Keywords: systems analysis, malicious software, intelligent protection system, chronological evaluation, two-stage architecture, feature reduction, adaptive updating, machine learning
UDC 004.056.5
DOI: 10.26102/2310-6018/2026.59.8.011
The paper addresses the problem of designing an intelligent protection system against malicious software under changing input flows, limited computational resources, and the need for stable operation on new data. The aim of the study was to show how systems analysis methods make it possible to move from a simple comparison of classification models to a justified choice of architecture, evaluation strategy, and update scenario. The experimental basis included 134435 objects, of which 57293 were malicious. After removing records without a recognized date and excluding the early archival fragment, an experimental subset of 123704 objects covering the period from August 2019 to September 2020 was formed. The study compares randomized and chronological evaluation schemes, baseline classification models, several feature reduction variants, and both single-stage and two-stage protection architectures. The results show that using 256 features in the first stage provides almost the same recognition quality as the full 2381-feature representation while requiring substantially lower computational costs. It is also shown that the two-stage architecture preserves the quality of the full model while sending only 0.25 percent of objects to the second stage and almost not increasing the average processing time per object. In addition, first-stage updating improves temporal robustness and reduces the risk of quality degradation on later monthly data segments.
1. Guerra-Manzanares A. Machine Learning for Android Malware Detection: Mission Accomplished? A Comprehensive Review of Open Challenges and Future Perspectives. Computers & Security. 2024;138:103654. https://doi.org/10.1016/j.cose.2023.103654
2. Yang L., Ciptadi A., Laziuk I., et al. BODMAS: An Open Dataset for Learning based Temporal Analysis of PE Malware. In: 2021 IEEE Security and Privacy Workshops, 27 May 2021, San Francisco, CA, USA. IEEE; 2021. P. 78–84. https://doi.org/10.1109/SPW53761.2021.00020
3. Jiang Y., Li G., Li Sh., et al. BenchMFC: A benchmark dataset for trustworthy malware family classification under concept drift. Computers & Security. 2024;139:103706. https://doi.org/10.1016/j.cose.2024.103706
4. Fernando D.W., Komninos N. FeSAD ransomware detection framework with machine learning using adaption to concept drift. Computers & Security. 2024;137:103629. https://doi.org/10.1016/j.cose.2023.103629
5. Li A.Sh., Iyengar A., Kundu A., et al. Revisiting Concept Drift in Windows Malware Detection: Adaptation to Real Drifted Malware with Minimal Samples. In: 32nd Annual Network and Distributed System Security Symposium, 24–28 February 2025, San Diego, CA, USA. The Internet Society; 2025. https://doi.org/10.14722/ndss.2025.240830
6. Maniriho P., Mahmood A.N., Chowdhury M.J.M. MeMalDet: A memory analysis-based malware detection framework using deep autoencoders and stacked ensemble under temporal evaluations. Computers & Security. 2024;142:103864. https://doi.org/10.1016/j.cose.2024.103864
7. Augello A., De Paola A., Lo Re G. Hybrid multilevel detection of mobile devices malware under concept drift. Journal of Network and Systems Management. 2025;33(2):36. https://doi.org/10.1007/s10922-025-09906-3
8. Liu Zh., Wang R., Peng B., et al. LDCDroid: Learning data drift characteristics for handling the model aging problem in Android malware detection. Computers & Security. 2025;150:104294. https://doi.org/10.1016/j.cose.2024.104294
9. Geurts P., Ernst D., Wehenkel L. Extremely randomized trees. Machine Learning. 2006;63(1):3–42. https://doi.org/10.1007/s10994-006-6226-1
10. Ke G., Meng Q., Finley Th., et al. LightGBM: A Highly Efficient Gradient Boosting Decision Tree. In: Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems, 04–09 December 2017, Long Beach, CA, USA. 2017. P. 3146–3154.
11. Lundberg S.M., Lee S.-I. A Unified Approach to Interpreting Model Predictions. In: Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems, 04–09 December 2017, Long Beach, CA, USA. 2017. P. 4765–4774.
12. Ceschin F., Botacin M., Gomes H.M., et al. Fast & Furious: On the modelling of malware detection as an evolving data stream. Expert Systems with Applications. 2023;212:118590. https://doi.org/10.1016/j.eswa.2022.118590
13. Botacin M., Gomes H. Towards more realistic evaluations: The impact of label delays in malware detection pipelines. Computers & Security. 2025;148:104122. https://doi.org/10.1016/j.cose.2024.104122
14. Augello A., De Paola A., Lo Re G. M2FD: Mobile malware federated detection under concept drift. Computers & Security. 2025;152:104361. https://doi.org/10.1016/j.cose.2025.104361
Keywords: systems analysis, malicious software, intelligent protection system, chronological evaluation, two-stage architecture, feature reduction, adaptive updating, machine learning
For citation: Abedlhussain A.A., Lyapuntsova E.V. Using systems analysis in designing intelligent protection systems against malicious software. Modeling, Optimization and Information Technology. 2026;14(8). URL: https://moitvivt.ru/ru/journal/article?id=2389 DOI: 10.26102/2310-6018/2026.59.8.011 (In Russ).
© Abedlhussain A.A., Lyapuntsova E.V. Статья опубликована на условиях лицензии Creative Commons Attribution-NonCommercial 4.0 International (CC BY-NS 4.0)Received 30.04.2026
Revised 17.08.2026
Accepted 24.08.2026
Published 31.08.2026