{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T03:58:35Z","timestamp":1782964715822,"version":"3.54.5"},"reference-count":51,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2023,11,11]],"date-time":"2023-11-11T00:00:00Z","timestamp":1699660800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Deputyship for Research &amp; Innovation, Ministry of Education in Saudi Arabia","award":["MoE-IF-UJ-22-4100409-8"],"award-info":[{"award-number":["MoE-IF-UJ-22-4100409-8"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Systems"],"abstract":"<jats:p>The Internet of Things (IoT) constitutes the foundation of a deeply interconnected society in which objects communicate through the Internet. This innovation, coupled with 5G and artificial intelligence (AI), finds application in diverse sectors like smart cities and advanced manufacturing. With increasing IoT adoption comes heightened vulnerabilities, prompting research into identifying IoT malware. While existing models excel at spotting known malicious code, detecting new and modified malware presents challenges. This paper presents a novel six-step framework. It begins with eight malware attack datasets as input, followed by insights from Exploratory Data Analysis (EDA). Feature engineering includes scaling, One-Hot Encoding, target variable analysis, feature importance using MDI and XGBoost, and clustering with K-Means and PCA. Our GhostNet ensemble, combined with the Gated Recurrent Unit Ensembler (GNGRUE), is trained on these datasets and fine-tuned using the Jaya Algorithm (JA) to identify and categorize malware. The tuned GNGRUE-JA is tested on malware datasets. A comprehensive comparison with existing models encompasses performance, evaluation criteria, time complexity, and statistical analysis. Our proposed model demonstrates superior performance through extensive simulations, outperforming existing methods by around 15% across metrics like AUC, accuracy, recall, and hamming loss, with a 10% reduction in time complexity. These results emphasize the significance of our study\u2019s outcomes, particularly in achieving cost-effective solutions for detecting eight malware strains.<\/jats:p>","DOI":"10.3390\/systems11110547","type":"journal-article","created":{"date-parts":[[2023,11,13]],"date-time":"2023-11-13T02:46:47Z","timestamp":1699843607000},"page":"547","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Enhancing Smart IoT Malware Detection: A GhostNet-based Hybrid Approach"],"prefix":"10.3390","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7181-2100","authenticated-orcid":false,"given":"Abdulwahab Ali","family":"Almazroi","sequence":"first","affiliation":[{"name":"Department of Information Technology, College of Computing and Information Technology at Khulais, University of Jeddah, Jeddah 21959, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1153-5401","authenticated-orcid":false,"given":"Nasir","family":"Ayub","sequence":"additional","affiliation":[{"name":"Department of Creative Technologies, Air University Islamabad, Islamabad 44000, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,11,11]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"59353","DOI":"10.1109\/ACCESS.2021.3073408","article-title":"Internet of Things Applications, Security Challenges, Attacks, Intrusion Detection, and Future Visions: A Systematic Review","volume":"9","author":"Mishra","year":"2021","journal-title":"IEEE Access"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"2023764","DOI":"10.1080\/17517575.2021.2023764","article-title":"A Comprehensive Survey on Machine Learning Approaches for Malware Detection in IoT-Based Enterprise Information System","volume":"17","author":"Gaurav","year":"2023","journal-title":"Enterp. Inf. Syst."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"109032","DOI":"10.1016\/j.comnet.2022.109032","article-title":"A Survey on Deep Learning for Cybersecurity: Progress, Challenges, and Opportunities","volume":"212","author":"Macas","year":"2022","journal-title":"Comput. Netw."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"103663","DOI":"10.1016\/j.autcon.2021.103663","article-title":"Customization of On-Site Assembly Services by Integrating the Internet of Things and BIM Technologies in Modular Integrated Construction","volume":"126","author":"Zhou","year":"2021","journal-title":"Autom. Constr."