DeepRadar: A cyber-defence interceptor for early warning and defusing malware injection attacks.

Saved in:
Bibliographic Details
Title: DeepRadar: A cyber-defence interceptor for early warning and defusing malware injection attacks.
Authors: Javaheri, Danial1 (AUTHOR) Danial.Javaheri@uws.ac.uk, Chizari, Hassan2 (AUTHOR) hchizari@glos.ac.uk, Fahmideh, Mahdi3 (AUTHOR) Mahdi.Fahmideh@unisq.edu.au, Nadimi-Shahraki, Mohammad H.4 (AUTHOR) nadimi@yuntech.edu.tw, Hur, Junbeom5 (AUTHOR) jbhur@korea.ac.kr
Source: Knowledge-Based Systems. Jan2026, Vol. 331, pN.PAG-N.PAG. 1p.
Subjects: Malware, Artificial neural networks, Risk assessment, Cyberterrorism
Abstract: • Generating early warning signals to proactively prevent malware injection attacks, including zero-day and emerging variants. • Intercepting malware API and IRP calls deep within the operating system kernel. • Incorporating a multi-layer runtime scanner that tracks inter-process communications, repelling up to 97.2% of injection attacks with proven long-term durability. • Employing a deep neural network architecture enhanced by fast Fourier convolution and association rule mining, scalable to large malware datasets. • Demonstrating robustness against obfuscation, evasion, and adversarial conditions, consistently outperforming leading anti-virus programs and state-of-the-art studies in accuracy and efficiency. Malware injection attacks are among the most sophisticated and elusive threats in cybersecurity, characterised by their capacity for privilege escalation, obfuscation, and the ability to deceive antivirus software. This paper introduces a multi-layer architecture, featuring innovative deep neural networks, fast Fourier convolution , and association rule mining strategies, designed for the early detection and defusal of malware injection attacks. We then propose a proactive AI-enabled malware detection platform, DeepRadar , as a novel real-world defence mechanism. This early warning functionality capable of anticipating the attack a few cycles before occurrence represents a novel idea and unique approach to detecting malware injection attacks. The experimental results validate DeepRadar's superior performance compared to not only previous related studies but also a standard benchmark of well-reputed antivirus applications under various scenarios and accredited datasets, including heavily obfuscated emerging malware variants and adversarial samples. It demonstrates higher Accuracy, F-score, ROC, and AUC metrics in early detection and classification of malware injection attacks while DeepRadar consumes significantly fewer system resources, including processor and memory during long-term scalable operation. The proposed early warning system succeeded in repelling up to 97.2% of attacks before malware could complete their malicious sequence. Lastly, the evaluation results were substantiated by formal statistical analysis using Friedman and Wilcoxon tests. The findings of this research and DeepRadar's runtime scanner provide vital early warnings against stealthy malware and injection attacks, offering robust protection for sensitive systems and critical infrastructure. [ABSTRACT FROM AUTHOR]
Copyright of Knowledge-Based Systems is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 190230764
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: DeepRadar: A cyber-defence interceptor for early warning and defusing malware injection attacks.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Javaheri%2C+Danial%22">Javaheri, Danial</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> Danial.Javaheri@uws.ac.uk</i><br /><searchLink fieldCode="AR" term="%22Chizari%2C+Hassan%22">Chizari, Hassan</searchLink><relatesTo>2</relatesTo> (AUTHOR)<i> hchizari@glos.ac.uk</i><br /><searchLink fieldCode="AR" term="%22Fahmideh%2C+Mahdi%22">Fahmideh, Mahdi</searchLink><relatesTo>3</relatesTo> (AUTHOR)<i> Mahdi.Fahmideh@unisq.edu.au</i><br /><searchLink fieldCode="AR" term="%22Nadimi-Shahraki%2C+Mohammad+H%2E%22">Nadimi-Shahraki, Mohammad H.