{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,19]],"date-time":"2026-08-19T19:42:49Z","timestamp":1787168569648,"version":"3.56.0"},"reference-count":42,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100004515","name":"Universiti Kebangsaan Malaysia","doi-asserted-by":"publisher","award":["GUP-2022-060"],"award-info":[{"award-number":["GUP-2022-060"]}],"id":[{"id":"10.13039\/501100004515","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Malware is one of the most frequent cyberattacks, with its prevalence growing daily across the network. Malware traffic is always asymmetrical compared to benign traffic, which is always symmetrical. Fortunately, there are many artificial intelligence techniques that can be used to detect malware and distinguish it from normal activities. However, the problem of dealing with large and high-dimensional data has not been addressed enough. In this paper, a high-performance malware detection system using deep learning and feature selection methodologies is introduced. Two different malware datasets are used to detect malware and differentiate it from benign activities. The datasets are preprocessed, and then correlation-based feature selection is applied to produce different feature-selected datasets. The dense and LSTM-based deep learning models are then trained using these different versions of feature-selected datasets. The trained models are then evaluated using many performance metrics (accuracy, precision, recall, and F1-score). The results indicate that some feature-selected scenarios preserve almost the same original dataset performance. The different nature of the used datasets shows different levels of performance changes. For the first dataset, the feature reduction ratios range from 18.18% to 42.42%, with performance degradation of 0.07% to 5.84%, respectively. The second dataset reduction rate is between 81.77% and 93.5%, with performance degradation of 3.79% and 9.44%, respectively.<\/jats:p>","DOI":"10.3390\/sym15010123","type":"journal-article","created":{"date-parts":[[2023,1,2]],"date-time":"2023-01-02T02:12:48Z","timestamp":1672625568000},"page":"123","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":151,"title":["Malware Detection Using Deep Learning and Correlation-Based Feature Selection"],"prefix":"10.3390","volume":"15","author":[{"given":"Esraa Saleh","family":"Alomari","sequence":"first","affiliation":[{"name":"College of Education for Pure Sciences, Wasit University, Al-Kut 52001, Iraq"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3063-5360","authenticated-orcid":false,"given":"Riyadh Rahef","family":"Nuiaa","sequence":"additional","affiliation":[{"name":"College of Education for Pure Sciences, Wasit University, Al-Kut 52001, Iraq"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4228-9298","authenticated-orcid":false,"given":"Zaid Abdi Alkareem","family":"Alyasseri","sequence":"additional","affiliation":[{"name":"Information Technology Research and Development Centre (ITRDC), University of Kufa, Najaf 54001, Iraq"},{"name":"College of Engineering, University of Warith Al-Anbiyaa, Karbala 63514, Iraq"},{"name":"National Energy Centre, Universiti Tenaga Nasional (UNITEN), Selangor 43000, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3521-0465","authenticated-orcid":false,"given":"Husam Jasim","family":"Mohammed","sequence":"additional","affiliation":[{"name":"Department of Business Administration, College of Administration and Financial Sciences, Imam Ja\u2019afar Al-Sadiq University, Baghdad 10001, Iraq"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5802-5946","authenticated-orcid":false,"given":"Nor Samsiah","family":"Sani","sequence":"additional","affiliation":[{"name":"Center for Artificial Intelligence Technology, Faculty of Information Science & Technology, Universiti Kebangsaan Malaysia, Bangi 43600, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0702-422X","authenticated-orcid":false,"given":"Mohd Isrul","family":"Esa","sequence":"additional","affiliation":[{"name":"Center for Artificial Intelligence Technology, Faculty of Information Science & Technology, Universiti Kebangsaan Malaysia, Bangi 43600, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bashaer Abbuod","family":"Musawi","sequence":"additional","affiliation":[{"name":"Department of Biology, Faculty of Education for Girls, University of Kufa, Najaf 54001, Iraq"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,1,1]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Rathore, H., Agarwal, S., Sahay, S., and Sewak, M. (2018, January 10\u201313). Malware detection using machine learning and deep learning. Proceedings of the International Conference on Big Data Analytics, Seattle, WA, USA.","DOI":"10.1007\/978-3-030-04780-1_28"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Nasif, A., Othman, Z., and Sani, N.S. (2021). The deep learning solutions on lossless compression methods for alleviating data load on IoT nodes in smart cities. Sensors, 21.","DOI":"10.3390\/s21124223"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"46717","DOI":"10.1109\/ACCESS.2019.2906934","article-title":"Robust intelligent malware detection using deep learning","volume":"7","author":"Vinayakumar","year":"2019","journal-title":"IEEE Access"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"38","DOI":"10.4018\/IJSSCI.2021010103","article-title":"A two-phase load balancing algorithm for cloud environment","volume":"13","author":"Singh","year":"2021","journal-title":"Int. J. Softw. Sci. Comput. Intell."