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"106030","DOI":"10.1016\/j.engappai.2023.106030","article-title":"A Novel Deep Learning-Based Approach for Malware Detection","volume":"122","author":"Shaukat","year":"2023","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Pal\u0161a, J., \u00c1d\u00e1m, N., Hurtuk, J., Chovancov\u00e1, E., Mado\u0161, B., Chovanec, M., and Kocan, S. (2022). MLMD\u2014A Malware-Detecting Antivirus Tool Based on the XGBoost Machine Learning Algorithm. Appl. Sci., 12.","DOI":"10.3390\/app12136672"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.future.2021.11.030","article-title":"A Study on Malicious Software Behaviour Analysis and Detection Techniques: Taxonomy, Current Trends and Challenges","volume":"130","author":"Maniriho","year":"2022","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"5","DOI":"10.30564\/ssid.v2i2.1931","article-title":"Machine Learning: A Review","volume":"2","author":"Udousoro","year":"2020","journal-title":"Semicond. Sci. Inf. Devices"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"105461","DOI":"10.1016\/j.engappai.2022.105461","article-title":"A Novel Method for Improving the Robustness of Deep Learning-Based Malware Detectors against Adversarial Attacks","volume":"116","author":"Shaukat","year":"2022","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"6249","DOI":"10.1109\/ACCESS.2019.2963724","article-title":"A Comprehensive Review on Malware Detection Approaches","volume":"8","author":"Aslan","year":"2020","journal-title":"IEEE Access"},{"key":"ref_11","first-page":"1","article-title":"Malware Detection Techniques: A Comprehensive Study","volume":"1","author":"Mishra","year":"2023","journal-title":"Insights Int. Interdiscip. J."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Kwon, H.Y., Kim, T., and Lee, M.K. (2022). Advanced Intrusion Detection Combining Signature-Based and Behavior-Based Detection Methods. Electronics, 11.","DOI":"10.3390\/electronics11060867"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"101861","DOI":"10.1016\/j.sysarc.2020.101861","article-title":"A Survey on Machine Learning-Based Malware Detection in Executable Files","volume":"112","author":"Singh","year":"2021","journal-title":"J. Syst. Archit."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"800","DOI":"10.3390\/jcp2040041","article-title":"A Survey of the Recent Trends in Deep Learning Based Malware Detection","volume":"2","author":"Tayyab","year":"2022","journal-title":"J. Cybersecur. Priv."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Aboaoja, F.A., Zainal, A., Ghaleb, F.A., Al-rimy, B.A.S., Eisa, T.A.E., and Elnour, A.A.H. (2022). Malware Detection Issues, Challenges, and Future Directions: A Survey. Appl. Sci., 12.","DOI":"10.3390\/app12178482"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Alomari, E.S., Nuiaa, R.R., Alyasseri, Z.A.A., Mohammed, H.J., Sani, N.S., Esa, M.I., and Musawi, B.A. (2023). Malware Detection Using Deep Learning and Correlation-Based Feature Selection. Symmetry, 15.","DOI":"10.3390\/sym15010123"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Hemalatha, J., Roseline, S.A., Geetha, S., Kadry, S., and Dama\u0161evi\u010dius, R. (2021). An Efficient DenseNet-Based Deep Learning Model for Malware Detection. Entropy, 23.","DOI":"10.3390\/e23030344"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"280","DOI":"10.1016\/j.icte.2020.04.005","article-title":"A Survey of IoT Malware and Detection Methods Based on Static Features","volume":"6","author":"Ngo","year":"2020","journal-title":"ICT Express"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Khalid, A., Badshah, G., Ayub, N., Shiraz, M., and Ghouse, M. (2023). Software Defect Prediction Analysis Using Machine Learning Techniques. Sustainability, 15.","DOI":"10.3390\/su15065517"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"73","DOI":"10.1016\/j.comcom.2022.08.015","article-title":"A Multi-View Attention-Based Deep Learning Framework for Malware Detection in Smart Healthcare Systems","volume":"195","author":"Ravi","year":"2022","journal-title":"Comput. Commun."