{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T18:27:56Z","timestamp":1773772076406,"version":"3.50.1"},"reference-count":87,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2025,1,18]],"date-time":"2025-01-18T00:00:00Z","timestamp":1737158400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Banking malware poses a significant threat to users by infecting their computers and then attempting to perform malicious activities such as surreptitiously stealing confidential information from them. Banking malware variants are also continuing to evolve and have been increasing in numbers for many years. Amongst these, the banking malware Zeus and its variants are the most prevalent and widespread banking malware variants discovered. This prevalence was expedited by the fact that the Zeus source code was inadvertently released to the public in 2004, allowing malware developers to reproduce the Zeus banking malware and develop variants of this malware. Examples of these include Ramnit, Citadel, and Zeus Panda. Tools such as anti-malware programs do exist and are able to detect banking malware variants, however, they have limitations. Their reliance on regular updates to incorporate new malware signatures or patterns means that they can only identify known banking malware variants. This constraint inherently restricts their capability to detect novel, previously unseen malware variants. Adding to this challenge is the growing ingenuity of malicious actors who craft malware specifically developed to bypass signature-based anti-malware systems. This paper presents an overview of the Zeus, Zeus Panda, and Ramnit banking malware variants and discusses their communication architecture. Subsequently, a methodology is proposed for detecting banking malware C&amp;C communication traffic, and this methodology is tested using several feature selection algorithms to determine which feature selection algorithm performs the best. These feature selection algorithms are also compared with a manual feature selection approach to determine whether a manual, automated, or hybrid feature selection approach would be more suitable for this type of problem.<\/jats:p>","DOI":"10.3390\/jcp5010004","type":"journal-article","created":{"date-parts":[[2025,1,20]],"date-time":"2025-01-20T09:11:13Z","timestamp":1737364273000},"page":"4","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Detecting Malware C&amp;C Communication Traffic Using Artificial Intelligence Techniques"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5105-3581","authenticated-orcid":false,"given":"Mohamed Ali","family":"Kazi","sequence":"first","affiliation":[{"name":"Department of Computer Science, School of Computing and Communications, Faculty of Science, Technology, Engineering & Mathematics, The Open University, Walton Hall, Milton Keynes MK7 6AA, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,1,18]]},"reference":[{"key":"ref_1","first-page":"2217","article-title":"A Review on Cyber Crime: Major Threats and Solutions","volume":"8","author":"Wadhwa","year":"2017","journal-title":"Int. J. Adv. Res. Comput. Sci."},{"key":"ref_2","unstructured":"Morgan, S. (2024, December 07). Cybercrime to Cost the World 8 Trillion Annually in 2023. Cybercrime Magazine. Available online: https:\/\/cybersecurityventures.com\/cybercrime-to-cost-the-world-8-trillion-annually-in-2023\/."},{"key":"ref_3","unstructured":"(2024, December 07). Banking Malware Threats Surging as Mobile Banking Increases\u2014Nokia Threat Intelligence Report. n.d. Nokia. Available online: https:\/\/www.nokia.com\/about-us\/news\/releases\/2021\/11\/08\/banking-malware-threats-surging-as-mobile-banking-increases-nokia-threat-intelligence-report\/."},{"key":"ref_4","first-page":"31","article-title":"Emotet malware\u2014A banking credentials stealer","volume":"22","author":"Kuraku","year":"2020","journal-title":"IOSR J. Comput. Eng."