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"424","DOI":"10.1016\/j.icte.2021.09.003","article-title":"A Bayesian probability model for Android malware detection","volume":"8","author":"Mat","year":"2022","journal-title":"ICT Express"},{"key":"ref_6","first-page":"97","article-title":"Detecting compromised social network accounts using deep learning for behavior and text analyses","volume":"11","author":"Yen","year":"2021","journal-title":"Int. J. Cloud Appl. Comput."},{"key":"ref_7","first-page":"587","article-title":"Feature selection for phishing website classification","volume":"11","author":"Shabudin","year":"2020","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Liu, C.-H., Zhang, Z.-J., and Wang, S.-D. (2016, January 8\u201310). An android malware detection approach using Bayesian inference. Proceedings of the 2016 IEEE International Conference on Computer and Information Technology (CIT), Nadi, Fiji.","DOI":"10.1109\/CIT.2016.76"},{"key":"ref_9","unstructured":"(2022, November 22). GDATA Mobile Malware Report\u2014No let-up with Android malware. Available online: https:\/\/www.gdatasoftware.com\/news\/2019\/07\/35228-mobile-malware-report-no-let-up-with-android-malware."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3417978","article-title":"A survey of android malware detection with deep neural models","volume":"53","author":"Qiu","year":"2020","journal-title":"ACM Comput. Surv."},{"key":"ref_11","first-page":"2301","article-title":"An effective memory analysis for malware detection and classification","volume":"67","author":"Sihwail","year":"2021","journal-title":"Comput. Mater. Contin."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"2013","DOI":"10.1007\/s11192-020-03834-6","article-title":"Towards a systematic description of the field using bibliometric analysis: Malware evolution","volume":"126","author":"Mat","year":"2021","journal-title":"Scientometrics"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Bassel, A., Abdulkareem, A., Alyasseri, Z., Sani, N., and Mohammed, H.J. (2022). Automatic Malignant and Benign Skin Cancer Classification Using a Hybrid Deep Learning Approach. Diagnostics, 12.","DOI":"10.3390\/diagnostics12102472"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1080\/19361610.2018.1387734","article-title":"A new malware detection system using machine learning techniques for API call sequences","volume":"13","author":"Jerlin","year":"2018","journal-title":"J. Appl. Secur. Res."},{"key":"ref_15","first-page":"1125","article-title":"An Optimal Framework for SDN Based on Deep Neural Network","volume":"73","author":"Abdallah","year":"2022","journal-title":"Comput. Mater. Contin."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Han, H., Lim, S., Suh, K., Park, S., Cho, S., and Park, M. (2020, January 19\u201322). Enhanced android malware detection: An svm-based machine learning approach. Proceedings of the 2020 IEEE International Conference on Big Data and Smart Computing (BigComp), Busan, Republic of Korea.","DOI":"10.1109\/BigComp48618.2020.00-96"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Singh, P., Borgohain, S., and Kumar, J. (2022, January 24\u201325). Performance Enhancement of SVM-based ML Malware Detection Model Using Data Preprocessing. Proceedings of the 2022 2nd International Conference on Emerging Frontiers in Electrical and Electronic Technologies (ICEFEET), Patna, India.","DOI":"10.1109\/ICEFEET51821.2022.9848192"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Droos, A., Al-Mahadeen, A., Al-Harasis, T., Al-Attar, R., and Ababneh, M. (2022, January 21\u201323). Android Malware Detection Using Machine Learning. Proceedings of the 2022 13th International Conference on Information and Communication Systems (ICICS), Irbid, Jordan.","DOI":"10.1109\/ICICS55353.2022.9811130"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Baldini, G., and Geneiatakis, D. (2019, January 23\u201326). A performance evaluation on distance measures in KNN for mobile malware detection. Proceedings of the 2019 6th international conference on control, decision and information technologies (CoDIT), Paris, France.","DOI":"10.1109\/CoDIT.2019.8820510"},{"key":"ref_20","first-page":"2349","article-title":"An optimized KNN model for signature-based malware detection","volume":"8","author":"Assegie","year":"2021","journal-title":"Tsehay Admassu Assegie. Int. J. Comput. Eng. Res. Trends (IJCERT)"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"69","DOI":"10.4018\/IJSWIS.2020010104","article-title":"Internet data analysis methodology for cyberterrorism vocabulary detection, combining techniques of big data analytics, NLP and semantic web","volume":"16","year":"2020","journal-title":"Int. J. Semant. Web Inf. Syst."},{"key":"ref_22","first-page":"269","article-title":"Classification of Malicious Android Applications Using Naive Bayes and Support Vector Machine Algorithms","volume":"10","author":"Yilmaz","year":"2022","journal-title":"Int. J. Intell. Syst. Appl. Eng."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1142\/S0218194019500116","article-title":"Permission-based android malware detection system using feature selection with genetic algorithm","volume":"29","author":"Yildiz","year":"2019","journal-title":"Int. J. Softw. Eng. Knowl. Eng."