AI-Driven Malware Detection Using Static Code Inspection and Network Flow Monitoring
DOI:
https://doi.org/10.33411/IJIST/1715Keywords:
Malware Detection, Agentic Artificial Intelligence, Machine Learning, Static Code Analysis, Network Flow Monitoring, Hybrid Malware Detection, YARA, Scapy, CybersecurityAbstract
Malware refers to software designed to cause harm, steal data, disrupt services, or gain unauthorized access, often employed by attackers for financial gain or sabotage. Traditional detection methods struggle against novel threats that evade signature-based systems. This research introduces an AI-driven hybrid malware detection framework combining static code inspection with real-time network flow analysis. Developed in Python using YARA and Scapy, the system uses machine learning to enhance detection accuracy by correlating code-level and behavioral indicators, effectively identifying both dormant and active threats while reducing false positives. It also features an interactive interface for educational purposes, helping users understand malware behavior and cybersecurity concepts. Experimental results show improved detection precision and faster analysis compared to traditional methods, making this framework a scalable and instructive solution for malware detection and cybersecurity awareness.
References
Zahid Akhtar, “Malware Detection and Analysis: Challenges and Research Opportunities,” arXiv:2101.08429, 2021, [Online]. Available: https://arxiv.org/abs/2101.08429
Azar Abid Salih, Maiwan Bahjat Abdulrazzaq, “Cyber security: performance analysis and challenges for cyber attacks detection,” Indones. J. Electr. Eng. Comput. Sci., 2023, [Online]. Available: https://ijeecs.iaescore.com/index.php/IJEECS/article/view/30893
S. Rana and R. Chicone, “Fortifying the Future: Harnessing AI for Transformative Cybersecurity Training,” Fortifying Futur. Harnessing AI Transform. Cybersecurity Train., pp. 1–131, Jan. 2024, doi: 10.1007/978-3-031-81780-9.
R. H. Mahdi and H. Trabelsi, “Detection of Malware by Using YARA Rules,” 2024 21st Int. Multi-Conference Syst. Signals Devices, SSD 2024, pp. 568–575, 2024, doi: 10.1109/SSD61670.2024.10549308.
Haocong Li, Jie Li, “Automatically Generate Malware Detection Rules By Extracting Risk Information,” ACM Int. Conf. Proceeding Ser., 2024, [Online]. Available: https://dl.acm.org/doi/10.1145/3670105.3670209
M. A. Khalifa, I. Almomani, and W. El-Shafai, “SAMA: A Comprehensive Smart Automated Malware Analyzer Empowered by ChatGPT Integration,” 2024 IEEE 30th Int. Conf. Telecommun. ICT 2024, 2024, doi: 10.1109/ICT62760.2024.10606026.
H. T. Zaw, T. Aung, A. H. Maw, and M. Thida Mon, “Comparative Analysis of YARA and VirusTotal Integrations with Wazuh for Enhanced Malware Detection,” 2024 5th Int. Conf. Adv. Inf. Technol. ICAIT 2024, 2024, doi: 10.1109/ICAIT65209.2024.10754931.
“Malware Analysis: Digital Forensics, Cybersecurity, And Incident Response: Botwright, Rob: 9781839385315: Amazon.com: Books.” Accessed: Feb. 07, 2026. [Online]. Available: https://www.amazon.com/Malware-Analysis-Forensics-Cybersecurity-Incident/dp/1839385316
Pooja Kumari, Ankit Kumar Jain, “A comprehensive study of DDoS attacks over IoT network and their countermeasures,” Comput. Secur., vol. 127, p. 103096, 2023, [Online]. Available: https://www.sciencedirect.com/science/article/abs/pii/S0167404823000068
Anshuman Singh, Brij B. Gupta, “Distributed Denial-of-Service (DDoS) Attacks and Defense Mechanisms in Various Web-Enabled Computing Platforms: Issues, Challenges, and Future Research Directions,” Int. J. Semant. Web Inf. Syst., vol. 18, no. 1, p. 43, 2022, [Online]. Available: https://www.igi-global.com/article/distributed-denial-of-service-ddos-attacks-and-defense-mechanisms-in-various-web-enabled-computing-platforms/297143
B. A. Dahri, K. A., Vighio, M. S., & Zardari, “Detection and prevention of malware in the Android operating system,” Mehran Univ. Res. J. Eng. Technol., vol. 40, no. 4, pp. 847–859, 2021, [Online]. Available: https://www.researchgate.net/publication/355269909_Detection_and_Prevention_of_Malware_in_Android_Operating_System
Ö. A. Aslan, R. Samet, “A Comprehensive Review on Malware Detection Approaches,” IEEE Access, vol. 8, pp. 6249–6271, 2020, [Online]. Available: https://ieeexplore.ieee.org/document/8949524
Pedro LocoSebastian AlonsoGeorge HartmannJames WhitmoreEdward McLaughlin, “Adaptive Behavior-Based Ransomware Detection via Dynamic Flow Signatures,” Sciety, 2024, [Online]. Available: https://sciety.org/articles/activity/10.21203/rs.3.rs-5317374/v1
I. Mršulja, J. Slivka, and G. Sladić, “Obfuscated Malware Classification Using Hierarchy-Based Pipeline,” Lect. Notes Networks Syst., vol. 860 LNNS, pp. 401–409, 2024, doi: 10.1007/978-3-031-71419-1_34.
M. N. Ahmed, Z. Iqbal, H. Mahmood, and M. Abdullah, “CAP - A Context-Aware Framework for Detection and Analysis of Packed Malware,” 2024 Int. Conf. Front. Inf. Technol. FIT 2024, 2024, doi: 10.1109/FIT63703.2024.10838408.
Kenan Begovic, Abdulaziz Al-Ali, Qutaibah Malluhi, “Cryptographic ransomware encryption detection: Survey,” Comput. Secur., vol. 1321, p. 103349, 2023, [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0167404823002596
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 50sea

This work is licensed under a Creative Commons Attribution 4.0 International License.


