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Etaher, N., Weir, G.R.S., and Alazab, M. (2015, January 20\u201322). From zeus to zitmo: Trends in banking malware. Proceedings of the 2015 IEEE Trustcom\/BigDataSE\/ISPA, Helsinki, Finland.","DOI":"10.1109\/Trustcom.2015.535"},{"key":"ref_6","unstructured":"(2025, January 16). Godfather Banking Trojan Spawns 1.2K Samples across 57 Countries. Darkreading.com. Available online: https:\/\/www.darkreading.com\/endpoint-security\/godfather-banking-trojan-spawns-1k-samples-57-countries."},{"key":"ref_7","unstructured":"Nilupul, S.A. (2024). Evolution and Impact of Malware: A Comprehensive Analysis from the First Known Malware to Modern-Day Cyber Threats. Cyber Secur."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Mishra, R., Butakov, S., Jaafar, F., and Memon, N. (2020, January 17\u201322). Behavioral Study of Malware Affecting Financial Institutions and Clients. Proceedings of the 2020 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress (DASC\/PiCom\/CBDCom\/CyberSciTech), Calgary, AB, Canada.","DOI":"10.1109\/DASC-PICom-CBDCom-CyberSciTech49142.2020.00028"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"74","DOI":"10.3390\/jcp2010006","article-title":"A survey on botnets, issues, threats, methods, detection and prevention","volume":"2","author":"Owen","year":"2022","journal-title":"J. Cybersecur. Priv."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Boukherouaa, E.B., Shabsigh, M.G., AlAjmi, K., Deodoro, J., Farias, A., Iskender, E.S., Mirestean, M.A.T., and Ravikumar, R. (2021). Powering the Digital Economy: Opportunities and Risks of Artificial Intelligence in Finance, International Monetary Fund.","DOI":"10.5089\/9781589063952.087"},{"key":"ref_11","unstructured":"AMR (2025, January 16). IT Threat Evolution in Q3 2022. Non-Mobile Statistics. Securelist.com. Kaspersky. Available online: https:\/\/securelist.com\/it-threat-evolution-in-q3-2022-non-mobile-statistics\/107963\/."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"495","DOI":"10.1504\/IJGUC.2022.126167","article-title":"Comparing the performance of supervised machine learning algorithms when used with a manual feature selection process to detect Zeus malware","volume":"13","author":"Kazi","year":"2022","journal-title":"Int. J. Grid Util. Comput."},{"key":"ref_13","unstructured":"Punyasiri, D.L.S. (2023). Signature & Behavior Based Malware Detection. [Bachelor\u2019s Thesis, Sri Lanka Institute of Information Technology]."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"100529","DOI":"10.1016\/j.cosrev.2022.100529","article-title":"A comprehensive survey on deep learning based malware detection techniques","volume":"47","author":"Gopinath","year":"2023","journal-title":"Comput. Sci. Rev."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Alaskar, H., and Saba, T. (2021). Machine learning and deep learning: A comparative review. Proceedings of Integrated Intelligence Enable Networks and Computing: IIENC 2020, Springer.","DOI":"10.1007\/978-981-33-6307-6_15"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Madanan, M., Gunasekaran, S.S., and Mahmoud, M.A. (2023, January 14\u201316). A Comparative Analysis of Machine Learning and Deep Learning Algorithms for Image Classification. Proceedings of the 2023 6th International Conference on Contemporary Computing and Informatics (IC3I), Gautam Buddha Nagar, India.","DOI":"10.1109\/IC3I59117.2023.10398030"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Kazi, M.A., Woodhead, S., and Gan, D. (2019). Comparing and analysing binary classification algorithms when used to detect the Zeus malware. 