{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:27:38Z","timestamp":1760146058740,"version":"build-2065373602"},"reference-count":21,"publisher":"MDPI AG","issue":"19","license":[{"start":{"date-parts":[[2024,10,2]],"date-time":"2024-10-02T00:00:00Z","timestamp":1727827200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The rapid increase in new malware necessitates effective detection methods. While machine learning techniques have shown promise for malware detection, most research focuses on identifying malware through the content of executable files or full behavior logs collected from process start to finish. However, detecting threats like ransomware via full logs is redundant, as this malware type openly informs users of the infection. To address this, we present LEDA, a novel malware detection architecture designed to monitor process behavior during execution and to identify malicious actions in real time. LEDA dynamically learns the most relevant features for detection and optimally triggers model evaluations to minimize the performance impact perceived by users. We evaluated LEDA using a dataset of Windows malware and legitimate applications collected over a year, examining our model\u2019s temporal decay in effectiveness.<\/jats:p>","DOI":"10.3390\/s24196393","type":"journal-article","created":{"date-parts":[[2024,10,2]],"date-time":"2024-10-02T06:27:31Z","timestamp":1727850451000},"page":"6393","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["LEDA\u2014Layered Event-Based Malware Detection Architecture"],"prefix":"10.3390","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9008-1462","authenticated-orcid":false,"given":"Radu Marian","family":"Portase","sequence":"first","affiliation":[{"name":"Computer Science Department, Technical University of Cluj Napoca, 400114 Cluj Napoca, Romania"},{"name":"Bitdefender, 060071 Bucharest, Romania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8985-4728","authenticated-orcid":false,"given":"Raluca Laura","family":"Portase","sequence":"additional","affiliation":[{"name":"Computer Science Department, Technical University of Cluj Napoca, 400114 Cluj Napoca, Romania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2431-4253","authenticated-orcid":false,"given":"Adrian","family":"Colesa","sequence":"additional","affiliation":[{"name":"Computer Science Department, Technical University of Cluj Napoca, 400114 Cluj Napoca, Romania"},{"name":"Bitdefender, 060071 Bucharest, Romania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7773-1077","authenticated-orcid":false,"given":"Gheorghe","family":"Sebestyen","sequence":"additional","affiliation":[{"name":"Computer Science Department, Technical University of Cluj Napoca, 400114 Cluj Napoca, Romania"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2024,10,2]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Calleja, A., Tapiador, J., and Caballero, J. (2016). A look into 30 years of malware development from a software metrics perspective. Research in Attacks, Intrusions, and Defenses, Proceedings of the 19th International Symposium, RAID 2016, Paris, France, 19\u201321 September 2016, Springer. Proceedings 19.","DOI":"10.1007\/978-3-319-45719-2_15"},{"key":"ref_2","unstructured":"Goyal, M., and Kumar, R. (2020, January 30\u201331). The pipeline process of signature-based and behavior-based malware detection. Proceedings of the 2020 IEEE 5th International Conference on Computing Communication and Automation (ICCCA), Greater Noida, India."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"141045","DOI":"10.1109\/ACCESS.2023.3256979","article-title":"Machine learning algorithm for malware detection: Taxonomy, current challenges, and future directions","volume":"11","author":"Gorment","year":"2023","journal-title":"IEEE Access"},{"key":"ref_4","unstructured":"Alpaydin, E. (2021). Machine Learning, MIT Press."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Akhtar, M.S., and Feng, T. (2023). Evaluation of Machine Learning Algorithms for Malware Detection. Sensors, 23.","DOI":"10.3390\/s23020946"},{"key":"ref_6","first-page":"1210","article-title":"Dynamic Malware Analysis with Feature Engineering and Feature Learning","volume":"34","author":"Zhang","year":"2020","journal-title":"Proc. AAAI Conf. Artif. Intell."