A machine learning-based investigation into the detection of trojan horse malware using classification algorithms

Mohammad Aljaidi, Ayoub Alsarhan, Manish Kumar Singla · IET conference proceedings. · 2025

This study proposes a deep learning-based framework There has been an increase in internet use which has come along with the expanse of cyber crime especially on malware-based intrusion. The Trojan horse or a type of malicious software that claims to be authentic or harmless is still considered one of the most dangerous threats that grant them unauthorized access, provide remote control, and perform malicious actions including file elimination, disk formatting and non-authorized extraction of information. Its stealth characteristic often makes it possible to remain undetected longer, thus increasing the chances of serious system compromise. Traditional security systems in many cases show moderate effectiveness in identifying threats of the Trojan family, therefore, it is necessary to consider more flexible options. The current work proposes a machine-learning architecture to detect Trojan Horse malwares using an up to date and comprehensive dataset. In order to identify which model would be most appropriate in predictive classification, a comparative analysis of three supervised learning algorithms; namely Naive Bayes (NB), J48 decision trees and Instance-Based K-nearest neighbor (IBk) were examined. The number of samples used in the experiment is 172,144 with 21 different features. The algorithms have been implemented in the Python environment, which uses these algorithms to label instances and identify malicious behavior patterns, which are the sign of a Trojan activity. The analysis of the results shows that the Naive Bayes algorithm reached the best results when it comes to classifications, and it was characterized by high accuracy and low error rates compared to the other models.

Read the paper · More papers on PaperTik