Deep Learning-Based Malware Detection and Classification Using Memory Behavioral Features

Main Article Content

Mohammed Basil Abdulkareem
Kassem Hamze
Mohammad Abdullah Abbas

Abstract

As malware evolves and grows more sophisticated, it remains a major challenge for modern cybersecurity solutions to detect and prevent. The traditional approaches for malware detection, which are mostly based on signature-based detection and manually engineered features, are no longer effective against new variants of malware and the ones that are highly obfuscated. Considering these drawbacks, this research aims to propose an effective lightweight hybrid Convolutional Neural Network–Long Short-Term Memory (CNN–LSTM) for detecting and categorizing malware based on its memory behavioral features. The proposed framework can automatically learn the representative behavioral patterns that exist in the CIC-MalMem-2022 benchmark dataset using a systematic pipeline that includes data preprocessing, feature normalization, CNN-based feature extraction, LSTM-based sequential learning, and Softmax classification. Model performance is assessed on common performance metrics: Accuracy, Precision, Recall, F1-score, Confusion Matrix, Training Time, Inference Time. The experimental results show that the proposed CNN–LSTM framework not only performs well in terms of classification accuracy but also has a low computational complexity, which can be applied to practical cybersecurity applications. The hybrid architecture is able to effectively incorporate both spatial and sequential behavioural aspects to be able to discriminate between benign and other multiple malware families. In conclusion, the suggested approach offers a promising and effective deep learning method for detecting and categorizing malware using memory behavior analysis, which helps advance the creation of intelligent cybersecurity systems.

Article Details

Section

Articles

How to Cite

Deep Learning-Based Malware Detection and Classification Using Memory Behavioral Features (Mohammed Basil Abdulkareem, Kassem Hamze, & Mohammad Abdullah Abbas , Trans.). (2026). Babylonian Journal of Internet of Things, 2026, 158-173. https://doi.org/10.58496/BJIoT/2026/010