2019 Sixth HCT Information Technology Trends (ITT), IEEE.","DOI":"10.1109\/ITT48889.2019.9075115"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"100071","DOI":"10.1016\/j.dajour.2022.100071","article-title":"A comparative analysis of K-nearest neighbor, genetic, support vector machine, decision tree, and long short term memory algorithms in machine learning","volume":"3","author":"Bansal","year":"2022","journal-title":"Decis. Anal. J."},{"key":"ref_19","unstructured":"Kazi, M., Woodhead, S., and Gan, D. (2018, January 15\u201317). A contempory Taxonomy of Banking Malware. Proceedings of the First International Conference on Secure Cyber Computing and Communications, Jalandhar, India."},{"key":"ref_20","unstructured":"Falliere, N., and Chien, E. (2024, October 19). Zeus: King of the Bots. Available online: https:\/\/www.google.co.uk\/url?sa=t&source=web&rct=j&opi=89978449&url=https:\/\/pure.port.ac.uk\/ws\/portalfiles\/portal\/42722286\/Understanding_and_Mitigating_Banking_Trojans.pdf&ved=2ahUKEwizroXLwZqJAxU-VUEAHdgzKqEQFnoECDMQAQ&usg=AOvVaw1St11bbRwbhYj9IB4VdQv4."},{"key":"ref_21","unstructured":"Lelli, A. (2019, November 05). Zeusbot\/Spyeye P2P Updated, Fortifying the Botnet. Available online: https:\/\/www.symantec.com\/connect\/blogs\/zeusbotspyeye-p2p-updated-fortifying-botnet."},{"key":"ref_22","unstructured":"Cluley, G. (2025, January 16). GameOver Zeus Malware Returns from the Dead. Graham Cluley. Available online: https:\/\/grahamcluley.com\/gameover-zeus-malware\/."},{"key":"ref_23","unstructured":"Brumaghin, E. (2025, January 16). Poisoning the Well: Banking Trojan Targets Google Search Results. [online] Cisco Talos Blog. Available online: https:\/\/blog.talosintelligence.com\/zeus-panda-campaign\/#More."},{"key":"ref_24","unstructured":"Lamb, C. (2019). Advanced Malware and Nuclear Power: Past Present and Future, Sandia National Lab. (SNL-NM). No. SAND2019-14527C."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"De Carli, L., Torres, R., Modelo-Howard, G., Tongaonkar, A., and Jha, S. (2017, January 1\u20134). Botnet protocol inference in the presence of encrypted traffic. Proceedings of the IEEE INFOCOM 2017-IEEE Conference on Computer Communications, Atlanta, GA, USA.","DOI":"10.1109\/INFOCOM.2017.8057064"},{"key":"ref_26","unstructured":"Lioy, A., Atzeni, A., and Romano, F. (2023). Machine Learning for Malware Characterization and Identification. [Master\u2019s Thesis, Politecnico di Torino]."},{"key":"ref_27","unstructured":"Paganini, P. (2025, January 16). HTTP-Botnets: The Dark Side of a Standard Protocol! Security Affairs. Available online: http:\/\/securityaffairs.co\/wordpress\/13747\/cyber-crime\/http-botnets-the-dark-side-of-an-."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"236","DOI":"10.1109\/TDSC.2014.2382590","article-title":"An empirical study of HTTP-based financial botnets","volume":"13","author":"Sood","year":"2014","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"162","DOI":"10.1016\/j.ins.2022.04.018","article-title":"A novel approach based on adaptive online analysis of encrypted traffic for identifying Malware in IIoT","volume":"601","author":"Niu","year":"2022","journal-title":"Inf. Sci."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"756","DOI":"10.1016\/j.cose.2017.09.013","article-title":"A Survey of Similarities in Banking Malware Behaviours","volume":"77","author":"Black","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Pilania, S., and Kunwar, R.S. (2024). Zeus: In-Depth Malware Analysis of Banking Trojan Malware. Advanced Techniques and Applications of Cybersecurity and Forensics, Chapman and Hall\/CRC.","DOI":"10.1201\/9781003386926-9"},{"key":"ref_32","unstructured":"(2025, January 16). CLULEY, Graham. Russian Creator of NeverQuest Banking Trojan Pleads Guilty in American Court. Hot for Security. Available online: https:\/\/www.bitdefender.com\/en-us\/blog\/hotforsecurity\/russian-creator-of-neverquest-banking-trojan-pleads-guilty-in-american-court\/."