</searchLink><relatesTo>4</relatesTo> (AUTHOR)<i> nadimi@yuntech.edu.tw</i><br /><searchLink fieldCode="AR" term="%22Hur%2C+Junbeom%22">Hur, Junbeom</searchLink><relatesTo>5</relatesTo> (AUTHOR)<i> jbhur@korea.ac.kr</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Knowledge-Based+Systems%22">Knowledge-Based Systems</searchLink>. Jan2026, Vol. 331, pN.PAG-N.PAG. 1p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Malware%22">Malware</searchLink><br /><searchLink fieldCode="DE" term="%22Artificial+neural+networks%22">Artificial neural networks</searchLink><br /><searchLink fieldCode="DE" term="%22Risk+assessment%22">Risk assessment</searchLink><br /><searchLink fieldCode="DE" term="%22Cyberterrorism%22">Cyberterrorism</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: • Generating early warning signals to proactively prevent malware injection attacks, including zero-day and emerging variants. • Intercepting malware API and IRP calls deep within the operating system kernel. • Incorporating a multi-layer runtime scanner that tracks inter-process communications, repelling up to 97.2% of injection attacks with proven long-term durability. • Employing a deep neural network architecture enhanced by fast Fourier convolution and association rule mining, scalable to large malware datasets. • Demonstrating robustness against obfuscation, evasion, and adversarial conditions, consistently outperforming leading anti-virus programs and state-of-the-art studies in accuracy and efficiency. Malware injection attacks are among the most sophisticated and elusive threats in cybersecurity, characterised by their capacity for privilege escalation, obfuscation, and the ability to deceive antivirus software. This paper introduces a multi-layer architecture, featuring innovative deep neural networks, fast Fourier convolution , and association rule mining strategies, designed for the early detection and defusal of malware injection attacks. We then propose a proactive AI-enabled malware detection platform, DeepRadar , as a novel real-world defence mechanism. This early warning functionality capable of anticipating the attack a few cycles before occurrence represents a novel idea and unique approach to detecting malware injection attacks. The experimental results validate DeepRadar's superior performance compared to not only previous related studies but also a standard benchmark of well-reputed antivirus applications under various scenarios and accredited datasets, including heavily obfuscated emerging malware variants and adversarial samples. It demonstrates higher Accuracy, F-score, ROC, and AUC metrics in early detection and classification of malware injection attacks while DeepRadar consumes significantly fewer system resources, including processor and memory during long-term scalable operation. The proposed early warning system succeeded in repelling up to 97.2% of attacks before malware could complete their malicious sequence. Lastly, the evaluation results were substantiated by formal statistical analysis using Friedman and Wilcoxon tests. The findings of this research and DeepRadar's runtime scanner provide vital early warnings against stealthy malware and injection attacks, offering robust protection for sensitive systems and critical infrastructure. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Knowledge-Based Systems is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=190230764
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1016/j.knosys.2025.114830
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 1
        StartPage: N.PAG
    Subjects:
      – SubjectFull: Malware
        Type: general
      – SubjectFull: Artificial neural networks
        Type: general
      – SubjectFull: Risk assessment
        Type: general
      – SubjectFull: Cyberterrorism
        Type: general
    Titles:
      – TitleFull: DeepRadar: A cyber-defence interceptor for early warning and defusing malware injection attacks.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Javaheri, Danial
      – PersonEntity:
          Name:
            NameFull: Chizari, Hassan
      – PersonEntity:
          Name:
            NameFull: Fahmideh, Mahdi
      – PersonEntity:
          Name:
            NameFull: Nadimi-Shahraki, Mohammad H.
      – PersonEntity:
          Name:
            NameFull: Hur, Junbeom
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 03
              M: 01
              Text: Jan2026
              Type: published
              Y: 2026
          Identifiers:
            – Type: issn-print
              Value: 09507051
          Numbering:
            – Type: volume
              Value: 331
          Titles:
            – TitleFull: Knowledge-Based Systems
              Type: main
ResultId 1