H., & Suendri (2025). Enhancing the effectiveness of machine learning-based phishing email detection via an improved pre-processing technique for data security. Journal of Information and Communication Technology, 24(4), 87-110. https://doi.org/10. 32890/jict2025.24.4.

Zhang, X., & Jonassen, I. (2019). An ensemble feature selection framework integrating stability. 2021 IEEE International Conference on Bioinformatics and Biomedicine (BIBM). https://doi.org/10.1109/bibm47256.2019.8983310

Downloads

Published

31-07-2026

How to Cite

Sh. Daoud, M., Abualhaj, M. M., Al-Khatib, S. S., Al-Zyoud, M., Abu-Shareha, A., Al-Aqrabi, H., Alsharaiah, M. A., & Anbar, M. (2026). A Unified Machine Learning-Based IDS/IPS Framework with Bio-Inspired Feature Selection for Real-Time Detection of Malware-Laden URLs. Journal of Information and Communication Technology, 25(3), 1-30. https://doi.org/10.32890/jict2026.25.3.1

Research impact

Harvested 2026-09-26
0 citations recorded so far

Counts differ between services because each indexes a different body of literature. None of them is the whole picture.

Identifiers DOI 10.32890/jict2026.25.3.1 OpenAlex W7171544041 Scopus 105047433151