[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-124158-en":3,"doc-seo-124158-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},124158,13056703019404,"Miles","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Malware Classification Using Machine Learning and Dimension Reduction Techniques on PE File Data","Cyber incidents have surged alongside digital transformation, with malware attacks becoming a persistent threat. This study develops a malware detection method for Portable Executable (PE) file data using machine learning classifiers—Random Forest, XGBoost, and AdaBoost—trained on raw and integrated feature datasets. Principal Component Analysis and Linear Discriminant Analysis are applied to improve classification efficiency. Results show Random Forest and XGBoost outperform AdaBoost, delivering strong recall and F1-scores for ransomware and trojans, while preserving performance under reduced feature sets.","Malware Classification Using Machine Learning and Dimension Reduction Techniques on PE File Data  \nArif Harsa Pradipta1, Lili Ayu Wulandhari2  \n1,2Department of Computer Science, BINUS Graduate Program, Master of Computer Science, Bina Nusantara University,  \nJakarta, Indonesia  \n\n| Article history:\u003Cbr>Received Jun 20, 2024 Revised Aug 8, 2024 Accepted Sep 9, 2024 | The digital transformation has enhanced efficiency, transparency, and accessibility but has also led to a notable increase in cyber incidents, including malware attacks. According to the 2022 annual report from the Honeynet Project by the National Cyber and Encryption Agency, Indonesia experienced over 370 million cyber attacks, with 800,000 of these being malware attacks. The increasing complexity of Portable Executable files further complicates accurate classification in machine learning models. This research aims to develop an effective malware detection approach using machine learning classifiers—Random Forest, XGBoost, and AdaBoost—on raw feature dataset and integrated feature dataset. Dimension reduction techniques such as Principal Component Analysis and Linear Discriminant Analysis were utilized to enhance classification efficiency. The results demonstrated that Random Forest and XGBoost consistently outperformed AdaBoost, particularly in classifying ransomware, achieving recall values ranging from 0.72 to 0.85 and F1-scores from 0.74 to 0.81 For the trojan class, both Random Forest and XGBoost achieved recall values ranging from 0.96 to 0.97, with corresponding F1-scores between 0.95 and 0.97. Both classifiers maintained high precision, recall, and F1-scores across all malware classes, even with reduced feature sets.\u003Cbr>Copyright © 2024 Institute of Advanced Engineering and Science.\u003Cbr>All rights reserved. |\n| --- | --- |\n| Keywords:\u003Cbr>Cyber Security\u003Cbr>Machine Learning\u003Cbr>Data Dimension Reduction Malware Classification Portable Executable Format |  |\n\nCorresponding Author:  \nArif Harsa Pradipta, Department of Computer Science, Bina Nusantara University,  \nJl. Raya Kb. Jeruk No.27, RT.1/RW.9, Kemanggisan, Kec. Palmerah, Kota Jakarta Barat, Daerah Khusus Ibukota Jakarta 11530, Indonesia.  \nEmail: [arif.pradipta@binus.ac.id](arif.pradipta@binus.ac.id)  \nArticle Info ABSTRACT  \n1. INTRODUCTION  \nThe Electronic-Based Government System (SPBE), as stipulated in Presidential Regulation Number 95 of 2018 regarding the Electronic-Based Government System, has revolutionized public administration in Indonesia, including within a certain institution. Through the implementation of advanced and up-to-date information and communication technology, SPBE enables the institution to enhance efficiency, transparency, and accessibility in public services related to infrastructure and housing. This system allows for better data management, real-time monitoring of infrastructure projects, and more effective and efficient communication between various work units within the institution. Alongside the progress and development of digital transformation in the government system, it is undeniable that this correlates with an increase in cyber incidents in the government sector. According to the 2022 annual report from the Honeynet Project by the National Cyber and Encryption Agency, Indonesia experienced over 370 million cyber attacks, with 800,000 of these being malware attacks [1] .  \nTo understand malware, malware analysis is essential. Malware analysis is a process aimed at determining and identifying the behavior of malware in attacking a system. There are two primary techniques for analyzing malware: static analysis and dynamic analysis [2] . Static analysis involves examining the source code or executable files without running them, to identify suspicious signs or potential vulnerabilities that could  \nbe exploited. In contrast, dynamic analysis involves running the malware in a controlled environment to monitor and understand its behavior. Malware contains valuable informatio","cbCaiaGeayXsD6cq","https://ap.wps.com/l/cbCaiaGeayXsD6cq","pdf",690534,1,16,"English","en",105,"# Introduction\n## Malware analysis: static vs dynamic\n## Portable Executable (PE) format\n## Dimension reduction for high-dimensional data\n# Methods and Experimental Design\n## Classifiers: Random Forest, XGBoost, AdaBoost\n## Feature sets: raw vs integrated\n## Dimension reduction: PCA and LDA\n# Results and Discussion\n## Performance comparison across malware families\n## Impact of reduced feature sets","[{\"question\":\"Why is malware classification difficult for PE file data?\",\"answer\":\"Portable Executable files increase in complexity, and the resulting high-dimensional feature space can reduce classification accuracy without preprocessing such as dimension reduction.\"},{\"question\":\"Which machine learning models were used in the study?\",\"answer\":\"The research compares Random Forest, XGBoost, and AdaBoost as malware classifiers, evaluated using both raw feature datasets and integrated feature datasets.\"},{\"question\":\"How did dimension reduction techniques affect performance?\",\"answer\":\"Principal Component Analysis and Linear Discriminant Analysis improved classification efficiency, and Random Forest/XGBoost maintained high precision, recall, and F1-scores even when feature sets were reduced.\"}]","Malware Classification Using Machine Learning and Dimension Reduction Techniques on PE File Data | PDF",1785820785,40,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"malware-classification-using-machine-learning-and-dimension-reduction-techniques-on-pe-file-data","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/malware-classification-using-machine-learning-and-dimension-reduction-techniques-on-pe-file-data/124158/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is malware classification difficult for PE file data?","Question",{"text":75,"@type":76},"Portable Executable files increase in complexity, and the resulting high-dimensional feature space can reduce classification accuracy without preprocessing such as dimension reduction.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which machine learning models were used in the study?",{"text":80,"@type":76},"The research compares Random Forest, XGBoost, and AdaBoost as malware classifiers, evaluated using both raw feature datasets and integrated feature datasets.",{"name":82,"@type":73,"acceptedAnswer":83},"How did dimension reduction techniques affect performance?",{"text":84,"@type":76},"Principal Component Analysis and Linear Discriminant Analysis improved classification efficiency, and Random Forest/XGBoost maintained high precision, recall, and F1-scores even when feature sets were reduced.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":29,"slug":118},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]