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"103704","DOI":"10.1016\/j.jnca.2023.103704","article-title":"API-MalDetect: Automated malware detection framework for windows based on API calls and deep learning techniques","volume":"218","author":"Maniriho","year":"2023","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Nishiyama, T., Kumagai, A., Fujino, A., and Kamiya, K. (2024, January 6\u20139). Malicious Log Detection Using Machine Learning to Maximize the Partial AUC. Proceedings of the 2024 IEEE 21st Consumer Communications & Networking Conference (CCNC), Las Vegas, NV, USA.","DOI":"10.1109\/CCNC51664.2024.10454779"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Nguyen, N.T., Pham, T.T., Dang, T.X., Dao, M.S., Dang-Nguyen, D.T., Gurrin, C., and Nguyen, B.T. (2020, January 10\u201312). Malware detection using system logs. Proceedings of the 2020 ACM Workshop on Intelligent Cross-Data Analysis and Retrieval, Dublin, Ireland.","DOI":"10.1145\/3379174.3392318"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Mills, A., Spyridopoulos, T., and Legg, P. (2019, January 3\u20134). Efficient and Interpretable Real-Time Malware Detection Using Random-Forest. Proceedings of the 2019 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (Cyber SA), Oxford, UK.","DOI":"10.1109\/CyberSA.2019.8899533"},{"key":"ref_11","unstructured":"Chistyakov, A., Lobacheva, E., Shevelev, A., and Romanenko, A. (2018). Monotonic models for real-time dynamic malware detection. arXiv."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"2518","DOI":"10.1109\/TNNLS.2021.3121248","article-title":"Learning Fast and Slow: Propedeutica for Real-Time Malware Detection","volume":"33","author":"Sun","year":"2022","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref_13","unstructured":"IBM (2024, August 12). Berkeley Packet Filters. Available online: https:\/\/www.ibm.com\/docs\/en\/qsip\/7.4?topic=queries-berkeley-packet-filters."},{"key":"ref_14","unstructured":"Apple (2024, August 12). Endpoint Security. Available online: https:\/\/developer.apple.com\/documentation\/endpointsecurity."},{"key":"ref_15","unstructured":"Zamboni, D. (2008). Learning and Classification of Malware Behavior. Detection of Intrusions and Malware, and Vulnerability Assessment, Proceedings of the DIMVA 2018, Saclay, France, 28\u201329 June 2018, Springer."},{"key":"ref_16","unstructured":"Strom, B.E., Applebaum, A., Miller, D.P., Nickels, K.C., Pennington, A.G.P., and Thomas, C.B. (2018). MITRE ATT&CK\u2122: Design and Philosophy. Technical Report, MITRE."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Sebasti\u00e1n, S., and Caballero, J. (2020). AVClass2: Massive Malware Tag Extraction from AV Labels. arXiv.","DOI":"10.1145\/3427228.3427261"},{"key":"ref_18","unstructured":"Buitinck, L., Louppe, G., Blondel, M., Pedregosa, F., Mueller, A., Grisel, O., Niculae, V., Prettenhofer, P., Gramfort, A., and Grobler, J. (2013). API design for machine learning software: Experiences from the scikit-learn project. arXiv."},{"key":"ref_19","first-page":"2825","article-title":"Scikit-learn: Machine Learning in Python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"ref_20","unstructured":"AV-Test (2024, August 12). AV-Test Test Module\u2014Performance (System Load). Available online: https:\/\/www.av-test.org\/en\/antivirus\/business-windows-client\/."},{"key":"ref_21","unstructured":"ULEnterprise (2024, August 12). PCMARK 10\u2014THE COMPLETE BENCHMARK. Available online: https:\/\/benchmarks.ul.com\/pcmark10."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/19\/6393\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T16:09:07Z","timestamp":1760112547000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/19\/6393"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,2]]},"references-count":21,"journal-issue":{"issue":"19","published-online":{"date-parts":[[2024,10]]}},"alternative-id":["s24196393"],"URL":"https:\/\/doi.org\/10.3390\/s24196393","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2024,10,2]]}}}