},{"key":"ref_33","unstructured":"Fisher, D. (2025, January 16). Cridex Malware Takes Lesson from GameOver Zeus. Threatpost.com. Threatpost. Available online: https:\/\/threatpost.com\/cridex-malware-takes-lesson-from-gameover-zeus\/107785\/."},{"key":"ref_34","unstructured":"Ilascu, I. (2025, January 16). Softpedia. Available online: https:\/\/news.softpedia.com\/news\/Cridex-Banking-Malware-Variant-Uses-Gameover-Zeus-Thieving-Technique-455193.shtml."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Andriesse, D., Rossow, C., Stone-Gross, B., Plohmann, D., and Bos, H. (2013, January 22\u201324). Highly resilient peer-to-peer botnets are here: An analysis of gameover zeus. Proceedings of the 2013 8th International Conference on Malicious and Unwanted Software: \u201cThe Americas\u201d (MALWARE), Fajardo, PR, USA.","DOI":"10.1109\/MALWARE.2013.6703693"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"1972","DOI":"10.35940\/ijeat.F7941.088619","article-title":"Botnet detection on the analysis of Zeus panda financial botnet","volume":"8","author":"Sarojini","year":"2019","journal-title":"Int. J. Eng. Adv. Technol."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Aboaoja, F.A., Zainal, A., Ghaleb, F.A., Al-Rimy, B.A.S., Eisa, T.A.E., and Elnour, A.A.H. (2022). Malware detection issues, challenges, and future directions: A survey. Appl. Sci., 12.","DOI":"10.3390\/app12178482"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"4934082","DOI":"10.1155\/2017\/4934082","article-title":"An effective conversation-based botnet detection method","volume":"2017","author":"Chen","year":"2017","journal-title":"Math. Probl. Eng."},{"key":"ref_39","first-page":"25","article-title":"Intrusion detection system using support vector machine","volume":"3","author":"Jha","year":"2013","journal-title":"Int. J. Appl. Inf. Syst. (IJAIS)"},{"key":"ref_40","first-page":"1","article-title":"A novel approach to malware detection using static classification","volume":"13","author":"Singla","year":"2015","journal-title":"Int. J. Comput. Sci. Inf. Secur."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"209","DOI":"10.1007\/s00542-016-3237-0","article-title":"Bot detection using unsupervised machine learning","volume":"24","author":"Wu","year":"2018","journal-title":"Microsyst. Technol."},{"key":"ref_42","first-page":"51","article-title":"BotOnus: An Online Unsupervised Method for Botnet Detection","volume":"4","author":"Yahyazadeh","year":"2012","journal-title":"ISeCure"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"2771","DOI":"10.1016\/j.aej.2016.04.004","article-title":"Detection of randomized bot command and control traffic on an end-point host","volume":"55","author":"Soniya","year":"2016","journal-title":"Alex. Eng. J."},{"key":"ref_44","first-page":"332","article-title":"The effectiveness of cost sensitive machine learning algorithms in classifying Zeus flows","volume":"17","author":"Azab","year":"2022","journal-title":"Int. J. Inf. Comput. Secur."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Haddadi, F., Runkel, D., Zincir-Heywood, A.N., and Heywood, M.I. (2014, January 12\u201316). On botnet behaviour analysis using GP and C4. 5. Proceedings of the Companion Publication of the 2014 Annual Conference on Genetic and Evolutionary Computation, Vancouver, BC, Canada.","DOI":"10.1145\/2598394.2605435"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Mohaisen, A., and Alrawi, O. (2013, January 13\u201317). Unveiling zeus: Automated classification of malware samples. Proceedings of the 22nd International Conference on World Wide Web, Rio de Janeiro, Brazil.","DOI":"10.1145\/2487788.2488056"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Wang, J., Yang, Q., and Ren, D. (2009, January 18\u201319). An intrusion detection algorithm based on decision