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"103277","DOI":"10.1016\/j.cose.2023.103277","article-title":"A System Call-Based Android Malware Detection Approach with Homogeneous & Heterogeneous Ensemble Machine Learning","volume":"130","author":"Bhat","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_22","first-page":"24","article-title":"A New Malware Detection Model Using Emerging Machine Learning Algorithms","volume":"13","author":"Dewanje","year":"2021","journal-title":"Int. J. Electron. Inf. Eng."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Patil, S., Varadarajan, V., Walimbe, D., Gulechha, S., Shenoy, S., Raina, A., and Kotecha, K. (2021). Improving the Robustness of AI-Based Malware Detection Using Adversarial Machine Learning. Algorithms, 14.","DOI":"10.3390\/a14100297"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"230","DOI":"10.1016\/j.future.2019.11.034","article-title":"Similarity-Based Android Malware Detection Using Hamming Distance of Static Binary Features","volume":"105","author":"Taheri","year":"2020","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Sayadi, H., Patel, N., Sasan, A., Rafatirad, S., and Homayoun, H. (2018, January 24\u201329). Ensemble Learning for Effective Run-Time Hardware-Based Malware Detection: A Comprehensive Analysis and Classification. Proceedings of the 55th Annual Design Automation Conference, San Francisco, CA, USA.","DOI":"10.1145\/3195970.3196047"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Sihwail, R., Omar, K., Zainol Ariffin, K.A., and Al Afghani, S. (2019). Malware Detection Approach Based on Artifacts in Memory Image and Dynamic Analysis. Appl. Sci., 9.","DOI":"10.3390\/app9183680"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1007\/s11265-020-01588-1","article-title":"A Method for Windows Malware Detection Based on Deep Learning","volume":"93","author":"Huang","year":"2021","journal-title":"J. Signal Process. Syst."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Atitallah, S.B., Driss, M., and Almomani, I. (2022). A Novel Detection and Multi-Classification Approach for IoT-Malware Using Random Forest Voting of Fine-Tuning Convolutional Neural Networks. Sensors, 22.","DOI":"10.3390\/s22114302"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1109\/TLA.2023.10015144","article-title":"An assessment of the effectiveness of pretrained neural networks for malware detection","volume":"21","author":"Malvacio","year":"2023","journal-title":"IEEE Latin America Transactions"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"206303","DOI":"10.1109\/ACCESS.2020.3036491","article-title":"Intelligent Vision-Based Malware Detection and Classification Using Deep Random Forest Paradigm","volume":"8","author":"Roseline","year":"2020","journal-title":"IEEE Access"},{"key":"ref_31","unstructured":"Andreopoulos, W.B. (2021). Malware Analysis Using Artificial Intelligence and Deep Learning, Springer."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"5770","DOI":"10.1002\/int.22529","article-title":"Hybrid Sequence-Based Android Malware Detection Using Natural Language Processing","volume":"36","author":"Zhang","year":"2021","journal-title":"Int. J. Intell. Syst."},{"key":"ref_33","first-page":"179","article-title":"Methods for Automatic Malware Analysis and Classification: A Survey","volume":"17","year":"2022","journal-title":"Int. J. Inf. Comput. Secur."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"1328","DOI":"10.1109\/TKDE.2019.2946162","article-title":"A Survey on Data Collection for Machine Learning: A Big Data-AI Integration Perspective","volume":"33","author":"Roh","year":"2019","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_35","first-page":"42","article-title":"Image Based Malware Classification with Multimodal Deep Learning","volume":"10","author":"Demirezen","year":"2021","journal-title":"Int. J. Inf. Secur. Sci."},{"key":"ref_36","first-page":"122255","article-title":"Detection approaches for android malware: Taxonomy and review analysis","volume":"2023","author":"Manzil","year":"2023","journal-title":"Expert Syst. Appl."