Skip to content
Conference

Intelligent Extraction of Static and Dynamic Invariants for Botnet Classification

Sep 2026 · Automation, Control, and Information Technology · pp. 773-778 · 0 citations · 48 references

Abstract

The rapid mutation and obfuscation techniques employed by modern polymorphic botnets create a highly dynamic and non-stationary distribution of malware signatures, rendering traditional detection algorithms obsolete. This paper addresses the challenge of identifying such evasive threats by proposing a machine learning-driven framework focused on the intelligent extraction of invariant feature spaces. Instead of relying on volatile binary structures, the proposed methodology maps executable files into a hybrid, multi-dimensional feature space. This space intelligently aggregates statically derived structural topology, such as Shannon entropy and Control Flow Graphs (CFG), with dynamically captured behavioral semantics, including system API call sequences and network anomalies. To accurately navigate this complex feature representation, an ensemble learning model based on the Random Forest algorithm is utilized to define non-linear decision boundaries. This classifier effectively isolates invariant malicious patterns from benign software distributions. To address the data imbalance problem typical in network traffic analysis, the model's robustness is evaluated using a simulation-based methodology with a synthetically generated dataset comprising over 10,000 unique polymorphic mutations. Experimental results confirm that the intelligent invariantextraction approach achieves a classification accuracy exceeding 95% while maintaining a false positive rate strictly below 1%, proving its high efficacy for integration into cognitive defense systems.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.