tree technology. Proceedings of the 2009 Asia-Pacific Conference on Information Processing, Shenzhen, China.","DOI":"10.1109\/APCIP.2009.218"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Sajjad, S., and Jiana, B. (2020, January 20\u201322). The use of Convolutional Neural Network for Malware Classification. Proceedings of the 2020 IEEE 9th Data Driven Control and Learning Systems Conference (DDCLS), Liuzhou, China.","DOI":"10.1109\/DDCLS49620.2020.9275164"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Walker, A., and Sengupta, S. (2020, January 9\u201310). Malware family fingerprinting through behavioral analysis. Proceedings of the 2020 IEEE International Conference on Intelligence and Security Informatics (ISI), Arlington, VA, USA.","DOI":"10.1109\/ISI49825.2020.9280529"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Ramakrishna, M., Rama Satish, A., and Siva Krishna, P.S.S. (2021). Design and development of an efficient malware detection Using ML. Proceedings of International Conference on Computational Intelligence and Data Engineering: ICCIDE 2020, Springer.","DOI":"10.1007\/978-981-15-8767-2_35"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"38947","DOI":"10.1109\/ACCESS.2018.2846740","article-title":"BotDet: A System for Real Time Botnet Command and Control Traffic Detection","volume":"6","author":"Ghafir","year":"2018","journal-title":"IEEE Access"},{"key":"ref_52","first-page":"3","article-title":"Implementation of signature-based detection system using snort in windows","volume":"3","author":"Agarwal","year":"2014","journal-title":"Int. J. Comput. Appl. Inf. Technol."},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"He, S., Zhu, J., He, P., and Lyu, M.R. (2016, January 23\u201327). Experience report: System log analysis for anomaly detection. Proceedings of the 2016 IEEE 27th International Symposium on Software Reliability Engineering (ISSRE), Ottawa, ON, Canada.","DOI":"10.1109\/ISSRE.2016.21"},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"3051","DOI":"10.1109\/TIFS.2022.3201379","article-title":"DeepSyslog: Deep Anomaly Detection on Syslog Using Sentence Embedding and Metadata","volume":"17","author":"Zhou","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1186\/s42400-019-0038-7","article-title":"Survey of intrusion detection systems: Techniques, datasets and challenges","volume":"2","author":"Khraisat","year":"2019","journal-title":"Cybersecurity"},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"19242","DOI":"10.1002\/er.8010","article-title":"Comparative evaluation of AI-based intelligent GEP and ANFIS models in prediction of thermophysical properties of Fe3O4-coated MWCNT hybrid nanofluids for potential application in energy systems","volume":"46","author":"Sharma","year":"2022","journal-title":"Int. J. Energy Res."},{"key":"ref_57","first-page":"14","article-title":"Introduction to machine learning, neural networks, and deep learning","volume":"9","author":"Choi","year":"2020","journal-title":"Transl. Vis. Sci. Technol."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"527","DOI":"10.3390\/jcp2030027","article-title":"Cybersecurity Threats and Their Mitigation Approaches Using Machine Learning\u2014A Review","volume":"2","author":"Ahsan","year":"2022","journal-title":"J. Cybersecur. Priv."},{"key":"ref_59","unstructured":"Elmachtoub, A.N., Liang, J.C.N., and McNellis, R. (2020, January 12\u201318). Decision trees for decision-making under the predict-then-optimize framework. Proceedings of the International Conference on Machine Learning, Virtual."},{"key":"ref_60","unstructured":"Liberman, N. (2025, January 16). Decision Trees and Random Forests. Towards Data Science. Available online: https:\/\/towardsdatascience.com\/decision-trees-and-random-forests-df0c3123f991."