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"6760920","DOI":"10.1155\/2022\/6760920","article-title":"An empirical evaluation of supervised learning methods for network malware identification based on feature selection","volume":"2022","author":"Manzano","year":"2022","journal-title":"Complexity"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"68066","DOI":"10.1109\/ACCESS.2021.3077498","article-title":"Recurrent neural networks-based online behavioral malware detection techniques for cloud infrastructure","volume":"9","author":"Kimmel","year":"2021","journal-title":"IEEE Access"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"14","DOI":"10.9734\/ajrcos\/2021\/v7i430185","article-title":"A detailed analysis of benchmark datasets for a network intrusion detection system","volume":"7","author":"Ghurab","year":"2021","journal-title":"Asian J. Res. Comput. Sci."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Alavizadeh, H., Jang-Jaccard, J., Enoch, S.Y., Al-Sahaf, H., Welch, I., Camtepe, S.A., and Kim, D.S. (2021). A Survey on Threat Situation Awareness Systems: Framework, Techniques, and Insights. arXiv.","DOI":"10.1145\/3530809"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"6227","DOI":"10.1007\/s00521-021-06786-x","article-title":"A real-time adaptive network intrusion detection for streaming data: A hybrid approach","volume":"34","author":"Saeed","year":"2022","journal-title":"Neural Comput. Appl."},{"key":"ref_42","unstructured":"(2023, September 12). Malware Dataset, IoT23. Available online: https:\/\/www.stratosphereips.org\/datasets-iot23."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Chicco, D., and Jurman, G. (2020). The Advantages of the Matthews Correlation Coefficient (MCC) over F1 Score and Accuracy in Binary Classification Evaluation. BMC Genom., 21.","DOI":"10.1186\/s12864-019-6413-7"},{"key":"ref_44","unstructured":"Geetha, K., and Brahmananda, S.H. (2022). Network Traffic Analysis Through Deep Learning for Detection of an Army of Bots in Health IoT Network. Int. J. Pervasive Comput. Commun., ahead-of-print."},{"key":"ref_45","first-page":"37","article-title":"Ensemble Feature Selection and Classification of Internet Traffic Using XGBoost Classifier","volume":"11","author":"Manju","year":"2019","journal-title":"Int. J. Comput. Netw. Inf. Secur."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"AbdulRaheem, M., Oladipo, I.D., Imoize, A.L., Awotunde, J.B., Lee, C.C., Balogun, G.B., and Adeoti, J.O. (2023). Machine Learning Assisted Snort and Zeek in Detecting DDoS Attacks in Software-Defined Networking. Int. J. Inf. Technol., 1\u201317.","DOI":"10.1007\/s41870-023-01469-3"},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"1387","DOI":"10.1007\/s10044-021-00977-x","article-title":"A Hybrid Reciprocal Model of PCA and K-means with an Innovative Approach of Considering Sub-datasets for the Improvement of K-means Initialization and Step-by-Step Labeling to Create Clusters with High Interpretability","volume":"24","author":"Anaraki","year":"2021","journal-title":"Pattern Anal. Appl."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Shutaywi, M., and Kachouie, N.N. (2021). Silhouette analysis for performance evaluation in machine learning with applications to clustering. Entropy, 23.","DOI":"10.3390\/e23060759"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Lovmar, L., Ahlford, A., Jonsson, M., and Syv\u00e4nen, A.C. (2005). Silhouette Scores for Assessment of SNP Genotype Clusters. BMC Genom., 6.","DOI":"10.1186\/1471-2164-6-35"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"1479","DOI":"10.1109\/TKDE.2019.2947676","article-title":"Extended Isolation Forest","volume":"33","author":"Hariri","year":"2019","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Han, K., Wang, Y., Tian, Q., Guo, J., Xu, C., and Xu, C. (2020, January 13\u201319). GhostNet: More Features from Cheap Operations. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition; IEEE\/CVF, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00165"}],"container-title":["Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2079-8954\/11\/11\/547\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:21:36Z","timestamp":1760131296000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2079-8954\/11\/11\/547"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,11]]},"references-count":51,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2023,11]]}},"alternative-id":["systems11110547"],"URL":"https:\/\/doi.org\/10.3390\/systems11110547","relation":{},"ISSN":["2079-8954"],"issn-type":[{"value":"2079-8954","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,11]]}}}