DeepRadar: A cyber-defence interceptor for early warning and defusing malware injection attacks.

Saved in:
Bibliographic Details
Title: DeepRadar: A cyber-defence interceptor for early warning and defusing malware injection attacks.
Authors: Javaheri, Danial1 (AUTHOR) Danial.Javaheri@uws.ac.uk, Chizari, Hassan2 (AUTHOR) hchizari@glos.ac.uk, Fahmideh, Mahdi3 (AUTHOR) Mahdi.Fahmideh@unisq.edu.au, Nadimi-Shahraki, Mohammad H.4 (AUTHOR) nadimi@yuntech.edu.tw, Hur, Junbeom5 (AUTHOR) jbhur@korea.ac.kr
Source: Knowledge-Based Systems. Jan2026, Vol. 331, pN.PAG-N.PAG. 1p.
Subjects: Malware, Artificial neural networks, Risk assessment, Cyberterrorism
Abstract: • Generating early warning signals to proactively prevent malware injection attacks, including zero-day and emerging variants. • Intercepting malware API and IRP calls deep within the operating system kernel. • Incorporating a multi-layer runtime scanner that tracks inter-process communications, repelling up to 97.2% of injection attacks with proven long-term durability. • Employing a deep neural network architecture enhanced by fast Fourier convolution and association rule mining, scalable to large malware datasets. • Demonstrating robustness against obfuscation, evasion, and adversarial conditions, consistently outperforming leading anti-virus programs and state-of-the-art studies in accuracy and efficiency. Malware injection attacks are among the most sophisticated and elusive threats in cybersecurity, characterised by their capacity for privilege escalation, obfuscation, and the ability to deceive antivirus software. This paper introduces a multi-layer architecture, featuring innovative deep neural networks, fast Fourier convolution , and association rule mining strategies, designed for the early detection and defusal of malware injection attacks. We then propose a proactive AI-enabled malware detection platform, DeepRadar , as a novel real-world defence mechanism. This early warning functionality capable of anticipating the attack a few cycles before occurrence represents a novel idea and unique approach to detecting malware injection attacks. The experimental results validate DeepRadar's superior performance compared to not only previous related studies but also a standard benchmark of well-reputed antivirus applications under various scenarios and accredited datasets, including heavily obfuscated emerging malware variants and adversarial samples. It demonstrates higher Accuracy, F-score, ROC, and AUC metrics in early detection and classification of malware injection attacks while DeepRadar consumes significantly fewer system resources, including processor and memory during long-term scalable operation. The proposed early warning system succeeded in repelling up to 97.2% of attacks before malware could complete their malicious sequence. Lastly, the evaluation results were substantiated by formal statistical analysis using Friedman and Wilcoxon tests. The findings of this research and DeepRadar's runtime scanner provide vital early warnings against stealthy malware and injection attacks, offering robust protection for sensitive systems and critical infrastructure. [ABSTRACT FROM AUTHOR]
Copyright of Knowledge-Based Systems is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Description
Abstract:• Generating early warning signals to proactively prevent malware injection attacks, including zero-day and emerging variants. • Intercepting malware API and IRP calls deep within the operating system kernel. • Incorporating a multi-layer runtime scanner that tracks inter-process communications, repelling up to 97.2% of injection attacks with proven long-term durability. • Employing a deep neural network architecture enhanced by fast Fourier convolution and association rule mining, scalable to large malware datasets. • Demonstrating robustness against obfuscation, evasion, and adversarial conditions, consistently outperforming leading anti-virus programs and state-of-the-art studies in accuracy and efficiency. Malware injection attacks are among the most sophisticated and elusive threats in cybersecurity, characterised by their capacity for privilege escalation, obfuscation, and the ability to deceive antivirus software. This paper introduces a multi-layer architecture, featuring innovative deep neural networks, fast Fourier convolution , and association rule mining strategies, designed for the early detection and defusal of malware injection attacks. We then propose a proactive AI-enabled malware detection platform, DeepRadar , as a novel real-world defence mechanism. This early warning functionality capable of anticipating the attack a few cycles before occurrence represents a novel idea and unique approach to detecting malware injection attacks. The experimental results validate DeepRadar's superior performance compared to not only previous related studies but also a standard benchmark of well-reputed antivirus applications under various scenarios and accredited datasets, including heavily obfuscated emerging malware variants and adversarial samples. It demonstrates higher Accuracy, F-score, ROC, and AUC metrics in early detection and classification of malware injection attacks while DeepRadar consumes significantly fewer system resources, including processor and memory during long-term scalable operation. The proposed early warning system succeeded in repelling up to 97.2% of attacks before malware could complete their malicious sequence. Lastly, the evaluation results were substantiated by formal statistical analysis using Friedman and Wilcoxon tests. The findings of this research and DeepRadar's runtime scanner provide vital early warnings against stealthy malware and injection attacks, offering robust protection for sensitive systems and critical infrastructure. [ABSTRACT FROM AUTHOR]
ISSN:09507051
DOI:10.1016/j.knosys.2025.114830