},{"key":"ref_61","first-page":"1","article-title":"Murtree: Optimal decision trees via dynamic programming and search","volume":"23","author":"Lukina","year":"2022","journal-title":"J. Mach. Learn. Res."},{"key":"ref_62","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1177\/1536867X20909688","article-title":"The random forest algorithm for statistical learning","volume":"20","author":"Schonlau","year":"2020","journal-title":"Stata J."},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Oshiro, T.M., Perez, P.S., and Baranauskas, J.A. (2012). How many trees in a random forest?. Machine Learning and Data Mining in Pattern Recognition, Proceedings of the 8th International Conference, MLDM 2012, Berlin, Germany, 13\u201320 July 2012, Springer. Proceedings 8.","DOI":"10.1007\/978-3-642-31537-4_13"},{"key":"ref_64","doi-asserted-by":"crossref","first-page":"113","DOI":"10.1186\/s40537-024-00973-y","article-title":"Enhancing K-nearest neighbor algorithm: A comprehensive review and performance analysis of modifications","volume":"11","author":"Halder","year":"2024","journal-title":"J. Big Data"},{"key":"ref_65","doi-asserted-by":"crossref","first-page":"43","DOI":"10.14445\/22315381\/IJETT-V70I7P205","article-title":"A review on analysis of k-nearest neighbor classification machine learning algorithms based on supervised learning","volume":"70","author":"Suyal","year":"2022","journal-title":"Int. J. Eng. Trends Technol."},{"key":"ref_66","doi-asserted-by":"crossref","unstructured":"Aggarwal, C.C. (2015). Data Classification, Springer International Publishing.","DOI":"10.1007\/978-3-319-14142-8_10"},{"key":"ref_67","doi-asserted-by":"crossref","unstructured":"Kazi, M.A., Woodhead, S., and Gan, D. (2022). Detecting Zeus Malware Network Traffic Using the Random Forest Algorithm with Both a Manual and Automated Feature Selection Process. IOT with Smart Systems: Proceedings of ICTIS 2022, Volume 2, Springer Nature Singapore.","DOI":"10.1007\/978-981-19-3575-6_54"},{"key":"ref_68","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s40708-022-00180-6","article-title":"Single classifier vs. ensemble machine learning approaches for mental health prediction","volume":"10","author":"Chung","year":"2023","journal-title":"Brain Inform."},{"key":"ref_69","doi-asserted-by":"crossref","first-page":"18391","DOI":"10.1007\/s00521-022-07451-7","article-title":"A soft voting ensemble learning-based approach for multimodal sentiment analysis","volume":"34","author":"Salur","year":"2022","journal-title":"Neural Comput. Appl."},{"key":"ref_70","first-page":"1104","article-title":"Advanced Threat Detection Using Soft and Hard Voting Techniques in Ensemble Learning","volume":"5","author":"Jabbar","year":"2024","journal-title":"J. Robot. Control (JRC)"},{"key":"ref_71","unstructured":"Shomiron (2022, July 25). Zeustracker. Available online: https:\/\/github.com\/dnif-archive\/enrich-zeustracker."},{"key":"ref_72","unstructured":"Stratosphere (2024, September 20). Stratosphere Laboratory Datasets. Available online: https:\/\/www.stratosphereips.org\/datasets-overviewRetrieved."},{"key":"ref_73","unstructured":"Abuse.ch (2022, May 13). Fighting Malware and Botnets. Available online: https:\/\/abuse.ch\/."},{"key":"ref_74","doi-asserted-by":"crossref","first-page":"1390","DOI":"10.1109\/JSYST.2014.2364743","article-title":"Benchmarking the effect of flow exporters and protocol filters on botnet traffic classification","volume":"10","author":"Haddadi","year":"2014","journal-title":"IEEE Syst. J."