},{"key":"ref_24","unstructured":"Arora, A., Peddoju, S., Chouhan, V., and Chaudhary, A. (November, January 29). Hybrid Android malware detection by combining supervised and unsupervised learning. Proceedings of the 24th Annual International Conference on Mobile Computing and Networking, New Delhi, India."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.ins.2020.05.026","article-title":"Malware-detection method with a convolutional recurrent neural network using opcode sequences","volume":"535","author":"Jeon","year":"2020","journal-title":"Inf. Sci."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"106630","DOI":"10.1016\/j.asoc.2020.106630","article-title":"Cryptocurrency malware hunting: A deep recurrent neural network approach","volume":"96","author":"Yazdinejad","year":"2020","journal-title":"Appl. Soft Comput."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"293","DOI":"10.1007\/s10723-020-09510-6","article-title":"Detecting cryptomining malware: A deep learning approach for static and dynamic analysis","volume":"18","author":"Darabian","year":"2020","journal-title":"J. Grid Comput."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Hwang, C., Hwang, J., Kwak, J., and Lee, T. (2020). Platform-independent malware analysis applicable to windows and linux environments. Electronics, 9.","DOI":"10.3390\/electronics9050793"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"20008","DOI":"10.1109\/ACCESS.2022.3151357","article-title":"FAM: Featuring Android Malware for Deep Learning-Based Familial Analysis","volume":"10","author":"Ban","year":"2022","journal-title":"IEEE Access"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Smmarwar, S.K., Gupta, G., and Kumar, S. (2022). A Hybrid Feature Selection Approach-Based Android Malware Detection Framework Using Machine Learning Techniques. Cyber Security, Privacy and Networking, Springer.","DOI":"10.1007\/978-981-16-8664-1_30"},{"key":"ref_31","first-page":"74","article-title":"Static Feature Selection for IoT Malware Detection","volume":"1","author":"Toan","year":"2022","journal-title":"J. Sci. Technol. Inf. Secur."},{"key":"ref_32","unstructured":"N SARAVANA (2022, November 22). Malware Detection|Kaggle. Available online: https:\/\/www.kaggle.com\/datasets\/nsaravana\/malware-detection?select=Malware+dataset.csv."},{"key":"ref_33","unstructured":"SHASHWAT TIWARI (2022, November 22). Android Malware Dataset for Machine Learning|Kaggle. Available online: https:\/\/www.kaggle.com\/datasets\/shashwatwork\/android-malware-dataset-for-machine-learning."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"453","DOI":"10.1109\/TCYB.2017.2777960","article-title":"Droidfusion: A novel multilevel classifier fusion approach for android malware detection","volume":"49","author":"Yerima","year":"2018","journal-title":"IEEE Trans. Cybern."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Goutte, C., and Gaussier, E. (2005, January 21\u201323). A probabilistic interpretation of precision, recall and F-score, with implication for evaluation. Proceedings of the European conference on information retrieval, Santiago de Compostela, Spain.","DOI":"10.1007\/978-3-540-31865-1_25"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1007\/s13721-012-0006-6","article-title":"Threshold-based feature selection techniques for high-dimensional bioinformatics data","volume":"1","author":"Khoshgoftaar","year":"2012","journal-title":"Netw. Model. Anal. Heal. informatics Bioinforma."},{"key":"ref_37","first-page":"189","article-title":"Graph approach for android malware detection using machine learning techniques","volume":"2","author":"Gumaa","year":"2021","journal-title":"Humanit. Nat. Sci. J."},{"key":"ref_38","first-page":"102852","article-title":"An optimized and efficient android malware detection framework for future sustainable computing","volume":"54","author":"Smmarwar","year":"2022","journal-title":"Sustain. Energy Technol. Assess."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"3979","DOI":"10.1007\/s11042-017-5104-0","article-title":"Android malware detection based on system call sequences and LSTM","volume":"78","author":"Xiao","year":"2019","journal-title":"Multimed. Tools Appl."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"333","DOI":"10.1016\/j.future.2018.11.021","article-title":"A machine learning based approach to detect malicious android apps using discriminant system calls","volume":"94","author":"Vinod","year":"2019","journal-title":"Futur. Gener. Comput. Syst."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Taha, A., and Barukab, O. (2022). Android Malware Classification Using Optimized Ensemble Learning Based on Genetic Algorithms. Sustainability, 14.","DOI":"10.3390\/su142114406"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Masum, M., and Shahriar, H. (2019, January 9\u201312). Droid-NNet: Deep learning neural network for android malware detection. Proceedings of the 2019 IEEE International Conference on Big Data (Big Data), Los Angeles, CA, USA.","DOI":"10.1109\/BigData47090.2019.9006053"}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/15\/1\/123\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T17:55:19Z","timestamp":1760118919000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/15\/1\/123"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,1]]},"references-count":42,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,1]]}},"alternative-id":["sym15010123"],"URL":"https:\/\/doi.org\/10.3390\/sym15010123","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,1,1]]}}}