},{"key":"ref_75","doi-asserted-by":"crossref","first-page":"38597","DOI":"10.1109\/ACCESS.2019.2905633","article-title":"A deep learning method with filter based feature engineering for wireless intrusion detection system","volume":"7","author":"Kasongo","year":"2019","journal-title":"IEEE Access"},{"key":"ref_76","doi-asserted-by":"crossref","unstructured":"Miller, S., Curran, K., and Lunney, T. (2018, January 11\u201312). Multilayer perceptron neural network for detection of encrypted VPN network traffic. Proceedings of the 2018 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (Cyber SA), Glasgow, UK.","DOI":"10.1109\/CyberSA.2018.8551395"},{"key":"ref_77","first-page":"1","article-title":"An Investigation to Detect Banking Malware Network Communication Traffic Using Machine Learning Techniques","volume":"3","author":"Kazi","year":"2023","journal-title":"J. Cybersecur. Priv."},{"key":"ref_78","doi-asserted-by":"crossref","first-page":"4694567","DOI":"10.1155\/2022\/4694567","article-title":"A Novel Framework Based on Deep Learning and ANOVA Feature Selection Method for Diagnosis of COVID-19 Cases from Chest X-Ray Images","volume":"2022","author":"Nasiri","year":"2022","journal-title":"Comput. Intell. Neurosci."},{"key":"ref_79","doi-asserted-by":"crossref","unstructured":"Alshanbari, H.M., Mehmood, T., Sami, W., Alturaiki, W., Hamza, M.A., and Alosaimi, B. (2022). Prediction and classification of COVID-19 admissions to intensive care units (ICU) using weighted radial kernel SVM coupled with recursive feature elimination (RFE). Life, 12.","DOI":"10.3390\/life12071100"},{"key":"ref_80","unstructured":"Kavya, D. (2025, January 16). Optimizing Performance: SelectKBest for Efficient Feature Selection in Machine Learning. Medium. Available online: https:\/\/medium.com\/@Kavya2099\/optimizing-performance-selectkbest-for-efficient-feature-selection-in-machine-learning-3b635905ed48."},{"key":"ref_81","doi-asserted-by":"crossref","first-page":"102389","DOI":"10.1016\/j.jocs.2024.102389","article-title":"XAI-driven antivirus in pattern identification of citadel malware","volume":"82","year":"2024","journal-title":"J. Comput. Sci."},{"key":"ref_82","doi-asserted-by":"crossref","unstructured":"Liu, Z., Wang, C., and Li, G. (2023). Feature Selection Algorithm Based on CFS Algorithm Emphasizing Data Discrimination. preprint.","DOI":"10.21203\/rs.3.rs-3181980\/v1"},{"key":"ref_83","doi-asserted-by":"crossref","first-page":"259","DOI":"10.1016\/0169-7439(89)80095-4","article-title":"Analysis of variance (ANOVA)","volume":"6","author":"St","year":"1989","journal-title":"Chemom. Intell. Lab. Syst."},{"key":"ref_84","first-page":"250","article-title":"A review of using machine learning approaches for precision education","volume":"24","author":"Luan","year":"2021","journal-title":"Educ. Technol. Soc."},{"key":"ref_85","doi-asserted-by":"crossref","unstructured":"Davis, J., and Goadrich, M. (2006, January 25\u201329). The relationship between Precision-Recall and ROC curves. Proceedings of the 23rd International Conference on Machine Learning, Pittsburgh, PA, USA.","DOI":"10.1145\/1143844.1143874"},{"key":"ref_86","doi-asserted-by":"crossref","unstructured":"Fourure, D., Javaid, M.U., Posocco, N., and Tihon, S. (2021). Anomaly detection: How to artificially increase your f1-score with a biased evaluation protocol. Joint European Conference on Machine Learning and Knowledge Discovery in Databases, Springer International Publishing.","DOI":"10.1007\/978-3-030-86514-6_1"},{"key":"ref_87","first-page":"120","article-title":"Confusion matrix-based feature selection","volume":"710","author":"Visa","year":"2011","journal-title":"Maics"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/1\/4\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,8]],"date-time":"2025-10-08T10:31:33Z","timestamp":1759919493000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/1\/4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,18]]},"references-count":87,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,3]]}},"alternative-id":["jcp5010004"],"URL":"https:\/\/doi.org\/10.3390\/jcp5010004","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,18]]}}}